πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 745 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0b88ab64-26c7-4182-bd46-c5f5df052af3 MEDIUM 6.4 The Team Members for Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… wordfence
0b7d7b64-8194-4b81-83f5-1f3b23109455
< 2.4
MEDIUM 6.4 The Guest Author plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's guest author paramet… wordfence
0b79a851-1212-4a9c-89fe-b5f2d50ec18c
< 4.3.25
MEDIUM 6.4 The FluentForms plugin for WrodPress is vulnerable to stored Cross-Site Scripting via custom form fields in versions up … wordfence
0b77243f-f48b-4a94-9d60-bf96dc26fe77 MEDIUM 6.4 The AH Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'column' shortcode attribute… wordfence
0b7234b0-edfc-417c-8ef4-394d62cf83f7
< 3.1.1
MEDIUM 6.4 The Interface theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.1… wordfence
0b6a84d7-9e77-4a2f-b065-872e8650e75e
< 3.2.16
MEDIUM 6.4 The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu… wordfence
0b5894d8-0d3c-44cc-94a3-d8a46e0c0ef2 MEDIUM 6.4 The Build theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.3 due t… wordfence
0b56f54b-978e-41ea-8cbe-846facb71cd3 MEDIUM 6.4 The Endless Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all ver… wordfence
0b493316-511d-479f-b65c-c04ecd17171f
< 2.3.24
MEDIUM 6.4 The jQuery T(-) Countdown Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shor… wordfence
0b4178d1-e54d-4902-933d-49f9d4400b0e
< 7.5.2
MEDIUM 6.4 The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Server-Side Request Forgery in all vers… wordfence
0b40c664-95e0-4928-a5c2-b26277607ef5 MEDIUM 6.4 The Penci Filter Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
0b20d638-82cb-48ce-96fa-fd42d06f649f
< 1.27
MEDIUM 6.4 The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id attribute of widgets in… wordfence
0b19e8c0-4451-4fe2-9915-e879aa0ab410
< 11.1
MEDIUM 6.4 The Greenshift plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 11.0.… wordfence
0b09d496-0e03-48a4-acf7-57febe18ed0a
< 1.2.2.1
MEDIUM 6.4 The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ive'… wordfence
0b070542-83fc-4086-a40d-15a8d31fadc5
< 1.7.4
MEDIUM 6.4 The Widgets for Tiktok Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trustind… wordfence
0afd981e-3ae8-4450-9750-23ff6fe612dc
< 1.0.277
MEDIUM 6.4 The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_vide… wordfence
0af219a7-6596-47b2-ab8e-a71f20218759
< 2.2.2
MEDIUM 6.4 The BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce plugin for WordPress is vulnerabl… wordfence
0aeef472-0f09-458f-a0dc-b7de190b9b6d
< 1.1.28
MEDIUM 6.4 The EmbedSocial plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versi… wordfence
0ae16c4e-0151-4414-8612-ec8eb92505fd
< 2.8.1
MEDIUM 6.4 The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
0acf3219-1443-42cc-b3c9-cffb8fd8af07 MEDIUM 6.4 The Busiprof theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.8 du… wordfence
0abbdf2c-b1f8-4431-b892-1d7972749af6
< 2.10.3.2
MEDIUM 6.4 The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
0a907a0c-e9d2-4ba6-a149-dd8114837cad MEDIUM 6.4 The History Log by click5 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
0a8b5554-b4d9-48f2-ad16-cf96aabcbb6f
< 2.3.0
MEDIUM 6.4 The Tutor LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.4 … wordfence
0a8089e1-51ca-4e27-930c-d0bb57bbd641
< 2.27.0
MEDIUM 6.4 The Arkhe Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2… wordfence
0a7bc8b3-d000-46a1-aa36-eef38cb06e08 MEDIUM 6.4 The Ninja Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7… wordfence
← Prev 742 743 744 745 746 747 748 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top