ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 577 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a7d13d78-4d3f-476a-ba67-b47d0195a1ed
< 1.3.8
MEDIUM 6.4 The WishSuite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.7 … wordfence
a7c949f0-fcd1-4984-95a2-b19fb72f04bb
< 9.1.1
MEDIUM 6.4 The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of the 'tag' attribute… wordfence
a7c19095-3c21-440f-aa28-0117aea29d97 MEDIUM 6.4 The Newsletter & Bulk Email Sender plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
a7b370e1-0b6f-49bd-89ec-794f0a404c31 MEDIUM 6.4 The Pricer Ninja plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1… wordfence
a7a877d3-69b2-427b-9b5c-fb3ca93b4c09
< 1.3
MEDIUM 6.4 The Audio Player with Playlist Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
a7a53ba2-e983-4821-b3de-105a96b7cb0e
< 6.0.0
MEDIUM 6.4 The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
a7967b44-a3a1-48e5-a873-527348e2a88a
< 1.3.9.7
MEDIUM 6.4 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
a78c2621-afff-40b4-ae45-831b2b847756
< 2.1.2
MEDIUM 6.4 The Master Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ma_el_bh_tabl… wordfence
a780ce1b-0758-42ef-88e7-ff8d921eca6e
< 1.6.26.1
MEDIUM 6.4 The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the size att… wordfence
a777c79e-a3ff-4f9d-90da-3a67a0176584
< 1.3.6
MEDIUM 6.4 The Black Widgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
a770ab37-127a-4018-9ffa-1b326d5a016e MEDIUM 6.4 The Hide Email Address plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inline_css' parameter … wordfence
a767f65e-bc7d-4576-af78-b77bd23dc089
< 6.4.8
MEDIUM 6.4 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
a763da69-47d2-4aad-842b-ce12f62af179 MEDIUM 6.4 The Nepali Post Date plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
a75f030b-8678-4de0-ae72-42a7d1eed456
< 0.8
MEDIUM 6.4 The BeerXML Shortcode plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu… wordfence
a748da73-9489-46f7-baf0-8c4ccc847dcf
< 2024.0.0
MEDIUM 6.4 The Swift Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in a… wordfence
a739b805-e631-461e-802f-196e4117d403
< 6.3.15
MEDIUM 6.4 The WP Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgmza_store_locator_que… wordfence
a720b38c-37f0-4edf-9868-de3a105551ee
< 1.7.1018
MEDIUM 6.4 The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
a71e72dd-574c-41fc-a000-7a4cf658f3d7
< 3.8.9
MEDIUM 6.4 The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builde… wordfence
a71cbe66-4187-4260-bb87-8579bc6e75f5
< 2.4.5
MEDIUM 6.4 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
a717fea9-088c-4b65-9624-a1ba66028f4e
< 4.13
MEDIUM 6.4 The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.12… wordfence
a713d897-c549-4e0d-9cb3-7002ef2b127f
< 4.3.3
MEDIUM 6.4 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress … wordfence
a7131704-4803-492a-aae7-17a8ab33282f
< 2.1.18
MEDIUM 6.4 The Booking Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
a7041a2a-24d0-46c4-bf0d-f0447dac8c4b MEDIUM 6.4 The Meta Store Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
a7021586-16e8-41d2-8337-b700ce0b2d1d
< 1.6.6
MEDIUM 6.4 The CM Popup Plugin for WordPress – Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
a6eed2c5-43e8-40b6-814f-ddf5967d52bc
< 3.5.16.1
MEDIUM 6.4 The JetSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.16… wordfence
← Prev 574 575 576 577 578 579 580 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top