🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 739 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
11867941-bc8d-49eb-9b0e-5d141cf7bf58
< 19.9.9.7
MEDIUM 6.4 The REHub Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and excluding, … wordfence
11807042-be3c-4780-bb47-ecc54aead5f2 MEDIUM 6.4 The FAT Event Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
11681152-e4f0-4cea-8fc8-f297368e4b15
< 2.2.9
MEDIUM 6.4 The insert-php (aka Woody ad snippets) plugin before 2.2.9 for WordPress allows authenticated XSS via the winp_item para… wordfence
11542fc6-33e2-40b9-be74-9fbb788f6915
< 3.4.1
MEDIUM 6.4 The MX Time Zone Clocks WordPress plugin before 3.4.1 does not escape the time_zone attribute of the mxmtzc_time_zone_cl… wordfence
1144ed12-57bd-4f80-9df8-0aee1fcf6343
< 5.6.0
MEDIUM 6.4 The Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5… wordfence
1144e0d9-692e-45a5-ac63-bcdd64a8bd8a
< 2.17.14
MEDIUM 6.4 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
11419311-4369-4882-9841-9523571b2d35
< 7.4.0
MEDIUM 6.4 The Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
113c154d-94a0-41da-a5ed-d9b2617e1c2c
< 12.5.1
MEDIUM 6.4 The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ parameter in… wordfence
11386b6a-632c-451a-b726-846f74b6f42d
< 2.7.19
MEDIUM 6.4 The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter Twe… wordfence
1137f15c-4adc-49d5-94a4-f1ea543b0dac MEDIUM 6.4 The WPB Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
111a0507-aa51-4e4e-a582-9007041c811b
< 2.4.0
MEDIUM 6.4 The App Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'appizy' shortcode in a… wordfence
110a1b28-50e0-430e-82d4-c254d73836e2
< 5.0.8
MEDIUM 6.4 The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
1102b3ef-5f55-46ce-bcd9-c364b2f7e82f
< 1.1.2
MEDIUM 6.4 The Project Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
10f7688e-019c-4c6b-a6ac-dacb66bcc36f
< 6.4.4
MEDIUM 6.4 The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
10ea8f3a-35d6-494e-90f6-9165320cf99c MEDIUM 6.4 The Print-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'print-me' shortcod… wordfence
10d926d7-bcc9-4424-8422-90edc36f0ad4
< 1.5.5
MEDIUM 6.4 The Scrollsequence plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
10cfc6e2-1502-45cb-b868-32228b3ccdd9
< 1.6.2
MEDIUM 6.4 The Custom Add to Cart Button Label and Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
10b47054-29cc-4859-bdfc-4dde1437c037
< 9.0.2
MEDIUM 6.4 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
10b08a05-3561-4d05-985b-6a2339a547a7
< 4.2.6.7
MEDIUM 6.4 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘… wordfence
10aaf8de-677d-466e-8736-bf1c5ca17495 MEDIUM 6.4 The Google Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
10945855-675a-4a85-8bb2-84bc40c1b826
< 8.5
MEDIUM 6.4 The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple P… wordfence
10933105-50d7-407a-b123-10b5f00ba688 MEDIUM 6.4 The Textboxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.1.3.… wordfence
109317dc-630a-4670-8871-85b3dcc1d006
< 3.6.3
MEDIUM 6.4 The BuddyPress Members Only plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
108f3e7b-f4c1-445c-914c-97960b21b5fa
< 4.0.0
MEDIUM 6.4 The WP Dark Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in vers… wordfence
108e9578-e586-4ed8-b0b2-dc6c26bf530e
< 1.5.7
MEDIUM 6.4 The Meteor Slides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and… wordfence
← Prev 736 737 738 739 740 741 742 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top