πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 742 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0eca4a3f-8f08-447b-8092-0432d67c56e9
< 3.10.01
MEDIUM 6.4 The ElementsKit Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
0eb875d6-03ff-441e-9a4e-69aa577c8587
< 1.0.8
MEDIUM 6.4 The Taskbuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in versions up to,… wordfence
0eb50d3f-9e01-4e3d-a3ed-8c3fec006be6
< 2.5.19
MEDIUM 6.4 The Html5 Video Player – mp4 player, Video Player for WordPress plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
0eafe473-9177-47c4-aa1e-2350cb827447
< 3.5.0
MEDIUM 6.4 The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile Display Name and Social Se… wordfence
0ea59a87-1b69-42fa-afc4-d68b33df94b1 MEDIUM 6.4 The Google Org Chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
0ea0f826-5ae9-4dad-89d0-9fc9f10f526b MEDIUM 6.4 Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inj… wordfence
0e9ec6af-fa51-4e14-abf6-450c1ca6f8d5
< 3.4.9
MEDIUM 6.4 The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cro… wordfence
0e9e2864-6624-497f-8bec-df8360ed3f4a
< 4.35
MEDIUM 6.4 The (Simply) Guest Author Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's post m… wordfence
0e9dc5e3-9d72-4c04-8ba9-56428a6fdddd
< 2.19.29
MEDIUM 6.4 The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross… wordfence
0e951b97-3d17-4360-8fec-393e2f0c13d2
< 1.9.8
MEDIUM 6.4 The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
0e9324ba-1cbf-4326-80b5-7b9d969441ad
< 2.15.8
MEDIUM 6.4 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
0e89f295-df1e-48a6-b19e-7a73b24ac402
< 7.1.3
MEDIUM 6.4 The Enfold theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.1.2 due … wordfence
0e7e9fcc-804a-46a8-95cd-b358ba7681ec MEDIUM 6.4 The Entry Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'entry-views' shortco… wordfence
0e75c346-8152-4c4f-995a-7ab90a31feb0
< 2.8.1
MEDIUM 6.4 The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
0e67ce3b-144f-4ce1-b658-47d865312c6a
< 2.2.0
MEDIUM 6.4 The Contact Form – Custom Builder, Payment Form, and More plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
0e6492e5-a506-4d77-96d2-08f700b6ee76
< 3.99.0
MEDIUM 6.4 The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
0e606ceb-a7b4-4e60-ae2c-8939bd5acbfe
< 1.3.2
MEDIUM 6.4 The Solace Extra plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,… wordfence
0e5c0e0e-9851-4d28-a87b-b55fc7f76e0b
< 2.13.5
MEDIUM 6.4 The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
0e57cf85-eec0-4cf6-a800-ceb2b46e2bcd
< 0.9.2
MEDIUM 6.4 The glomex oEmbed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'glomex_integration… wordfence
0e4f4bc3-8fe8-401b-9027-b6f91b6c521f
< 3.0.3
MEDIUM 6.4 The Sky Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
0e41384f-1dec-418b-be48-fc61def5ca28
< 2.7.6
MEDIUM 6.4 The Elementor Website Builder for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
0e3575f8-7adc-4546-9f78-bcb2cf3caa2a
< 7.7
MEDIUM 6.4 wordfence
0e2e3c0e-9ac3-4f6f-b49f-2e50e0fb905f
< 1.0.5
MEDIUM 6.4 The Easy YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
0e24c8f4-32c9-4c21-88d9-588913cbb474
< 1.2.9
MEDIUM 6.4 The Elementor ImageBox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image box widget in all… wordfence
0e1e17c9-b9ee-495a-be49-9aa88f8023a2
< 2.5.1
MEDIUM 6.4 The Code Embed plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2… wordfence
← Prev 739 740 741 742 743 744 745 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top