πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 757 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
009b9b0d-6cbd-402e-bc81-24661ff16b9d
< 1.4.8
MEDIUM 6.4 The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
0088d9d8-0b29-481f-ba0b-ef05764d40c2
< 4.5.6
MEDIUM 6.4 The Social Sharing Plugin – Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ve… wordfence
00866e54-42b0-4947-a194-48b8d5cad027 MEDIUM 6.4 The Allmart plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.… wordfence
0084ec4e-1c10-4bfe-a7c6-155aa9a48dc1 MEDIUM 6.4 The Chess Tempo Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
00733c55-1071-4406-9ff3-d67b6411353a MEDIUM 6.4 The Stockholm Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
0064f4c0-ca94-4ce9-ba2f-e4a74b8b2fc2
< 2.7.15
MEDIUM 6.4 The Jobs for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
005fc05c-6d82-49ca-b114-a3e64a3a572f
< 4.10.37
MEDIUM 6.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Anim… wordfence
005bf2f0-892f-4248-afe3-263ae3d2ac54
< 7.6.19
MEDIUM 6.4 The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and i… wordfence
005b22a5-9899-4d67-8353-5322ed0b4ae6 MEDIUM 6.4 The Tabs For WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
0045c5a4-0807-4e89-8639-0802e54ce6ab
< 1.62.3
MEDIUM 6.4 The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid widge… wordfence
00376356-4a85-4898-a101-710e1cb5c6bb
< 3.3.1
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer… wordfence
00234d96-cece-4217-89c9-1a329887e8da MEDIUM 6.4 The WidgetShortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'widget' shortcode due to … wordfence
001b452e-3f8a-4605-b77a-ba8fbd0d79d7
< 1.7.3
MEDIUM 6.4 The ID-SK Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions… wordfence
00192a36-4b75-4dae-9a6e-0afb02ed5bad
< 6.1.15
MEDIUM 6.4 The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI Form Builder module in all… wordfence
00145a6b-26fd-4cba-a446-8236438075d8 MEDIUM 6.4 The PhotoFade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'time' parameter in all versions… wordfence
00107941-effc-4540-aa52-9e9725a417d6 MEDIUM 6.4 The MyBookTable Bookstore plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
000bf956-1781-4596-ac12-81691fdd789c
< 1.6.4
MEDIUM 6.4 The PWA β€” easy way to Progressive Web App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG Fi… wordfence
fcc0fc00-b7d6-429c-9ab3-f08971c48777
< 8.2.4
MEDIUM 6.3 The Media Library Folders plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on … wordfence
fb6f4b0b-25b8-4dcd-b002-293ce8ab307e
< 1.10.0
MEDIUM 6.3 The NitroPack – Cache & Speed Optimization for Core Web Vitals, Defer CSS & JavaScript, Lazy load Images plugin for Wo… wordfence
fb147a5d-65ad-4304-b13a-670f11398e63
< 1.4.5
MEDIUM 6.3 The WPS Cleaner plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.4.4. This… wordfence
fa0a296a-a93f-4c0e-9911-b4f9bdd53fad
< 1.7.15
MEDIUM 6.3 The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and… wordfence
f9337519-0b33-43fa-9be4-2390b8b3afb9
< 5.1.8
MEDIUM 6.3 The ProfileGrid plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 5.1.6, via the 'pm… wordfence
f8f27037-5dd6-467e-b633-494f30ec8b7a
< 2.0.19
MEDIUM 6.3 Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for Wor… wordfence
f7d66176-73a8-4076-8ae0-1f1fd8260f8e
< 3.7.21
MEDIUM 6.3 In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API. wordfence
f63d494c-1d1e-4faa-930a-3fcf2b136182
< 0.47
MEDIUM 6.3 The WP FEvents Book plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of… wordfence
← Prev 754 755 756 757 758 759 760 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top