🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 626 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
79091bc0-d9b6-4a4b-926d-0447193d27c5 MEDIUM 6.4 The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cro… wordfence
78fd9dcf-228e-46ec-b34f-2cb0c87cc895
< 2.4
MEDIUM 6.4 The Guest Author plugin for WordPress is vulnerable to Stored Cross-Site Scripting via author name in versions up to, an… wordfence
78f745f9-c44e-4458-9381-f639c842a31e
< 14.0.0
MEDIUM 6.4 Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPress plugin) <= 13.1.0.… wordfence
78f6d878-6ba8-4d80-9c9b-1a363d6aaed5
< 1.31
MEDIUM 6.4 The Simple Blog Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in ver… wordfence
78f43693-ff83-48d6-827d-6d521eb8e89c
< 3.1.32
MEDIUM 6.4 The Icegram Engage – Ultimate WP Popup Builder, Lead Generation, Optins, and CTA plugin for WordPress is vulnerable to… wordfence
78eeef12-123b-42f6-b446-c3f2d43153fd MEDIUM 6.4 The jQuery T(-) Countdown Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tmin… wordfence
78e9beef-4d2b-4004-8db7-4963882e405b
< 8.4
MEDIUM 6.4 The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widg… wordfence
78e49869-5e7e-45f2-8239-4df18b28db53
< 1.12.4
MEDIUM 6.4 The Advanced WordPress Backgrounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘imageTag… wordfence
78e35c10-2480-4b23-8f5c-a196ccdc71f2 MEDIUM 6.4 The Gallery Images Ape plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
78dae5be-a71b-45bc-8814-7cc86233ae90
< 4.0.0
MEDIUM 6.4 The Divi Torque Lite – Divi Theme and Extra Theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… wordfence
78da1f88-2446-4ea5-9437-a118324ab6c2
< 2.2.1
MEDIUM 6.4 The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
78d63e8d-447e-462a-bdce-7824d6db4101 MEDIUM 6.4 The Responsive jQuery Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
78cb078e-a3ce-42e7-a2e3-b85f5343a0d0 MEDIUM 6.4 The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
78c6b9c0-c503-4486-8102-92dbd34ad9c9 MEDIUM 6.4 The Alpha Price Table For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
78c2d5fc-240a-4fed-92ae-b9f84de3e119
< 0.1.11
MEDIUM 6.4 The Uptodown APK Download Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'utd… wordfence
78b7d99a-d521-4491-a168-df7c2cb4f285 MEDIUM 6.4 The OS Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
78b60dca-0225-43c8-b6cf-0213b1619b65
< 1.9.6
MEDIUM 6.4 The PJ News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in al… wordfence
78b444a2-e5d7-4c3a-86a4-c215c54687a2
< 3.7.1
MEDIUM 6.4 The Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Tabl… wordfence
78b24567-c185-4bef-b025-016b091be2e4
< 3.5.3
MEDIUM 6.4 The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem… wordfence
78a8feac-70f5-4593-a855-da66d3c7d6b6
< 3.2.2
MEDIUM 6.4 The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
789497b1-36cf-4de2-bca0-52c0c2a08f72
< 2.02
MEDIUM 6.4 The BBSpoiler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions u… wordfence
7892842f-88d0-404e-ba1d-47239f4a4b66 MEDIUM 6.4 The Faltu Testimonial Rotator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
7891b657-a6bc-40e8-bf43-02b4c05d63a9
< 2.0.6
MEDIUM 6.4 The Ultimate Store Kit Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
78912210-50d3-41fd-9d79-61b09b54ac78 MEDIUM 6.4 The Media Modal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.… wordfence
788c94a7-a8d6-4ae3-b4ca-f5c60e536f57 MEDIUM 6.4 The Easy Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wqt-question' sh… wordfence
← Prev 623 624 625 626 627 628 629 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top