πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 625 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7a1240b7-e476-4834-aaae-36aa826eb725
< 2.1.7
MEDIUM 6.4 The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
7a0b5585-1182-4f82-8b9e-11df39136199 MEDIUM 6.4 The Plenigo plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.12.0 d… wordfence
7a0a281d-840f-488f-b9ef-c0df8514b47c
< 28.0.4
MEDIUM 6.4 The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button shortcode and Custo… wordfence
79ed2c2b-5d76-4202-ac8a-d1813a57dcec MEDIUM 6.4 The WPAchievements Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
79de2a90-225a-4d3e-b511-d12ede2cface
< 3.10.5
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
79d96a6c-6191-44d8-aab8-f01bb2692767
< 1.1.8.8
MEDIUM 6.4 The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
79d4e5a8-028a-488e-b419-77a0981a28a9
< 1.0.5
MEDIUM 6.4 The WP Remote Site Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s… wordfence
79a91fd1-305e-4307-84fa-53a557bacef6 MEDIUM 6.4 The FlexIDX Home Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
7990f4f3-838c-4112-8958-2b2dd8fe54d5
< 1.4.1.1
MEDIUM 6.4 The Anima theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, <=1.4.1 due… wordfence
79896a39-eada-4136-a820-47e93b4595f1
< 2.2.6
MEDIUM 6.4 The WPAdverts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.5 … wordfence
797ec6dc-bced-48d0-b39f-4ad640b697fe
< 3.0.3
MEDIUM 6.4 The LeadConnector plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.… wordfence
797768b3-5e4b-4f6e-8c5b-3513eace447d
< 2.5.5.3
MEDIUM 6.4 The Beaver Builder – WordPress Page Builder for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Image … wordfence
79752ac3-cb5f-4d86-be58-c4b892e4edd6
< 5.0.3
MEDIUM 6.4 The Advanced Accordion Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File up… wordfence
79705897-77d7-409d-bf04-c1e3742c92a7
< 2.0.8
MEDIUM 6.4 The Gutena Kit – Gutenberg Blocks and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in v… wordfence
796fd9a1-6599-4319-8d3e-aa962c6875ff MEDIUM 6.4 The Mobile Kiosk plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3… wordfence
796c37bb-0ff2-4f13-b752-71319adcbc61
< 5.6.4
MEDIUM 6.4 The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
7957f5e8-a3ee-452f-969e-169544773d51
< 3.1.13
MEDIUM 6.4 The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.1… wordfence
7943c21b-dfc3-4f31-a636-0a1a745628bf
< 1.5.1
MEDIUM 6.4 The Structured Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in … wordfence
7941a6d3-9785-4dcb-ac56-17d4611f5201 MEDIUM 6.4 The Gallery Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
79337804-beff-4316-98b3-aacb8416eb52
< 4.0.0
MEDIUM 6.4 The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.… wordfence
792fa6cb-e55a-4f68-b8a8-9039fb1ff694
< 2.4.0
MEDIUM 6.4 The Gutenverse Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all version… wordfence
79147dad-4bce-40fb-b9c1-e211845251a0 MEDIUM 6.4 The Simple News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'news' shortcode in a… wordfence
7911c774-3fb0-4d6c-a847-101e5ad8637a
< 4.14.4
MEDIUM 6.4 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
790d6336-0c16-4058-9ddb-d182ef56263c
< 0.5
MEDIUM 6.4 The muse.ai video embedding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's muse-ai s… wordfence
790bd89d-3913-4b43-9b00-7d4de5c4227d
< 2.2.0
MEDIUM 6.4 The Progress Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wppb' shortcode in versions … wordfence
← Prev 622 623 624 625 626 627 628 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top