🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,373
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,373 vulnerabilities found (page 1078 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7cbc157b-4f1b-4212-9e5c-dd10dd443df7
< 2.8.0
MEDIUM 5.4 The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plug… wordfence
7c9b9ab3-ecfa-49d0-820f-4edb5abae9ee MEDIUM 5.4 The Image Hover Effects – Elementor Addon plugin for WordPress is vulnerable to unauthorized access due to a missing c… wordfence
7c89eb8e-bbd1-4c26-84ed-74456a6157a1 MEDIUM 5.4 The Oshine Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
7c6fe986-df68-4a62-9a43-5632c622b5fc
< 1.11.2
MEDIUM 5.4 The “Elementor Addon Elements” WordPress Plugin before 1.11.2 has several widgets that are vulnerable to stored Cros… wordfence
7c6b7dca-dd82-45b4-b9e2-0b44201396e9
< 2.5.1
MEDIUM 5.4 The GamiPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.0. … wordfence
7c632452-8b13-4f78-aa8a-3c92bef5907f
< 6.0.21
MEDIUM 5.4 The Image Map Pro plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a miss… wordfence
7bf1d6f9-afe2-41c2-968b-20dbc474cd73
< 4.4.6
MEDIUM 5.4 The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in va… wordfence
7bcbc6b6-ed05-4709-bf05-214418798339
< 2.8.4.3
MEDIUM 5.4 The WP Mobile Menu – The Mobile-Friendly Responsive Menu plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
7bb5a5a2-9644-4850-a5f9-7c925af000c8
< 5.1.5
MEDIUM 5.4 The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a miss… wordfence
7b6ac72f-11f4-46bd-a972-fbcb46b34ce6
< 2.4.10
MEDIUM 5.4 The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows … wordfence
7b3c77d8-0e90-41ee-b7e4-6160f1d5760f
< 1.5.5.5
MEDIUM 5.4 The “DeTheme Kit for Elementor” WordPress Plugin before 1.5.5.5 has a widget that is vulnerable to stored Cross-Site… wordfence
7b3446e5-ca01-4468-927a-86e951e662ab
< 4.0.6
MEDIUM 5.4 The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Server-Side Request Forgery in all vers… wordfence
7b24fe1d-1b21-4f8f-b66e-6df3bfc0e180
< 1.5.89
MEDIUM 5.4 The KB Support plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.… wordfence
7a931496-f130-4910-9116-6c2c4df760f5 MEDIUM 5.4 The My Shortcodes plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… wordfence
7a659071-df11-4318-86c2-7881163c8b62
< 5.2.4
MEDIUM 5.4 The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable … wordfence
7a4db03d-ec40-4145-aa95-fee78bda5205
< 1.1.4
MEDIUM 5.4 The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du… wordfence
79766bb2-a796-48b4-afb5-520303a73739
< 1.0.6
MEDIUM 5.4 The Product Configurator for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletions in versions up t… wordfence
797554c9-7008-451a-8e8d-3242a207347e
< 3.3.4
MEDIUM 5.4 The Load More Anything plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… wordfence
793082f8-5b5e-4973-819c-d2f11d1a596e
< 1.2.6
MEDIUM 5.4 The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lea… wordfence
791ae60d-f2b7-4a53-9008-35cd2d465124
< 1.7.46
MEDIUM 5.4 The AddToAny Share Buttons WordPress plugin before 1.7.46 does not sanitise its Sharing Header setting when outputting i… wordfence
78d8ddc9-69ad-4d69-ac23-5a31dfeafd54
< 1.5.108
MEDIUM 5.4 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cros… wordfence
78ca8110-fd39-4fcb-bac7-94732c14aee2
< 5.3.0
MEDIUM 5.4 The PixelYourSite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
78af6e06-4b4c-4f56-a6f8-f98e8f681976
< 7.3.0
MEDIUM 5.4 The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
788fdee8-2eae-437e-8a8d-1d01776cbe6b
< 0.9.1
MEDIUM 5.4 The Easyship WooCommerce Shipping Rates plugin for WordPress is vulnerable to unauthorized modification and deletion of … wordfence
787a19cf-a553-4aec-96c5-978956826756
< 9.13
MEDIUM 5.4 The WP Spell Check plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9.… wordfence
← Prev 1075 1076 1077 1078 1079 1080 1081 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top