πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 756 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
017eeb19-d4e3-4def-b640-1656ab1cb8e5 MEDIUM 6.4 The Local Search SEO Contact Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
01785582-3568-4dfc-ae50-1ab92dbdcb8f MEDIUM 6.4 The Custom Dashboard Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
016462cf-abe9-4c90-abd2-b5bb69348d7e
< 1.15.5
MEDIUM 6.4 The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Bookmark URL field in all vers… wordfence
0149ae49-5d40-4431-9612-04182afce2ec
< 1.5.127
MEDIUM 6.4 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cros… wordfence
0144ae03-00ce-481d-8d29-7a484f1f6cbf MEDIUM 6.4 The WP AD Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'startindex' parameter of th… wordfence
01391c72-6829-4c17-af0b-597965ee9fca
< 1.1.6
MEDIUM 6.4 The Colorbox Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
013661c3-66f3-46df-af63-801e159abbd2 MEDIUM 6.4 The Effect Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2… wordfence
012946d4-82ce-48b9-9b9a-1fc49846dca6
< 2.3.2
MEDIUM 6.4 The VK Filter Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vk_filter_searc… wordfence
01280afb-4745-4f36-823e-ed794bb3353a
< 2.1.1
MEDIUM 6.4 The Surbma | Booking.com Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `s… wordfence
011c8a06-298e-4a53-9ef8-552585426d79
< 1.5
MEDIUM 6.4 The Sitekit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sitekit_iframe' shortcode in versions… wordfence
011acdd3-8185-4288-968b-aa7cf33e3018 MEDIUM 6.4 The Skyword API Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
0119b7c3-0e5b-4448-98fc-662695012532
< 8.5.1
MEDIUM 6.4 The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
0114a028-42ef-4668-815f-d62494565116
< 6.4.12
MEDIUM 6.4 The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for W… wordfence
01142e56-ac59-40bc-b401-bbaf12c3a351
< 1.2.8
MEDIUM 6.4 The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
00f7a207-2dc0-4322-a23d-7cd2eb10c21e
< 1.7.13
MEDIUM 6.4 The Web Directory Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
00f5cf90-cc63-4e51-b1be-1152abefc59d MEDIUM 6.4 The Responsive Video Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rem_video' shor… wordfence
00d5c081-d703-4195-aa92-204624d72203
< 5.7
MEDIUM 6.4 The XStore Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 5.7 due to insuffici… wordfence
00d46496-4ca0-4297-a276-a40f91d50555
< 1.6.5
MEDIUM 6.4 The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.4 … wordfence
00b60b53-77bf-4640-bf2b-84e011014623
< 3.2.0
MEDIUM 6.4 The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
00b278af-6ce6-4e70-a83a-a1b035542cd4
< 3.3.0
MEDIUM 6.4 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Compari… wordfence
00b1b289-1b14-4e97-a9de-1132d0eea06f MEDIUM 6.4 The GNA Search Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
00a7768f-5fd6-49ff-bcd6-e44dd59ae8d9
< 6.3.2
MEDIUM 6.4 The Photo Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.3… wordfence
00a456bc-c795-41cd-a19e-906b6d5b2339 MEDIUM 6.4 The Parallax Scrolling Enllax.js plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
00a3d8e3-17b1-488b-9c42-2479932c9bf7
< 4.6.11
MEDIUM 6.4 The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortco… wordfence
009e5f43-19e0-4110-890e-1df715f51a84 MEDIUM 6.4 The WP Link Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includi… wordfence
← Prev 753 754 755 756 757 758 759 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top