πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 752 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
058d1aa0-2ef6-49a4-b978-43a91c8e55f3
< 8.3.2
MEDIUM 6.4 The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widg… wordfence
0582fe7d-884c-4019-837a-861d36ccc842
< 2.7.7
MEDIUM 6.4 The Related Posts by Taxonomy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'relate… wordfence
05806b8f-bd39-4107-8d1a-54586f15d7a4
< 2.1.22.1
MEDIUM 6.4 The JetProductGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
057a440e-4917-45c5-90ab-bb8654eae68f
< 2.0.1
MEDIUM 6.4 The Quick Restaurant Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in it… wordfence
056884d2-d737-4ae5-b800-cb2ff31347ab
< 2.8.2
MEDIUM 6.4 The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored Cr… wordfence
0565cdf1-55fe-4676-8529-8c79be5e8b01 MEDIUM 6.4 The VerticalResponse Newsletter Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'… wordfence
0519d77a-2fbd-48d5-bc2b-9efb84f9e559 MEDIUM 6.4 The Simple Baseball Scoreboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
0512e478-210f-42a9-86ea-a892cd6cfcd1
< 2.1.1
MEDIUM 6.4 The Internal Links Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Internal Title (ti… wordfence
050d0352-c0a5-41b0-bf40-914f6bf7cba4 MEDIUM 6.4 The Horizontal scroll image slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… wordfence
050301c3-3236-43d2-9ecc-4469697d4c05
< 3.2
MEDIUM 6.4 The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
04df6d4b-7beb-4347-9f88-a6cfaad389aa MEDIUM 6.4 The Zoomify embed for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
04d9c206-b40d-436a-93f3-bd7e3bb49892
< 1.9.0
MEDIUM 6.4 The Crypto Converter ⚑ Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's short… wordfence
04bec1c5-10a9-4093-b7dc-c40d3de87bfd MEDIUM 6.4 The Powerful Auto Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and incl… wordfence
04a6f9f1-1a59-482c-8a42-6f41e4c41cb4
< 1.7.22
MEDIUM 6.4 The CBX Bookmark & Favorite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and… wordfence
04a6a3f3-6aa3-4262-8e55-054b664d5bd4 MEDIUM 6.4 The WE – Client Logo Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
049efe5a-3f68-46ad-b73a-1892f03c9d1d MEDIUM 6.4 The Triton Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the them… wordfence
049ec60a-fa84-4c03-a766-7f2a56e5295a
< 2.26.1
MEDIUM 6.4 The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom name fie… wordfence
049657cf-9253-4a2d-a032-5f2f1d795eec MEDIUM 6.4 The WP Listings Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
048ea84c-0d53-434b-ae49-d804ec1de8c4
< 3.2.29
MEDIUM 6.4 The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'user-search' sho… wordfence
047aa84b-6e6a-4975-8a3f-3f8b4518704e
< 2.5.6
MEDIUM 6.4 The Slideshow SE plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5… wordfence
0458867f-c39e-4231-9ede-5ab1beb61878 MEDIUM 6.4 The Free Downloads EDD plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
04516d92-7f66-47b3-aeae-6752e03c1f95
< 3.7.5
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x befo… wordfence
044d7480-ccd7-4ce8-bb5d-367ba5d0217c
< 5.2.1
MEDIUM 6.4 The Alma – Pay in installments or later for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
044babea-8c04-4461-be53-80f2171da619
< 2.3.1
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordPress 2.3 allows remote attackers to inje… wordfence
0446af38-540d-4f3c-bffc-eeee0ef10a20 MEDIUM 6.4 The QuoteMedia Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
← Prev 749 750 751 752 753 754 755 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top