🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 743 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0e1bbf81-a61e-48d6-8485-9a6b6278dc39
< 2.7.8
MEDIUM 6.4 The Embed Any Document plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
0e1982bd-3ea8-48cd-8b89-39910567525c
< 2.0.8.3
MEDIUM 6.4 The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin fo… wordfence
0dfbee4c-b720-4d10-bfe0-fe9dc12e6268
< 4.4.5
MEDIUM 6.4 The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to Stored Cross-S… wordfence
0df493cb-2b5e-4a16-b6d8-4cd9a473540d
< 2.7.10
MEDIUM 6.4 The Spectra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.9 du… wordfence
0de75f3f-1e6b-42ea-9f08-54c32e37b4c7 MEDIUM 6.4 The Exxp plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.9 due t… wordfence
0ddb582a-e966-4c0b-a743-29d8943f846b
< 5.9.2
MEDIUM 6.4 WordPress Core in versions 5.9 - 5.9.1 is vulnerable to Contributor+ stored Cross-Site Scripting via the double JSON enc… wordfence
0dca2c66-64df-44c7-9c75-330dddf582c8 MEDIUM 6.4 The Simple Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'simple_chart' shor… wordfence
0dc82635-e3c4-4a15-93ef-e2cacbfae799
< 1.1.41
MEDIUM 6.4 The Weather Widget Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and incl… wordfence
0db63414-b8c3-41bf-a6df-4b6113ea7388 MEDIUM 6.4 The Softtemplates For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
0dad759d-9b44-47ca-8410-e39f65dc919c
< 3.8.6
MEDIUM 6.4 The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu… wordfence
0da6d357-e55f-4bf6-9cd7-50e3dc712434
< 1.2.20
MEDIUM 6.4 The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmflat' shortcode … wordfence
0d9712c2-1698-4c67-a700-a4598cb25a95 MEDIUM 6.4 The WPSite Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'format' shortcode attrib… wordfence
0d96465a-d1b6-4991-8e81-e80a0d15a902
< 1.3.2
MEDIUM 6.4 The Social Media Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'twitter'… wordfence
0d8c043c-e347-4dc8-8a72-943a7e6c4394
< 7.0.2
MEDIUM 6.4 The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
0d837229-52fa-42ae-b733-8fbeb444f110
< 2.7.6
MEDIUM 6.4 The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,… wordfence
0d82c866-5b35-414e-bd72-30530930d5d8
< 1.6.47
MEDIUM 6.4 wordfence
0d7b65eb-ec97-4307-be01-ed4c0d6d2f10
< 1.5.0
MEDIUM 6.4 The Kata Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.7 … wordfence
0d5d47bd-4f05-4dc7-84c1-f7bc1196ee16
< 3.21.2
MEDIUM 6.4 The Elementor Website Builder – More than Just a Page Builder Pro plugin for WordPress is vulnerable to Stored Cross-S… wordfence
0d1b2539-bff0-4185-8162-9e8b75183bb8
< 1.17.6
MEDIUM 6.4 The Hyperlink Group Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
0d127114-9c80-4722-953a-3ee1382b9f81 MEDIUM 6.4 The ST Categories Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's st-categorie… wordfence
0d0a03e5-b09c-430d-aa65-8ef9e01cf241
< 2.5.2
MEDIUM 6.4 The Conference Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ param… wordfence
0cebc614-7ceb-49ed-96d7-57f7cc61c396 MEDIUM 6.4 The Link View plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.8.0 … wordfence
0ce2a9fe-3364-46b5-a6ae-b4feb3e20647
< 1.0.1
MEDIUM 6.4 The GDPR-Extensions-com – Consent Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG Fi… wordfence
0cdadbf2-8b5d-4018-8cee-0d0fb07696f9
< 2.12
MEDIUM 6.4 The WP SPID Italia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all v… wordfence
0cd66329-098e-4adf-b66f-d82a47720629
< 1.0.8
MEDIUM 6.4 The Algori PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to the use of a vulnerable v… wordfence
← Prev 740 741 742 743 744 745 746 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top