πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 755 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0297cdfa-0798-417b-ba49-119669df329d
< 1.18.0
MEDIUM 6.4 The ParOne Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1… wordfence
0293f989-a5fa-46e3-896e-84f58c4e171e MEDIUM 6.4 The WP Responsive Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
02737f71-7ea6-4ce7-87e8-3988e3759f00
< 1.2.9
MEDIUM 6.4 The Gutenberg Blocks – Unlimited blocks For Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
026b72f5-b650-4d48-8564-450a22ea7784 MEDIUM 6.4 The Top Flash Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
024af9de-d4c7-43ec-a602-c45ded3ddad3
< 4.11.9
MEDIUM 6.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-countdow… wordfence
024a6a0f-f819-40e7-9618-71219c27aa64 MEDIUM 6.4 The Zypento Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table of Contents block in … wordfence
0241a9fc-ce42-4a97-9f33-f07cf53c0f52
< 2.10.32
MEDIUM 6.4 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Type … wordfence
02396b9d-5b13-48ad-b44a-da8eeb059514 MEDIUM 6.4 The Easy Magazine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
02103a32-4fac-401a-b995-e86dd734484b
< 3.5.25
MEDIUM 6.4 The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User Contact… wordfence
020d14f8-e8e2-4da2-9a4b-4d15cb0994c8
< 3.1.10
MEDIUM 6.4 The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
02073716-4f6a-4a51-933f-c5ab8dfbc08c
< 3.2.18
MEDIUM 6.4 The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2… wordfence
020052ba-dece-4e70-88e7-8bd8918b8376
< 2.10.33
MEDIUM 6.4 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Registration Form w… wordfence
01ebc1b1-2dd3-4e91-93b2-fc8e5e93e925
< 3.7.25
MEDIUM 6.4 WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement). wordfence
01cf3196-1817-4506-8f70-ca54cc5e09f9 MEDIUM 6.4 The Workable Api plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's workable_jobs shortc… wordfence
01cd05c3-9629-4da4-ae9d-f99003253b95
< 3.6.5
MEDIUM 6.4 The Block, Suspend, Report for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lin… wordfence
01ccc7b8-3dd4-4b83-bd53-687f7479b214
< 1.1.8
MEDIUM 6.4 The MAS Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions… wordfence
01b1ebc8-e489-4053-9dbf-511cd83270d6
< 3.5.27
MEDIUM 6.4 The WPFunnels plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.26… wordfence
01a6dcf2-6f0b-494b-a18c-04bd9c44e0ce
< 3.1.44
MEDIUM 6.4 The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerabl… wordfence
01a6cca8-cca9-4863-a879-20fdca23b334
< 4.3.2.2
MEDIUM 6.4 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
019f85c8-e52b-40f7-8930-a2ddff0aaf97
< 1.5.3
MEDIUM 6.4 The Advanced FAQ Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
019c5e06-1345-4c8e-abb9-dc0ea5d55ef5 MEDIUM 6.4 The Ideal Interactive Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
0191e5b0-b669-439b-8ad4-9f860e6ee637
< 3.5.1.14
MEDIUM 6.4 The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in ve… wordfence
0189d8cf-237f-4b5b-89f7-6346455d35a9 MEDIUM 6.4 The G Meta Keywords plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
0184b2b5-0b50-407e-8911-b0845714ea17
< 3.3.54
MEDIUM 6.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
0183625a-611c-4353-9d2a-7a25ae12709a MEDIUM 6.4 The Silesia theme for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜link’ attribute within the the… wordfence
← Prev 752 753 754 755 756 757 758 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top