ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 744 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0cd6350c-6da8-4d5a-8ceb-d587ddf40d1d MEDIUM 6.4 Promotion Slider in versions up to and including 3.3.4 is vulnerable to Authenticated Stored Cross-Site Scripting via po… wordfence
0cd4d88d-0a88-4b81-a2f6-a98a0ddfdfb6
< 2.7
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPr… wordfence
0cd4b65d-b916-432f-bb59-d2f8a9aadeac
< 13.4.2
MEDIUM 6.4 The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
0cd2ad77-c5de-470d-bc17-729233e4ab92
< 5.3
MEDIUM 6.4 The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
0ccc60f3-122f-4959-b629-4b83d17083ad
< 5.1.3
MEDIUM 6.4 The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1… wordfence
0cc9cad8-0e2f-4ecf-9ca7-15ca060879c1
< 2.2.12
MEDIUM 6.4 The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPre… wordfence
0cb43deb-63f6-42d8-8dd6-55a59fca31ae
< 1.4.1
MEDIUM 6.4 The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
0caedaa2-4ac7-4402-9f4b-4bb39ff232cc
< 2.6.8
MEDIUM 6.4 The WP Date and Time Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
0c963224-e680-4ca6-85ae-07cd0ee6c1d4
< 2.3.1
MEDIUM 6.4 The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
0c84075b-4685-4706-91d0-05ce6cd276ca MEDIUM 6.4 The Accordion Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes i… wordfence
0c79eb10-2f4f-4d02-ad73-e74477afc947 MEDIUM 6.4 The Simple Colorbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
0c796ee7-5394-40f3-9158-1a006efbf085
< 3.29.1
MEDIUM 6.4 The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_te… wordfence
0c43a88c-6374-414f-97ae-26ba15d75cdc
< 0.8.11
MEDIUM 6.4 The Featured Image Caption plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode … wordfence
0c1e2397-72a8-464c-93c7-d518e6611149
< 3.8.12
MEDIUM 6.4 The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.8.12 due to insuffic… wordfence
0c1c343c-ef16-4468-a983-0dc9fd152dd5 MEDIUM 6.4 The Simple Nivo Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode paramete… wordfence
0c1758fc-5b0b-4071-b31b-1d72e34cc924
< 5.9.4
MEDIUM 6.4 The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
0c0827fd-05e6-48bb-9592-bcc373d5f77d MEDIUM 6.4 The Slideshow Wp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sswpid' attribute of the 'ss… wordfence
0bef99e0-1c97-4058-83a4-faa36ebcbf1f MEDIUM 6.4 The AzonBox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.2 du… wordfence
0be84866-2a49-42da-b498-962fc1bcb811
< 1.4.5
MEDIUM 6.4 The Product Code for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
0bc7ad47-aac9-4192-af04-234962f46f49
< 1.3.16
MEDIUM 6.4 The All Bootstrap Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
0bc330d5-7362-4158-90dc-b4ccb5e58ff3 MEDIUM 6.4 The Arkhe Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2… wordfence
0bb7920b-2999-4bd3-bfef-3b9971f845e9 MEDIUM 6.4 The Galleries by Angie Makes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcod… wordfence
0bb02fd7-1090-4139-ae0e-977fdec5da7f MEDIUM 6.4 The RT Easy Builder – Advanced addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
0b9e6f21-4c26-4ff8-9d0f-c66cd537fdcc
< 2.0
MEDIUM 6.4 The WP Youtube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all v… wordfence
0b9e11f5-5a05-4867-abd8-fb07c84a49b0 MEDIUM 6.4 The WP Random Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cat', 'nocat', and 'text… wordfence
← Prev 741 742 743 744 745 746 747 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top