πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1309 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7fab176c-d9fc-4114-8ee5-25be4b8571b6
< 1.2.2
MEDIUM 4.4 The AffiliateWP – External Referral Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… wordfence
7f97af51-1532-4034-8b2a-8356b65cb617
< 4.2.2
MEDIUM 4.4 The Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to… wordfence
7f6f1c16-afd6-4c69-8988-70c6c0105748
< 3.0.4.2
MEDIUM 4.4 The Everest Forms – Build Contact Forms, Surveys, Polls, Quizzes, Newsletter & Application Forms, and Many More with E… wordfence
7f52cbb4-8fe3-4402-8ece-261d32329a42
< 2.6.99
MEDIUM 4.4 The Smart Forms – when you need more than just a contact form plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
7f49477f-7a43-489b-8d3c-db8d0efeb596
< 1.3.3
MEDIUM 4.4 The Cancel order request WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setting… wordfence
7ef23b03-8452-4730-860c-2c2ef1686202
< 2.6
MEDIUM 4.4 The Namaste! LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accept_other_payment_methods… wordfence
7eb4b190-5b4f-4950-b8ec-381c94c7f0cd MEDIUM 4.4 The Skitter Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
7eb37504-a3b0-4e95-b66f-d9a1683c6a0e
< 6.0.6
MEDIUM 4.4 The Webba Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.… wordfence
7e8745da-fd3a-44b3-b288-9a2b83e8dcd8
< 2.69.1
MEDIUM 4.4 The WP-EMail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and… wordfence
7e52a487-8e87-49b7-a044-9fb8452f3dd1
< 8.6.6
MEDIUM 4.4 The Contact Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title’ parameter in all… wordfence
7e2014bd-2809-4f79-913d-d7a35eda63ef
< 4.5.5
MEDIUM 4.4 The Publish to Schedule plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
7d98034d-e91e-4f37-8309-621555fcf309
< 2.2.2
MEDIUM 4.4 The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
7d2f30e7-75f2-40c2-a421-aec13d436efc
< 15.3
MEDIUM 4.4 The WP Content Copy Protection & No Right Click (PRO) plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
7d249bc4-1230-4d85-8b29-e00a9cb80434
< 2.0.26
MEDIUM 4.4 The Beds24 Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
7d11b2db-d097-433f-923c-f49ef2951c0e MEDIUM 4.4 The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
7cdfba69-c232-4387-aa7e-961e70cef378 MEDIUM 4.4 The Smart Related Products plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
7cd412d8-6d14-4803-aae6-087e02f9d75f
< 6.15
MEDIUM 4.4 The MembershipWorks – Membership, Events & Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
7cc618c8-63a9-4321-ad18-ee5277a5f5e0
< 1.5.0
MEDIUM 4.4 The SMTP2GO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜[function_or_param]’ paramete… wordfence
7caa4c73-cf57-4f99-8bc6-6fd02308a58f
< 1.0.12
MEDIUM 4.4 The Reservation.Studio widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ve… wordfence
7c8faa22-ff1f-4267-b690-a2c51c4807f5
< 2.5.3
MEDIUM 4.4 The Advanced Cron Manager – debug & control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admi… wordfence
7c44efe0-bdc0-42e0-9bdd-cf25bff1d2d5
< 1.6.18
MEDIUM 4.4 The weForms – Easy Drag & Drop Contact Form Builder For WordPress plugin for WordPress is vulnerable to Stored Cross-S… wordfence
7c1811f7-0fb4-4f50-93ac-6abd9e6a1d66 MEDIUM 4.4 The Smart External Link Click Monitor [Link Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad… wordfence
7c07098d-8d7c-4a7f-b58c-b0daf2f56e1e
< 2.17.1
MEDIUM 4.4 The Issues and Series for Newspapers, Magazines, Publishers, Writers plugin for WordPress is vulnerable to Stored Cross-… wordfence
7bffb16d-38dc-49b8-96bd-c13923069d9c
< 4.3.0
MEDIUM 4.4 The Call for Price for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings … wordfence
7bbc181f-318e-48ea-a2f7-c668ad15c8a6 MEDIUM 4.4 The Eyes Only: User Access Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setting… wordfence
← Prev 1306 1307 1308 1309 1310 1311 1312 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top