🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 751 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
06424d9f-0064-4101-b819-688489a18eee MEDIUM 6.4 The Telephone Number Linker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'telnumli… wordfence
063f47f5-277c-420e-b080-fd4908468848 MEDIUM 6.4 The Simple Photo Sphere plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
063345b7-040b-4576-8634-663eda9135fa
< 0.2.1
MEDIUM 6.4 The Ketchup Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
063224fe-3cf8-40b6-8645-86c8e8dc876e
< 1.6.7
MEDIUM 6.4 The Post Grid, Slider & Carousel Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
063011d3-d744-46a7-9069-89e3a8f843f3
< 2.14.31
MEDIUM 6.4 The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
062f5bc7-9d53-4a28-b603-9901ce2175d8
< 1.4.7
MEDIUM 6.4 The Smash Balloon Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Req… wordfence
062af58f-32e6-4551-b82b-a2766ad5644c MEDIUM 6.4 The JB News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of… wordfence
062844b8-5d19-447f-86df-7b084fa275cb
< 2.4.5
MEDIUM 6.4 The HT Politic plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.4… wordfence
062620fc-3d37-4913-bcc7-ce5e9b812d6c MEDIUM 6.4 The SpaBiz theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.18 due… wordfence
0624108b-cd60-4278-802d-d4853f73ec6a
< 3.14.27
MEDIUM 6.4 The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘api_key’ and 'ap… wordfence
061eeba3-10ad-4272-9880-dc01d4368683 MEDIUM 6.4 The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rocketchat'… wordfence
061ada09-932f-4d2c-aa9e-c53f1d711c85
< 1.7.3
MEDIUM 6.4 The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button wi… wordfence
0612c377-ec67-43b3-add0-5e9b0696eea1
< 2.1.19
MEDIUM 6.4 The Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar plugin for WordPress… wordfence
05de06b1-52bb-47f7-af5e-e9320cf0437f
< 2.5.5.3
MEDIUM 6.4 The Beaver Builder – WordPress Page Builder for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text E… wordfence
05dd7c96-7880-44a8-a06f-037bc627fd8d
< 1.64.0.0
MEDIUM 6.4 The VK Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vk-blocks/ancestor-pag… wordfence
05da4808-385c-4e9f-96f8-5d5c04e7371b
< 4.0.8
MEDIUM 6.4 The MainWP Wordfence Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and includi… wordfence
05d6b27f-b1e5-4bb8-b7db-f8295a5e0d5b
< 3.0.8
MEDIUM 6.4 The 404 to 301 plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the open_r… wordfence
05d26003-ae7e-480a-bd63-1c5f5e9c3cab
< 1.4.1
MEDIUM 6.4 The Image Hover Effects – Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'e… wordfence
05cd8f96-533a-4036-a01f-6ba1ad2d2b5e
< 1.5
MEDIUM 6.4 The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p… wordfence
05c7267e-2e0c-48e9-bdaa-c8bc0b9ec8a6
< 1.5.0
MEDIUM 6.4 The Kata Plus – Addons for Elementor – Widgets, Extensions and Templates plugin for WordPress is vulnerable to Store… wordfence
05c44865-26ba-44c1-8ffd-bf28c0463a54
< 2.3.16
MEDIUM 6.4 The Firelight Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via posts in all versions up to… wordfence
05a9c77d-a8d6-41b6-a98e-f20638b959d6
< 1.0.13
MEDIUM 6.4 The Ogulo – 360° Tour plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slug’ parameter … wordfence
0597a63d-2627-477f-874a-c35b6df7afd5
< 2.5.8
MEDIUM 6.4 The WP AdCenter – Ad Manager & Adsense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p… wordfence
0590d3ad-8dd0-428e-aadd-581e53e83edb MEDIUM 6.4 The WordPress Jitsi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortco… wordfence
058e47cd-55c8-48b3-8aa6-ef299886061d MEDIUM 6.4 The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… wordfence
← Prev 748 749 750 751 752 753 754 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top