πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 753 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0441bedd-4608-4347-9542-d70c21fdbc32
< 2.1.20.1
MEDIUM 6.4 The JetWooBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
043d64ed-78dd-442e-87c9-92b5b64260b8
< 3.7.21
MEDIUM 6.4 In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files,… wordfence
04325ba9-73d1-403a-a0be-fbb9eb3aaff9
< 1.0.3
MEDIUM 6.4 The CodePen Embedded Pens Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
042b0d01-f9bc-4726-a41d-6849aea0f7e0
< 1.7.4
MEDIUM 6.4 The Additional Custom Product Tabs for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
0420c558-b6d0-4f95-9f78-869efab46089 MEDIUM 6.4 The ImbaChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.4 d… wordfence
041c21fb-f2f0-45cb-b3ae-20f3ae22c947 MEDIUM 6.4 The WP Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up… wordfence
041a7c9a-d7dc-4742-b879-f1836f324a46
< 3.1.1
MEDIUM 6.4 The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPres… wordfence
04057d0b-f831-4629-af74-393bb77689e3 MEDIUM 6.4 The Login Logout Register Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
03fba6bb-ff30-42bb-936b-93c009a7e3f7
< 2.5.1
MEDIUM 6.4 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
03fa3a62-c5b7-4772-b8fe-26ae476b4ae4
< 2.16
MEDIUM 6.4 The Advanced Woo Labels plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
03e6fa1d-0d6a-43e9-97ff-da874a51474a
< 4.7.7
MEDIUM 6.4 The ProfileGrid – User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Si… wordfence
03e23a91-530b-44c6-be54-04cbf35a8cda
< 1.4.12
MEDIUM 6.4 The Custom Layouts – Post + Product grids made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
03d5c82e-f82f-4156-bb3e-e6eb365a6c36
< 3.7.4
MEDIUM 6.4 The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `… wordfence
03d05c74-da50-4175-86f5-f39a89dbffd4
< 1.54.0
MEDIUM 6.4 The VK Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post functionality in versions u… wordfence
03c9e4c4-c680-474e-b172-d34d3eba2183
< 6.6.0
MEDIUM 6.4 The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attribute(s) i… wordfence
03c76e61-f263-459f-8618-7565225467e8
< 1.3.7
MEDIUM 6.4 The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… wordfence
03b37c90-4bb5-4003-a440-3fb57a5c1cae
< 2.3.1
MEDIUM 6.4 The ShareThis Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sharethi… wordfence
03a64a72-6643-4747-a916-000197cc2794
< 4.6.1.1
MEDIUM 6.4 The All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic plugin for WordPress… wordfence
039a9e3d-0e88-4eae-9537-58682aaf7b10
< 1.4.6.6
MEDIUM 6.4 The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
03956922-988a-4cb6-bf20-51878a5b1555
< 1.5.12
MEDIUM 6.4 The Hammas Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'apix' parameter in the 'h… wordfence
037ff4f5-7855-43e8-af25-9a0fcd5f0b64
< 1.6.2
MEDIUM 6.4 The WordPress Social Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortco… wordfence
037882e8-4d66-47b9-8ca5-3fa3866b9125
< 6.6
MEDIUM 6.4 The ND Shortcodes plugin for WordPress is vulnerable to stored Cross-Site Scripting via multiple shortcodes. This makes … wordfence
03721b29-7b26-4166-bba1-81614b412a09
< 7.7.7
MEDIUM 6.4 The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module … wordfence
03564cae-df90-454b-8379-6ad9f22b7389
< 1.3.5
MEDIUM 6.4 The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Box … wordfence
034d3d52-cb77-40dd-85a1-81ca3bfd1f23
< 1.1.3
MEDIUM 6.4 The LegalWeb Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'legalweb-popup' s… wordfence
← Prev 750 751 752 753 754 755 756 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top