πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 747 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0987285b-4daf-4979-934b-7fa4a0ded99f
< 3.7.14
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in Word… wordfence
098348de-f6b5-4eab-ae41-2dd32ca951fd
< 1.6.4
MEDIUM 6.4 The Simple Pull Quote plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
0982cc3e-87d7-49d2-afa3-8c18355d7968
< 1.4.7
MEDIUM 6.4 The Payment Page | Payment Form for Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pr… wordfence
098177e8-2d81-4a9f-bcf4-5f649c9c47ca
< 6.5.2
MEDIUM 6.4 The Shortcoder β€” Create Shortcodes for Anything plugin for WordPress is vulnerable to Stored Cross-Site Scripting in v… wordfence
097760a6-0b8b-437d-a6ad-29675cbb5091
< 3.2.3
MEDIUM 6.4 The Sprout Clients plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3… wordfence
0976ab6c-d7ad-47c6-9017-2cc6ebd8158f
< 8.6.11
MEDIUM 6.4 The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.5.31 du… wordfence
09631637-55e2-4e1e-9dcb-bba205be5f43
< 1.5.24
MEDIUM 6.4 The Page Builder: Live Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting parameter in versions … wordfence
09506d1c-986e-45c8-b43c-7f2578eb2dbd MEDIUM 6.4 The Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0… wordfence
094d4fb1-1b8e-4d0c-9e79-91ecf39caf9f
< 1.1.39
MEDIUM 6.4 The Hydra Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
09479df1-ff7e-4df8-9aea-8c7622ecea4e MEDIUM 6.4 The f(x) TOC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions… wordfence
0946fab3-6299-4f62-9664-c0a049e2dbb3
< 7.4.8
MEDIUM 6.4 The Zigaform – Price Calculator & Cost Estimation Form Builder Lite plugin for WordPress is vulnerable to Stored Cross… wordfence
09463140-2edc-4458-900b-a898d115f34d MEDIUM 6.4 The Elfsight WhatsApp Chat CC plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
093f69c8-890b-4885-81bf-e46d994c3fdb
< 3.0.1
MEDIUM 6.4 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
093959d3-a8a9-4ff1-856d-7ea121e330cc MEDIUM 6.4 The ML Responsive Audio player with playlist Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
09316a23-3a99-47f2-9c3f-795dc0a4a792
< 2.16.4
MEDIUM 6.4 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
092e13db-1667-458c-a1c0-f35c167d5d45
< 3.21.1
MEDIUM 6.4 The Ultimate Addons for WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… wordfence
0923bbb1-3c67-4503-adc4-86955a8ec63d
< 1.1.22
MEDIUM 6.4 The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
091c6cb3-dc5a-4fb8-a1a5-770b2361401f
< 11.14
MEDIUM 6.4 The WPMobile.App β€” Android and iOS Mobile Application plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
0907c74e-0bb8-4761-aabf-79d880c78415 MEDIUM 6.4 The Comparison Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slider title parameter i… wordfence
08f8f489-6b31-45d8-a122-bbaa283a2b10
< 4.16.1
MEDIUM 6.4 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
08ef71da-50f2-4f7e-8a23-23adbabee09d
< 2.0.0
MEDIUM 6.4 The LSX Tour Operator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all vers… wordfence
08ef43cc-42ea-43bd-a590-4f9b2c719491 MEDIUM 6.4 The Shortcodely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'widget_area' parameter in all… wordfence
08ecde76-3249-4be2-81b8-cccc60f73063
< 1.2.1
MEDIUM 6.4 The Restrict Anonymous Access plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
08d4ed49-1338-422f-b55f-a102f2d1d6c8
< 3.0.1
MEDIUM 6.4 The Essential Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ew-author, ew-a… wordfence
08bfa13b-7335-4973-a5e5-e0d09cbf5b06 MEDIUM 6.4 The Nias course plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.… wordfence
← Prev 744 745 746 747 748 749 750 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top