πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 622 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7d45ab3c-0186-4feb-821d-24c37cb68ee5
< 1.1.2
MEDIUM 6.4 The JSFiddle Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'jsfiddle' sho… wordfence
7d32b2cc-9336-432e-9d2e-67db8b0e3f90 MEDIUM 6.4 The WP Blocks Hub plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions… wordfence
7d25e85f-28f7-4cc5-9856-25cc5aaf1418
< 4.3.4
MEDIUM 6.4 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress … wordfence
7d1ea1c5-6a9e-4b77-bfdf-62e50d4a4c03
< 4.6.3
MEDIUM 6.4 The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the fifu_input_… wordfence
7d0cb432-785a-4f38-830f-72b95e65aa5a
< 2.3.0
MEDIUM 6.4 The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clientId' block attribute… wordfence
7cff6946-3983-49ea-ab4f-22cf9fa149a4
< 3.6.8.1
MEDIUM 6.4 The JetSmartFilters plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
7cfab048-efc6-4c7c-a1bd-0a9daf8779bc
< 2.8.4.3
MEDIUM 6.4 The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
7ce6e40e-b090-447a-9bf9-6337d30e7da3
< 8.3.6
MEDIUM 6.4 The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜style’ a… wordfence
7ce1ae54-1011-4d8e-9329-ac72770c4386 MEDIUM 6.4 The NextGen Cooliris Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
7ccca628-9851-44d1-b4be-77c04e8b8de4
< 3.5.7.1
MEDIUM 6.4 The JetSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.7 … wordfence
7ccb7534-b588-4bdd-9627-0e38c0ee5e8a MEDIUM 6.4 The Pinterest Site Verification plugin using Meta Tag plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
7ccaee26-277e-4730-8242-9b5e6a281fcc
< 1.5.0
MEDIUM 6.4 The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Ima… wordfence
7cca8164-c0ce-4c10-aeb2-5ba7983e4e81
< 8.14.1
MEDIUM 6.4 The MapSVG – Vector maps, Image maps, Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
7c964abb-8b7b-4dc4-a64a-817d450eb3b9 MEDIUM 6.4 The DOP Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all v… wordfence
7c95bbba-6459-420f-a072-3b02c7d58ea0
< 2.8.11
MEDIUM 6.4 The Portfolio – WordPress Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multi… wordfence
7c959f9c-8ac4-4f59-9d93-8f96e650b02d
< 1.9
MEDIUM 6.4 The WP Category Dropdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' parameter in … wordfence
7c6db7a5-712e-4c6b-ac29-813f6e1b78d9
< 1.0.4
MEDIUM 6.4 The Elo Rating Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
7c67d2f8-d918-42ef-a301-27eed7fa41b2
< 3.2.98
MEDIUM 6.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packag… wordfence
7c66fdab-d067-4043-a602-9bbe94962a00
< 4.0.11
MEDIUM 6.4 The Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Tab' titles in all versions u… wordfence
7c666589-6a2b-4edd-bc28-1d609217584e MEDIUM 6.4 The Simple Nested Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
7c633419-e231-437f-a2af-6f564cffc2df
< 1.5.0
MEDIUM 6.4 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin… wordfence
7c5e400a-e578-4ec4-98b3-01bf45aac542 MEDIUM 6.4 The Raise The Money plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
7c54588f-6436-406f-93cb-b08965586d11
< 3.11.12
MEDIUM 6.4 The Avada Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all v… wordfence
7c4f9958-0e5a-483c-926e-ceaee00ffa45
< 2.0.22
MEDIUM 6.4 The Easy Accordion WordPress plugin before 2.0.22 does not properly sanitize inputs when adding new items to an accordio… wordfence
7c439193-cc7d-4e40-8585-87cb2c40fe9b MEDIUM 6.4 The Eventbee Ticketing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eventbeeticketw… wordfence
← Prev 619 620 621 622 623 624 625 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top