🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 621 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7e35e79a-4838-4ed9-bd08-80e8f9043ec4 MEDIUM 6.4 The EPay.bg Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'epay' shortcode… wordfence
7e342aac-2f32-48a6-8801-19c81af5a73a MEDIUM 6.4 The Simplish theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.4 du… wordfence
7e1d4080-cd8a-455a-85f4-87f195ebe4a2
< 26.6.3
MEDIUM 6.4 The Betheme theme for WordPress is vulnerable to authorization bypass that leads to stored Cross-Site Scripting in versi… wordfence
7e1bb306-c1a4-4b59-ad57-a9ca4500b049
< 1.10.29
MEDIUM 6.4 The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS. wordfence
7e1885be-dc9f-4858-a155-ad6fcc117d0d
< 2.4.28
MEDIUM 6.4 The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
7e033919-ca00-4789-8635-b4189e1499ef
< 1.0.15
MEDIUM 6.4 The NMR Strava activities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `strava_nmr… wordfence
7df85c11-6308-4b23-8c41-eea6bff5ca50
< 6.4.0
MEDIUM 6.4 The Easy Social Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in ve… wordfence
7def307b-5788-4cb4-82a4-517c5c9fe500
< 1.1.5
MEDIUM 6.4 The Easy Media Download plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the easy_media_download sh… wordfence
7de6415a-5236-46ec-ae2e-f4ec40c90f4d MEDIUM 6.4 The Ultimate Social Comments – Email Notification & Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
7de5cb89-240a-4ba3-a82c-261629620948
< 3.2.8
MEDIUM 6.4 The TemplatesNext ToolKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes … wordfence
7ddf167e-f436-4150-87e2-69c970952cd9 MEDIUM 6.4 The UX Flat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.4.0 du… wordfence
7dded505-8968-4ed2-8883-42a3ec50155c
< 4.0.2
MEDIUM 6.4 The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to St… wordfence
7dd6f9d2-e6c2-49fa-a4bb-1f2126809a06
< 4.0.0
MEDIUM 6.4 The Careerfy - Job Board WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Acade… wordfence
7da1c26e-39da-4d54-ac5f-03b4d6241a77 MEDIUM 6.4 The Brand my Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
7da00af0-edd1-4c39-ae33-a0dc21bd25a2
< 3.13.3
MEDIUM 6.4 The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'set… wordfence
7d9dc500-f7b5-418f-a6e3-116f844556d0 MEDIUM 6.4 The jQuery Colorbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… wordfence
7d9b5f4e-5d98-49b2-adbb-1db906b07c45
< 1.15.0
MEDIUM 6.4 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… wordfence
7d92790d-cc45-4507-b178-5f654383c90f MEDIUM 6.4 The Super Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
7d849eda-4c61-47e2-af7c-59a57fffab65
< 7.3.5
MEDIUM 6.4 The Quiz And Survey Master plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in v… wordfence
7d7a819a-97e6-444f-b48c-8fac9c405486 MEDIUM 6.4 The Elizaibots plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.2… wordfence
7d75851d-4dd5-4fb4-97bc-fc63575e483e
< 1.1.10
MEDIUM 6.4 The Kingcabs theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter … wordfence
7d692242-4779-449a-94a7-88e202aaefc2
< 3.1.7
MEDIUM 6.4 The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
7d68ada0-eddf-407e-95c6-5b9b0b52cd82 MEDIUM 6.4 The WoWHead Tooltips plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
7d61e6ea-4975-452a-8f9c-1c6d428372ac MEDIUM 6.4 The Simple Random Posts Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'container_r… wordfence
7d4c574f-f603-49eb-8d86-c98c060c1dfe
< 2.8.12
MEDIUM 6.4 The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
← Prev 618 619 620 621 622 623 624 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top