πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 627 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7888aedb-5421-4c3a-8459-d6177b398a06 MEDIUM 6.4 The Simple Responsive Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, an… wordfence
787ab3f0-c8c4-46cd-bfbe-ac1ca508898a
< 2.0.4
MEDIUM 6.4 The Better Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes (such… wordfence
7879aaad-37b2-410d-9b21-029bed47202c MEDIUM 6.4 The Media Library Alt Text Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bv… wordfence
78797c97-a5b8-4d2d-acd2-ebd508f2f836 MEDIUM 6.4 The iFlyChat – WordPress Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
78760d4d-04fc-4a6c-8c0d-6bf897335651
< 2.1.1
MEDIUM 6.4 A CSV Injection vulnerability was discovered in Flamingo up to version 2.1. It allows a user with low level privileges t… wordfence
786e16be-dee9-43de-afe3-dcc0d17bc92b
< 1.3.27
MEDIUM 6.4 The All Bootstrap Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Accordion" widget in… wordfence
78579ed9-1540-44be-9884-51fc2afec2bd
< 6.13.0
MEDIUM 6.4 The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in … wordfence
78526fa8-31f8-4618-8064-60baa2cd5615
< 2.24
MEDIUM 6.4 The PlayerJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.23 du… wordfence
7834c0be-3051-4d97-928e-cf5295c93463
< 1.7.4
MEDIUM 6.4 The Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode plugin for WordPress i… wordfence
7830b3dc-7d20-4516-b4d6-57636ca773e9
< 2.34.4
MEDIUM 6.4 The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Paramet… wordfence
782fcee6-0892-4454-be1f-384df653fb6e
< 3.6
MEDIUM 6.4 The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
7826a6ab-50c4-4fc0-b58d-74084172b4e5 MEDIUM 6.4 The Media Alt Renamer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜_wp_attachment_image_… wordfence
781ead7a-f6d3-4fa8-b9aa-fd089e5cfd2b
< 1.6.1
MEDIUM 6.4 The Make Column Clickable Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
781987af-3753-46ec-9d56-fb8b6ef42277
< 1.3.5
MEDIUM 6.4 The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading wi… wordfence
7813dfdc-06e0-4fa9-aabe-b5b9772368c2
< 2.1.12
MEDIUM 6.4 The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcf_donate short… wordfence
7812dd30-2896-45a7-8920-92ea061f4da3
< 2.16.4
MEDIUM 6.4 The Elements Plus! plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includin… wordfence
77ff128b-952b-43a3-a57a-f274491ac022
< 1.4.4
MEDIUM 6.4 The My Favorites plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4… wordfence
77e43062-1a3d-4db1-aeac-4d7505d18730 MEDIUM 6.4 The SVGPlus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versi… wordfence
77c4515f-bab7-4bb9-bbf6-ca0ee557055d
< 2.3.1
MEDIUM 6.4 The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
77bed6ce-84e7-4b71-8acd-bb5b73e362d2 MEDIUM 6.4 The Email Obfuscate Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email-… wordfence
779ecd51-16d6-4799-aad7-372c5d5f2884
< 3.4.2
MEDIUM 6.4 The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is… wordfence
779e7bd1-c02c-4eaa-b85f-3df87baa9783
< 14.2
MEDIUM 6.4 The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
779ccc74-757d-4741-af82-53f8988ef9e0 MEDIUM 6.4 The Amazing Hover Effects plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
77911b0f-c028-49ae-b85e-15909d806e30 MEDIUM 6.4 The WhatsApp Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'whatsapp' … wordfence
7790777d-9421-48c6-b789-f1feab109ec7
< 6.0.4
MEDIUM 6.4 The Modal Window plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.0… wordfence
← Prev 624 625 626 627 628 629 630 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top