🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 740 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1088098e-ae44-469f-8dc8-c6221c8ee5fd MEDIUM 6.4 The Advanced Typekit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
1079282d-3183-4190-8a54-d6085d27935a
< 2.23.0
MEDIUM 6.4 The Arkhe Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2… wordfence
1067cc82-3595-4228-a7a2-5b3be7677b1f
< 1.0.6
MEDIUM 6.4 The Media Player Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtitl… wordfence
105f501c-741d-4352-b080-e6730d0a7200
< 3.4.9
MEDIUM 6.4 The WP eBay Product Feeds plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and i… wordfence
1058078b-3afa-4fe7-913a-b6fc32252bf6
< 7.4
MEDIUM 6.4 The Zotpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nickname’ parameter in all v… wordfence
1056804b-c317-4b9f-85ce-41b4ed0ac40a
< 0.6.26
MEDIUM 6.4 The YaMaps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up … wordfence
1053ff60-469f-4940-a865-35ed28fc769a
< 1.6.3
MEDIUM 6.4 The Easy Coming Soon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘coming_soon_page_setti… wordfence
104b3c01-4623-43cb-aed4-16e3be62e1f9
< 9.1.1
MEDIUM 6.4 The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [wprm-recipe-inst… wordfence
103e7658-78d6-414d-ad68-e9adf77f1c60
< 1.4.3
MEDIUM 6.4 The My Favorites plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4… wordfence
103dea33-0c30-460e-80e4-fead18928a62
< 1.2
MEDIUM 6.4 The WPB Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter i… wordfence
103cbd07-4698-4b64-820d-d2df3fce95da
< 2.16.4
MEDIUM 6.4 The Age Gate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Additional content’ field in… wordfence
1036a34d-ec03-4bec-8455-02c83fdb8b36
< 2.3.7
MEDIUM 6.4 The Image Editor by Pixo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘download’ parame… wordfence
1026b753-e82b-4fa3-9023-c36ab9863b29
< 4.10.19
MEDIUM 6.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclic… wordfence
101b5012-7f12-4b6d-b9c8-aafb0b9bf039
< 1.9.6
MEDIUM 6.4 The Curator.io plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.5… wordfence
101945f6-d709-4c99-8c80-def9dd2fa636
< 7.6
MEDIUM 6.4 The ANAC XML Bandi di Gara plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(… wordfence
1016f16c-0ab2-4cac-a7a5-8d93a37e7894
< 4.4.6.2
MEDIUM 6.4 The Social Sharing Plugin – Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p… wordfence
1012f06d-2306-44bc-9235-528c1632be16 MEDIUM 6.4 The BlogLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.9… wordfence
100f6ccd-02d3-4b9e-8dd4-957a518c2a55
< 2.1.4
MEDIUM 6.4 The iChart – Easy Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width… wordfence
0ff67beb-638e-4d74-8d0e-6aece9207bb9
< 1.4.0
MEDIUM 6.4 The About Author plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_title’ parameter in… wordfence
0ff2bbe3-430d-4ef7-b2eb-30d0b69107d5
< 1.1.4
MEDIUM 6.4 The Icon List Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
0feeca6b-b611-44d3-90a6-569e4d2ccf5a
< 3.1.20
MEDIUM 6.4 The Icegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the campaign message field in versions… wordfence
0fe2e1d6-7431-4121-93ad-cfe7837ac374
< 1.2.7
MEDIUM 6.4 The myCred Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
0fda86d9-2b80-47f9-bfb5-4bdb780a718f
< 1.7
MEDIUM 6.4 The Goftino plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6 due … wordfence
0fc6cc1b-7d49-48cd-9bce-d37c6dcfece9
< 5.3.0
MEDIUM 6.4 The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulner… wordfence
0faca93b-b1b7-4157-a764-6d754c8b3976 MEDIUM 6.4 The Speaker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.13 d… wordfence
← Prev 737 738 739 740 741 742 743 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top