🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 619 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7fa5206e-8888-4872-b4bd-91fe5628498c MEDIUM 6.4 The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `… wordfence
7f9b1ed9-fdbf-4096-b355-9798a3f5c5ba MEDIUM 6.4 The SocialMark – Easy Watermark/Logo on Social Media Post Link Share Preview plugin for WordPress is vulnerable to Ser… wordfence
7f99af65-c283-4da4-8912-9a3e15d9c46d MEDIUM 6.4 The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
7f96a16e-0ae5-421e-b3d3-7299a5f99e1d
< 4.4.4
MEDIUM 6.4 The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Server-… wordfence
7f8e836e-c9af-4614-83b2-c15e77d51155
< 0.9
MEDIUM 6.4 The WordPrezi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions … wordfence
7f86a85c-fe40-4020-b4d2-623dabac98a2 MEDIUM 6.4 The Fan Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all vers… wordfence
7f86568f-dcdd-44fb-905a-9c5474f56515
< 3.6.6
MEDIUM 6.4 The affiliate-toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's atkp_product sh… wordfence
7f7827bb-44d7-432d-85aa-3fdb117e1898
< 2.10.0.6
MEDIUM 6.4 The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
7f716cbb-a8be-4e32-a7ce-0b393a89b32e
< 1.2.11
MEDIUM 6.4 The WPZOOM Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
7f708c72-7ce2-4eb0-869b-cec4613f6f3f
< 1.3.8
MEDIUM 6.4 The WP Posts Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play_timeout’ … wordfence
7f5d8eac-fca9-4222-9a5f-a12748d298ec MEDIUM 6.4 The Smart Icons For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in … wordfence
7f51ae93-6880-4dc8-b183-424a8407f441
< 4.1.5
MEDIUM 6.4 The Livefyre Comments 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘site_id’ and ‘s… wordfence
7f4c9a5b-93ec-4979-921a-91134cb09566
< 2.8.9
MEDIUM 6.4 The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in … wordfence
7f42ce13-9dca-4d99-baae-ec2b6f2e82e4
< 5.7.7
MEDIUM 6.4 The Eduma theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.7.6 due t… wordfence
7f3b13a5-0711-4ad3-b11c-f8556e1ca9f9
< 1.3.5
MEDIUM 6.4 The Events Listing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Event URL' paramete… wordfence
7f34f4a6-9092-4e67-8a1e-7c60edde0b2a
< 1.7.7
MEDIUM 6.4 The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu… wordfence
7f2dcf48-168d-4ae9-834c-8d0adf2f8f71
< 5.10.2
MEDIUM 6.4 The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.10.… wordfence
7f2bd1b0-c130-4317-a159-abcb4af290e7
< 0.3
MEDIUM 6.4 The WP Responsive Auto Fit Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
7f197721-d7d6-49db-8cdc-0162c0c2960b
< 1.7.1053
MEDIUM 6.4 The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Stored C… wordfence
7f0be29a-7896-4166-a2a6-64f99d845236
< 1.4
MEDIUM 6.4 The Sitekit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sitekit_iframe' shortcode attribu… wordfence
7f051566-ac84-4ab6-b0ce-4dbcafc09d67
< 4.1.3
MEDIUM 6.4 The "Easy Social Box / Page Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's s… wordfence
7ef79c77-53e7-439d-985a-786eb73c44eb
< 2.7.1.1
MEDIUM 6.4 The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
7ef6f598-e1a7-4036-9485-1aad0416349a
< 3.0.0
MEDIUM 6.4 The WP MapIt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_mapit' shortcode in … wordfence
7ef37e72-f98f-4df6-8adb-514690350a82
< 21.3.1
MEDIUM 6.4 The Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordP… wordfence
7eee591c-2676-479c-ab15-96da10f51ae0 MEDIUM 6.4 The Click To Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includin… wordfence
← Prev 616 617 618 619 620 621 622 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top