πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1310 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7b848b66-1dcd-4357-b472-4b7a27d2682f
< 0.9.9
MEDIUM 4.4 The POEditor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,… wordfence
7b56c684-90f6-4e8b-86fc-355a13b5368c MEDIUM 4.4 The Mendeley plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and… wordfence
7b3d68d9-fa82-4be3-8692-39a9dc216d17
< 1.2.1
MEDIUM 4.4 The Profile Box Shortcode And Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setting… wordfence
7b3954c0-294d-42d2-93af-35853d6b09c2 MEDIUM 4.4 The Contact Form 7 Star Rating plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all ver… wordfence
7ae14765-ba85-4aba-83ae-41f7de2f2551
< 2.8.1
MEDIUM 4.4 The Login rebuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up … wordfence
7ad4272c-75a1-4bc9-be3b-add80de45871
< 9.1.3
MEDIUM 4.4 The WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.1.… wordfence
7abf84ff-15e6-4fde-ae7d-23283ec83a28
< 1.3.33
MEDIUM 4.4 The HTML Forms – Simple WordPress Forms Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a… wordfence
7ab15669-92f6-4e85-bfa5-684e82f341ea MEDIUM 4.4 The WPCS ( WordPress Custom Search ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setting… wordfence
7aa05744-59c7-43ca-acb3-e6df09fa109b
< 2.3.8
MEDIUM 4.4 The month name translation benaceur plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings… wordfence
7a4cc65b-b0a7-4002-add4-ceacfe2f54f1 MEDIUM 4.4 The WPlyr Media Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_wplyr_accent_color' pa… wordfence
7a45ec93-8e0b-4765-9883-12aae42fdeef MEDIUM 4.4 The YaDisk Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… wordfence
7a14d35d-144c-4ddd-b288-5e0e006fb165 MEDIUM 4.4 The Custom New User Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's admi… wordfence
79e20ca1-9325-43af-b5c6-a66a7a15605a
< 1.34.0
MEDIUM 4.4 The FiboSearch – Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers… wordfence
79cce1fc-a27f-4842-b1a2-2c53857add4c
< 3.7.8
MEDIUM 4.4 The Ultimate Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions … wordfence
79c296b1-e385-404d-96c0-a98f10b89f08
< 2.6.3
MEDIUM 4.4 The Password Protected plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions … wordfence
79ae6c3e-5584-448b-a5c5-0a105377b81d
< 6.4.10
MEDIUM 4.4 The Admin Columns Pro plugin for WordPress is vulnerable to CSV Injection via the export functionality in all versions u… wordfence
797840ba-5589-42d6-9d50-52bf8c131d6e
< 1.0.97
MEDIUM 4.4 The Conditional cart fee / Extra charge rule for WooCommerce extra fees plugin for WordPress is vulnerable to Stored Cro… wordfence
79287545-77db-4c55-85cd-57dfd3fd4420 MEDIUM 4.4 The Badgearoo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to… wordfence
7922de94-986c-47c1-ab95-284734ef85d1 MEDIUM 4.4 The Meteor Slides plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
78f4709b-0560-48c6-a26c-d806311758a3 MEDIUM 4.4 The Annual Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … wordfence
78dc41f0-117e-44f6-b387-283353b1e8cc
< 1.1.5
MEDIUM 4.4 The Cards for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜[parameter nam… wordfence
78b79a03-f2d0-42bb-a6e9-298c6cdd2ffa
< 1.5.6
MEDIUM 4.4 The Better Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions… wordfence
78a464e0-f2d9-4916-aa93-d52a98757a91
< 2.1.2
MEDIUM 4.4 The Bug Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
783829c2-fe09-44a1-bbb5-2a694ad816ee
< 1.1.5
MEDIUM 4.4 The Easy Panorama plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to… wordfence
7827df3d-10ba-4bf1-aecb-fdf3f6f36ea6 MEDIUM 4.4 The Custom Comment plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
← Prev 1307 1308 1309 1310 1311 1312 1313 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top