๐Ÿ›ก๏ธ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 746 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0a77ea13-5ac2-427a-8e1c-a5fa29c9f2dc
< 1.3.3.9
MEDIUM 6.4 The MDTF plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.3.8 due… wordfence
0a6627e5-8831-4724-a427-aaf5ebb67f57
< 2.3.0
MEDIUM 6.4 The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.… wordfence
0a5fdadc-9229-45d4-b6cb-2fb81b39f31e
< 2.1
MEDIUM 6.4 The ูุฑู… ุณุงุฒ ูุฑู… ุงูุฒุงุฑ plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
0a576c71-615c-4333-8cd3-93343ce64f7b
< 3.1.9
MEDIUM 6.4 The Graphina โ€“ Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multi… wordfence
0a46420e-8ca5-43ac-8475-786e24185f55 MEDIUM 6.4 Persistent XSS in wordpress plugin rockhoist-badges v1.2.2 via badge description and title fields. wordfence
0a44013c-00c6-4d47-867c-a42091c96efd
< 2.1.5
MEDIUM 6.4 The Email Templates Customizer for WordPress โ€“ Drag And Drop Email Templates Builder โ€“ YeeMail plugin for WordPress … wordfence
0a308fde-1c44-4c34-ace5-6820dc949f53
< 1.6.14
MEDIUM 6.4 The BoldGrid Easy SEO โ€“ Simple and Effective SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
0a2c56e5-23c7-47da-9f30-b41cef5297b8
< 1.0.44
MEDIUM 6.4 The Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.43 … wordfence
0a281774-226a-4cb7-ba4a-ebb76f20eb47
< 1.2.4.5
MEDIUM 6.4 The Ibtana โ€“ WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜al… wordfence
0a24a4a6-f297-4049-83f6-3a39fedee16a MEDIUM 6.4 The Simple Goods plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.1… wordfence
0a1e0d55-2894-450b-afaf-134a13512403 MEDIUM 6.4 The FTP Access plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
0a0ee752-7fc4-46d3-9e0f-8b9317b0ea72 MEDIUM 6.4 The PullQuote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pullquote' shortcode i… wordfence
0a00efc3-59a8-4601-a869-7455edabdeed
< 30.2
MEDIUM 6.4 The WooCommerce Customers Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
09fd13db-3dbb-4684-8bd8-2bb3eb91cf6a
< 3.1.5
MEDIUM 6.4 The WPC Countdown Timer for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
09f328f6-8a66-46bf-80d9-3ffeaecfec32
< 2.1.9
MEDIUM 6.4 The Email Encoder โ€“ Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
09f2cb22-07e2-4fe5-8c2a-9d4420ee26ed
< 3.13.4
MEDIUM 6.4 The Prime Slider โ€“ Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tit… wordfence
09cff621-3cf3-496e-ab91-66d088fe79dc
< 7.13.45
MEDIUM 6.4 The Super Socializer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in ve… wordfence
09c8db69-60fa-4087-9096-5d34ce44f616
< 4.4.1
MEDIUM 6.4 The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_wrapper_form' shortcode … wordfence
09a052a1-6e69-4972-9dab-802754cfb93a MEDIUM 6.4 The RSSImport plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and inc… wordfence
099f4139-8680-4b12-9d0e-ee4e361151e5
< 3.7
MEDIUM 6.4 The Advanced Sermons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
099e8784-48d2-4be7-9549-b9dbe57fe637
< 3.7.4
MEDIUM 6.4 The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7.3 … wordfence
099af779-ab6f-4fad-a4a9-832e5a892fdd
< 1.8.3
MEDIUM 6.4 The Collapse-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in ve… wordfence
09989141-43ba-446c-8230-0485add7a1e2 MEDIUM 6.4 The Padlet Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'key' parameter in the 'w… wordfence
098f219d-77e5-46f9-b8c2-fa8ccdc5af38
< 4.1.2
MEDIUM 6.4 The MainWP Maintenance Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and inclu… wordfence
098b979f-337d-4fbd-bfcc-0e8a281e6982 MEDIUM 6.4 The Simple Bible Verse via Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's … wordfence
← Prev 743 744 745 746 747 748 749 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top