πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 624 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7ae31a9f-e5b2-46de-8e66-39dec7a73c57
< 2.6.0
MEDIUM 6.4 The Ultimate Store Kit Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
7ae0ce4b-743b-476d-93b3-bd5006f49c51 MEDIUM 6.4 The Powie's pLinks PagePeeker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
7ad70c32-ad98-4e67-a23c-3e61192b76f4
< 2.1.10
MEDIUM 6.4 The Nova Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.… wordfence
7ad6aaf4-7727-4b4a-920a-0d1754405163
< 4.1.0
MEDIUM 6.4 The Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider WordPress Plugin plugin for WordPress is vulnerabl… wordfence
7acb52d3-7bed-40fb-95dc-ad0bf262649b
< 6.0.5
MEDIUM 6.4 The WappPress – Create Mobile App for any WordPress site with our Mobile App Builder in just 1 minute plugin for WordP… wordfence
7ac2ac7a-4cb5-4051-bec7-a22693c50915
< 1.7.4
MEDIUM 6.4 The Minimal Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜align’ paramete… wordfence
7abb5103-7063-4a8d-8ca0-66074954acd5
< 1.4.17
MEDIUM 6.4 The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
7ab3e286-05db-430e-bbe7-bfaa31134c3c MEDIUM 6.4 The Elegant Addons for elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Swit… wordfence
7aa700ac-32de-4cd4-9d56-eea8ec0ba61b
< 1.4.3
MEDIUM 6.4 The Spotlight Social Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(… wordfence
7a98f7e9-3e50-41a1-9d53-29cafd3649eb
< 2.7.4.2
MEDIUM 6.4 The JetElements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
7a97f6f8-2226-4c63-965b-4dee58c254ad MEDIUM 6.4 The bVerse Convert plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
7a8c28d9-f290-4b08-b48c-beb560c63d2f
< 2.1.4
MEDIUM 6.4 The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPre… wordfence
7a74e4fb-15a9-4fc9-afa6-396b0f026615
< 11.16.9
MEDIUM 6.4 The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed… wordfence
7a74b09e-5cc0-4798-9f00-4a004b4ea3ae
< 20251118
MEDIUM 6.4 The Head Meta Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
7a6e361d-4a20-4c22-9003-84b2f2d94e2a
< 3.3.7
MEDIUM 6.4 The Ultimate Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
7a5ab5f1-db14-4448-9186-35a5f382cd1a
< 1.3.1
MEDIUM 6.4 The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p… wordfence
7a571386-fae1-4a56-8567-9d3e23249de1
< 7.6
MEDIUM 6.4 The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all v… wordfence
7a4ab215-c5ee-4841-858a-e5e8d3199fb2
< 3.1.2
MEDIUM 6.4 The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1… wordfence
7a49edd8-099d-4232-9cce-21932c44ae28
< 2.8.4.4
MEDIUM 6.4 The Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
7a341a7e-9ed2-436f-846a-59a5d51916fe MEDIUM 6.4 The Generic Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widget fields in ver… wordfence
7a32393e-f233-4ab6-addc-9dd1e04c0e0a
< 3.3.67
MEDIUM 6.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in… wordfence
7a30452a-9d7e-4312-87eb-56d9d1aeced3
< 1.5.3
MEDIUM 6.4 The Smartarget – Get 40% more sales, improve user engagement with 25+ free apps. plugin for WordPress is vulnerable to… wordfence
7a1ee5da-4e15-427a-96bc-0d1a015cdb17
< 1.6.0
MEDIUM 6.4 The Huurkalender WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
7a1b0440-743a-4c6f-aea5-bd46037dd149
< 3.29
MEDIUM 6.4 The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
7a189e25-0d9e-4e0c-b74d-e7f9d2556872 MEDIUM 6.4 The WP Glossary plugin for WordPress is vulnerable to Stored Cross-Site Scripting versions up to, and including, 3.1.2 d… wordfence
← Prev 621 622 623 624 625 626 627 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top