πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 620 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7ee97559-fee4-48e5-8255-0044cdf8fa8e
< 1.9.3
MEDIUM 6.4 The aBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.2 du… wordfence
7ee8f9d3-a8c4-443c-a297-27559142bb8e
< 2.2.4
MEDIUM 6.4 The Progress Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2… wordfence
7ee73abf-0ab8-48ab-bd94-18ed66f877fd
< 1.6.7
MEDIUM 6.4 The Formzu WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜id’ parameter in versions u… wordfence
7ee3d1ed-5d75-4539-bb1b-bfd3518043df MEDIUM 6.4 The Awesome WordPress Timeline Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions … wordfence
7edfff03-1fa5-4aa8-b93f-33b9d4241538
< 2.8.162
MEDIUM 6.4 The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable t… wordfence
7edc150f-5c38-4bb7-a65c-44a91c24325a
< 1.0.9
MEDIUM 6.4 The Calendar.online / Kalender.digital plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
7ece53a2-cbad-4ff8-baad-0e4ec14ecbee
< 45.11.0
MEDIUM 6.4 The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
7ec6b03c-e594-4b20-9da0-78413048ba70
< 5.6.1
MEDIUM 6.4 The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Regi… wordfence
7ec29589-b524-4b67-af60-982cd78b81c5
< 1.2.15
MEDIUM 6.4 The Astra Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
7ec1d883-147f-4a15-89ab-bd9c41893589
< 2.8.3
MEDIUM 6.4 The Automation By Autonami plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
7eb78b64-ebe3-44e9-9061-d380693c5566
< 1.15.0
MEDIUM 6.4 The CMSMasters Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in… wordfence
7eb60874-85c1-40a9-b19d-131c2c2d49ba
< 1.5.0
MEDIUM 6.4 The Posts per Cat [Unmaintained plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ppc'… wordfence
7eb0b413-d165-4b4f-9eda-49df664f0473
< 1.3.1
MEDIUM 6.4 The Themify Portfolio Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
7ea6079f-45a1-438f-890f-36457b7468ec MEDIUM 6.4 The Tuxquote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'TUXQUOTE' shortcode in versions … wordfence
7ea2bb8c-cc8b-49de-9c8e-2c8c0569f4ac
< 3.2.38
MEDIUM 6.4 The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-… wordfence
7e9f7670-fcde-4e6f-a0c1-f7eb43b320ba MEDIUM 6.4 The Rig Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
7e9b004a-2050-47e8-ac4d-491b715c87d2 MEDIUM 6.4 The Zenon Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜url’ parameter within the t… wordfence
7e97d9dd-7d4a-4862-abba-6e8816bbbe9b
< 0.45
MEDIUM 6.4 The Crisp plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.44 due t… wordfence
7e977be1-d346-4fcc-89a5-332cbd010d18
< 1.3
MEDIUM 6.4 The Download Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s)… wordfence
7e904ec1-c389-4e4c-9893-385f3482034e
< 1.5.5
MEDIUM 6.4 The Spiraclethemes Site Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
7e870ae2-abae-457a-b3d1-75a96ec09d41
< 2.1.8
MEDIUM 6.4 The Shoutcast Icecast HTML5 Radio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
7e7e6ea7-4e0b-4d8a-9306-45b55d41fbb5
< 1.27
MEDIUM 6.4 The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the cust… wordfence
7e7a289f-39ef-4961-bd08-34e6a7dfdac5
< 4.7.2.1
MEDIUM 6.4 The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
7e6b24a2-55ed-40e7-bcf0-a9ceb8ea022c
< 4.8.0
MEDIUM 6.4 The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
7e501592-4411-4c0a-aa67-e2d0a29d5d35
< 2.0
MEDIUM 6.4 The User Location and IP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in… wordfence
← Prev 617 618 619 620 621 622 623 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top