🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 741 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0f9eb9cb-ead9-4ddf-b40b-a0ce2f4910f6
< 4.10.17
MEDIUM 6.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Wrap… wordfence
0f9c5bed-a399-43e2-be40-d669e90d3736
< 2.4.7
MEDIUM 6.4 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
0f99e32b-3985-4c50-817e-f54245e8b9c1
< 2.18.1
MEDIUM 6.4 The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via parameters in th… wordfence
0f986535-efc2-470e-bb50-e0964bb775b3
< 2.1
MEDIUM 6.4 The Smart Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0… wordfence
0f8e1495-c5e1-4bb9-92e9-b27b9b997a5f MEDIUM 6.4 The SVG Complete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions … wordfence
0f7f19fa-f3d9-41e9-94f5-9d817330f1ef
< 1.1.2
MEDIUM 6.4 The FAQ And Answers – Create Frequently Asked Questions Area on WP Sites plugin for WordPress is vulnerable to Stored … wordfence
0f7b119d-ec56-40cb-80ef-67585dadad77
< 4.3.3
MEDIUM 6.4 The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including… wordfence
0f78479f-8e28-4fa4-bf2b-eefedffa4d72
< 1.7.3
MEDIUM 6.4 The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
0f721733-2245-4d8d-9881-91cc0b48551b
< 1.5.20
MEDIUM 6.4 The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
0f6e7fcd-f5f5-47a0-9d8a-74e2f67d10b5
< 1.3.6
MEDIUM 6.4 The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
0f58bfbc-82b7-4155-af19-d17d5ed4238b MEDIUM 6.4 The Qr Code and Barcode Scanner Reader plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
0f56427e-6103-43ae-ae2e-23f520646535 MEDIUM 6.4 The Metaphor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
0f537479-d5ec-46bb-a04e-2c33a2abc759
< 3.20.0
MEDIUM 6.4 The WordPress Tag and Category Manager – AI Autotagger plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
0f4f8b84-3f65-430b-b749-6afae8d53153
< 3.2.13.2
MEDIUM 6.4 The BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Cou… wordfence
0f4bba27-efdc-4b2d-80be-4a5c17ef5e7c
< 1.1.6
MEDIUM 6.4 The “Rife Elementor Extensions & Templates” WordPress Plugin before 1.1.6 has a widget that is vulnerable to stored … wordfence
0f44fcc8-c5e0-44f5-92c3-6603b19a06fe
< 3.5.4
MEDIUM 6.4 The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded lottie files in all v… wordfence
0f281ef5-bb2e-42f9-be51-6f7bd3069f59
< 5.6.12
MEDIUM 6.4 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W… wordfence
0f204d39-8a4a-4008-adc6-3ba72531f5a2 MEDIUM 6.4 The Ask Me Anything (Anonymously) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'as… wordfence
0f17a161-83c8-4e83-a3e1-3e9f2e5f2c00
< 3.10.9
MEDIUM 6.4 The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… wordfence
0f01f69e-0ff8-4771-9bf5-53ef78438cc2
< 1.0.7
MEDIUM 6.4 The Property Hive Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘price… wordfence
0efe8bbd-c1c9-48ed-adab-34c0ac3da8bf
< 6.2.0
MEDIUM 6.4 The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to St… wordfence
0ef8f81e-b241-43c3-9045-610cdbc08be1
< 3.6.5
MEDIUM 6.4 The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.6.4.… wordfence
0ef82a52-0a32-4dc4-b027-3d2098549404
< 1.9.2
MEDIUM 6.4 The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in … wordfence
0ef1679f-44ec-448a-a77b-489ac9bfaa7a
< 1.0.335
MEDIUM 6.4 The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_news… wordfence
0ecba857-03d8-4a2e-9450-146d442f5533
< 1.2.43
MEDIUM 6.4 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordP… wordfence
← Prev 738 739 740 741 742 743 744 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top