πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 754 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
034bb19b-1ee6-4ded-b907-a3f182745e67
< 3.6.8
MEDIUM 6.4 The WP Post Author plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3… wordfence
0346d69e-49f3-4269-9cae-733691a7d11d
< 1.1.3
MEDIUM 6.4 The Timeline Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
032861f0-9d94-4f6a-a119-eb0e09b20c5d
< 5.0.14
MEDIUM 6.4 The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored… wordfence
031995fb-48c4-4f56-8b64-d66a47b2fbe9
< 4.18.0
MEDIUM 6.4 The Sensei LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.17.… wordfence
0315150d-451b-4a78-8657-793cf901068c
< 7.5.20
MEDIUM 6.4 The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
030ec6bb-f19d-4145-b3fb-bd647c154666
< 2.0.34
MEDIUM 6.4 The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.33 du… wordfence
030d65bb-ec5b-4d26-8f59-5db9a9005ba6 MEDIUM 6.4 The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adi… wordfence
03075190-0312-43bb-9ea6-d8640eadb05b
< 3.1.9
MEDIUM 6.4 The Rey Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.8 d… wordfence
0306313b-5244-4303-8e98-1ae0570566a8
< 1.7
MEDIUM 6.4 The Penci Filter Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.7 due … wordfence
03056e70-77a2-47e9-b2b9-6cdda04ea2ca MEDIUM 6.4 The ESB Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
030534e2-bf7d-42e4-94a1-986f629bea15 MEDIUM 6.4 The WP Circliful plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of t… wordfence
02fceb91-7691-4629-b18b-57959e9f3f62
< 1.3.5
MEDIUM 6.4 The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonia… wordfence
02f957f6-2327-41e0-99f5-7a6893eeb614
< 2.1.3
MEDIUM 6.4 The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
02e8a576-bf00-4da9-9795-bd6b22bb0b19 MEDIUM 6.4 The Create Pinterest Pinboard Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜as_edit… wordfence
02e3f64c-1076-4247-9ee5-c1105edcfb39
< 3.8.2
MEDIUM 6.4 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulner… wordfence
02dd7f57-4379-4ea9-aced-67db6c8457d9
< 3.5.4.3
MEDIUM 6.4 The WP-Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.4… wordfence
02d4bc64-d05d-4151-bc38-523cbb2ef60c
< 1.2.2.1
MEDIUM 6.4 The Filr WordPress plugin before 1.2.2.1 does not have authorisation check in two of its AJAX actions, allowing them to … wordfence
02cffe63-dad2-4f6b-9530-7f494e3071d7
< 4.6.8
MEDIUM 6.4 The YouTube Playlist Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
02cff893-4f41-4bb0-9fb0-344a3a8afa0b MEDIUM 6.4 The Rotating Tweets (Twitter widget and shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
02cf711b-69af-4869-9ebd-31c657be1bc3
< 3.2.7
MEDIUM 6.4 The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to … wordfence
02ce06d6-f5f6-4add-9dcd-5fc35aabfe9a MEDIUM 6.4 The Builderall Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
02c9beba-dfa5-4a30-8355-62ff9a2630f7
< 5.7.0
MEDIUM 6.4 The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5… wordfence
02b9450e-422f-45f1-a55b-cf401e39247c MEDIUM 6.4 The Wish To Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all version… wordfence
02ad47d5-f011-4e0a-af29-088852d1e886
< 2.0.78
MEDIUM 6.4 The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Contact Info Block link parameter i… wordfence
029956d7-6e3f-4159-9f53-05691e0262fc
< 3.3.19
MEDIUM 6.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashbo… wordfence
← Prev 751 752 753 754 755 756 757 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top