🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1079 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
79766bb2-a796-48b4-afb5-520303a73739
< 1.0.6
MEDIUM 5.4 The Product Configurator for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletions in versions up t… wordfence
797554c9-7008-451a-8e8d-3242a207347e
< 3.3.4
MEDIUM 5.4 The Load More Anything plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… wordfence
793082f8-5b5e-4973-819c-d2f11d1a596e
< 1.2.6
MEDIUM 5.4 The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lea… wordfence
791ae60d-f2b7-4a53-9008-35cd2d465124
< 1.7.46
MEDIUM 5.4 The AddToAny Share Buttons WordPress plugin before 1.7.46 does not sanitise its Sharing Header setting when outputting i… wordfence
78d8ddc9-69ad-4d69-ac23-5a31dfeafd54
< 1.5.108
MEDIUM 5.4 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cros… wordfence
78ca8110-fd39-4fcb-bac7-94732c14aee2
< 5.3.0
MEDIUM 5.4 The PixelYourSite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
78af6e06-4b4c-4f56-a6f8-f98e8f681976
< 7.3.0
MEDIUM 5.4 The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
788fdee8-2eae-437e-8a8d-1d01776cbe6b
< 0.9.1
MEDIUM 5.4 The Easyship WooCommerce Shipping Rates plugin for WordPress is vulnerable to unauthorized modification and deletion of … wordfence
787a19cf-a553-4aec-96c5-978956826756
< 9.13
MEDIUM 5.4 The WP Spell Check plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9.… wordfence
786d147b-2013-476b-a684-d070f07a166d
< 0.3.5
MEDIUM 5.4 The AnyComment plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 0.3.4. This is due … wordfence
77d8d29b-b730-46be-a354-7abfa83ac664
< 2.5.1
MEDIUM 5.4 The Simple Page Ordering plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability c… wordfence
774776dc-3780-496c-907a-0d1f86a5d0ac
< 1.99
MEDIUM 5.4 The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.98. Thi… wordfence
7717cd0f-6aac-4cb0-b27e-2517d5d7ecd9
< 1.7.0-0cde1c2
MEDIUM 5.4 The Worthy – VG WORT Integration für WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in ve… wordfence
7707ca04-e136-4d4b-869b-cd270359991e
< 2.0.6
MEDIUM 5.4 The “The Plus Addons for Elementor Page Builder Lite” WordPress Plugin before 2.0.6 has four widgets that are vulner… wordfence
7681a661-21bd-42fb-ac97-1da808435520
< 1.7.9
MEDIUM 5.4 The Qubely plugin for WordPress contains a missing authorization weakness that makes it possible for subscriber-level us… wordfence
766b0bde-c555-40c1-b174-20045bd89c11
< 3.2.38
MEDIUM 5.4 The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
7661d648-543e-46c8-a859-fb722a0c3fc2
< 3.10.5
MEDIUM 5.4 The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and Cross-Site R… wordfence
76516f23-487f-48f6-82c0-88df651ddc65
< 3.7.24
MEDIUM 5.4 wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from t… wordfence
75d5366e-2908-4b8d-9ee2-1f11e483add1
< 2.2.0
MEDIUM 5.4 The Elements Kit Lite and Elements Kit Pro WordPress Plugins before 2.2.0 have a number of widgets that are vulnerable t… wordfence
7566beda-649f-4dfc-860f-fb1c48809461 MEDIUM 5.4 The Word Search Puzzles game plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
75424878-5976-4dc6-8a09-8eb46a7425b8
< 2.1.7
MEDIUM 5.4 The plugin Mail Subscribe List for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in vers… wordfence
7534f2e5-a296-4c54-99e3-d84f5c9a5b51
< 4.16.4
MEDIUM 5.4 The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4… wordfence
74fac72d-6f16-475c-bc80-e77968dd23ad
< 4.0.1
MEDIUM 5.4 The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before s… wordfence
74fa5a77-3c66-4aa5-aa58-3e608e3cba70
< 4.4.0
MEDIUM 5.4 The Essential Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
74a280e1-e4b6-4bd9-882b-d9f185332d61 MEDIUM 5.4 The BadgeOS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions … wordfence
← Prev 1076 1077 1078 1079 1080 1081 1082 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top