πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 623 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7c2f0a6f-41cd-4dd2-a814-ad057e4e9fc0 MEDIUM 6.4 The Author WIP Progress Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
7c23bd29-ba02-4c90-a631-5ce6294d7760
< 3.11.10
MEDIUM 6.4 The Avada | Website Builder For WordPress & eCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
7c10be28-43ff-4b43-8186-6ad9a487321e
< 1.1.5
MEDIUM 6.4 The Ultimate 410 Gone Status Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 410 entries … wordfence
7c0d1fdb-b5a2-4a6b-a537-cacbb356dae4
< 5.6.3.1
MEDIUM 6.4 The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
7c08260c-872d-4607-a87a-feb85cde2d2e
< 1.3.4
MEDIUM 6.4 The Cost Calculator for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
7c030b62-1bee-4534-9e93-41e726ae43a6
< 5.5.3
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
7bf68565-ea30-4caf-8323-b0b88561e89f MEDIUM 6.4 The Exclusive Divi – Divi Preloader, Modules for Divi & Extra Theme plugin for WordPress is vulnerable to Stored Cross… wordfence
7becdab6-f952-4649-8cea-4efadf841619
< 4.0.2
MEDIUM 6.4 The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gu… wordfence
7bd057d5-5350-43c9-abfc-34d8f6537d2e
< 4.0.38
MEDIUM 6.4 The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress … wordfence
7bccc409-e16f-4c32-ad3b-743defd7200f
< 1.4
MEDIUM 6.4 The Inazo Advanced Ads Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜adds’ p… wordfence
7bc9627b-08ff-43cf-a528-5f1fd25cb729 MEDIUM 6.4 The Custom Post Type Attachment plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
7bc2eebb-d232-4aef-94e5-68876bba0f93 MEDIUM 6.4 The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' and 'href' pa… wordfence
7baa8cca-96a5-4d6b-86d5-53cd1a4675cf
< 2.6.13
MEDIUM 6.4 The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video Button an… wordfence
7ba9b813-c6eb-47da-9fc1-1992413fc9a3
< 2.3.1
MEDIUM 6.4 The WP Social Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
7b9aaafb-cb39-4a3b-85db-d0a8e9498d60
< 2.1.22
MEDIUM 6.4 The Author Avatars List/Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
7b7dee9e-1272-4e70-926c-a73e2897968c
< 2.2.1
MEDIUM 6.4 The CURCY – Multi Currency for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ve… wordfence
7b76ce38-d9ee-4998-ba3b-9f21158ce18a
< 2.1.5
MEDIUM 6.4 The WP Matterport Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'matterport' short… wordfence
7b712d9c-a1d0-422d-8a6e-76c298744838
< 3.27.1
MEDIUM 6.4 The Print My Blog plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.… wordfence
7b6b9da8-75bb-4a5d-8168-6272a6292903 MEDIUM 6.4 The wp_automatic_widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
7b473f26-8f78-4e07-acc6-65a638743163
< 1.2.12
MEDIUM 6.4 The Flex QR Code Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
7b1daf51-ae9d-4c02-8fb2-0c5f9e20b7c5 MEDIUM 6.4 The WP Microdata plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0… wordfence
7b168e3e-9d22-4318-9b71-c217733a8d28
< 2.2.0
MEDIUM 6.4 The Radius Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… wordfence
7b107c5d-ff82-4422-b201-39b745c2f412
< 2.0.1
MEDIUM 6.4 The Dr. Flex plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.0 d… wordfence
7af32d7b-3832-4192-bc31-b4ba1f419668
< 3.1.5
MEDIUM 6.4 Multiple cross-site scripting (XSS) vulnerabilities in the Classipress theme before 3.1.5 for WordPress allow remote att… wordfence
7ae34640-ce6a-4d87-9d75-d3a574d23a93 MEDIUM 6.4 The Nexa Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.… wordfence
← Prev 620 621 622 623 624 625 626 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top