πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 750 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
070f6820-e70c-4325-b5cb-d2010da34dce
< 1.5.3
MEDIUM 6.4 The Simple Like Page Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode… wordfence
070ccd70-22c3-47f1-9dce-a884bff9ea76
< 5.0.32
MEDIUM 6.4 The Ultimate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'moreResultsText' block attr… wordfence
07088f04-5c83-40e1-966b-11dce82bfaed MEDIUM 6.4 The short.io plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.0 d… wordfence
070616c9-b6a3-43d9-a82d-5cbcffc39ad9 MEDIUM 6.4 The Single Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'single-mailchimp' shortc… wordfence
06ff683d-b3ef-4cae-84f4-be6ada37d5bf
< 1.5.8.7
MEDIUM 6.4 The Visitor Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'order' and 'sort_by' paramet… wordfence
06fa63f7-13c6-4280-b6c8-db27e5e73a6a
< 4.0
MEDIUM 6.4 The Custom Background Changer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
06ef1f0c-fdcc-4aaf-9e48-19b5be52351d
< 2.7.7.22
MEDIUM 6.4 The Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
06e48355-6932-4401-8787-e6432444930f
< 4.4.5
MEDIUM 6.4 The Video Conferencing with Zoom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zoo… wordfence
06c1dc58-483e-49f7-aff0-e5a1e70bb149 MEDIUM 6.4 The Material Design Iconic Font Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl… wordfence
06b4888d-b9cc-491e-bbcc-13f3e4bfe77a MEDIUM 6.4 The MyBookProgress by Stormhill Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
06b3396e-4f94-4b5f-a427-453a87067ffb MEDIUM 6.4 The xili-language plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
069efaf5-8e8b-46f2-93ac-e3648b06855d
< 4.3.4
MEDIUM 6.4 The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
069d0ae9-c6fe-4375-8e8a-deb51119c66e
< 3.5.1
MEDIUM 6.4 The Easy Replace Image plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and incl… wordfence
069b2f3e-da9d-476c-a9fa-1b7d445a704b MEDIUM 6.4 The NOTICE BOARD BY TOWKIR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'notice-bo… wordfence
06982502-6055-4a79-93ef-4896ba086322
< 1.5.2
MEDIUM 6.4 The Coaching Staffs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mstw-cs-table' s… wordfence
06929eb6-8f00-480f-9bf7-de8a7f5d7c6c
< 1.4
MEDIUM 6.4 The Timeline Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3… wordfence
069134e8-e34b-4007-8583-137f40c29d00
< 1.28.10
MEDIUM 6.4 The e2pdf plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.28.09 du… wordfence
068cb545-8ced-45a1-a50a-1b6a38e99741 MEDIUM 6.4 The Scoutnet Kalender plugin 1.1.0 and before for WordPress allows XSS via 'info' field. wordfence
0687e101-3c96-4c9b-941a-1b0fed2f76e2
< 3.0
MEDIUM 6.4 The Awesome Contact Form7 for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'AEP C… wordfence
06804bed-17c5-413c-a31b-f6f039015e26 MEDIUM 6.4 The Global Body Mass Index Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gbmical… wordfence
067bfeaf-f3dd-4188-b53a-72b2d81a87eb MEDIUM 6.4 The PB oEmbed HTML5 Audio – with Cache Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
066dfb01-4f3c-4d5a-8fbf-7e58dfc7ac91
< 3.0.6
MEDIUM 6.4 The Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.0… wordfence
066de6fc-a304-4faa-8706-3358fc2dbf0f
< 2.3.3
MEDIUM 6.4 The Travelers' Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
065d01b6-30e0-4bc8-bd70-25996c2df879
< 5.0.1
MEDIUM 6.4 The Flow-Flow Social Feed Stream plugin for WordPress is vulnerable to unauthorized modification of data due to a missin… wordfence
0654e3c9-106d-4d90-a4e4-9705c36f7564
< 2.1.1
MEDIUM 6.4 The CC Canadian Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '… wordfence
← Prev 747 748 749 750 751 752 753 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top