πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 749 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
07bcf9e3-a38b-4003-be3a-f076293886dd MEDIUM 6.4 The Gallery and Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
07aafbe4-d2ac-4cc3-beb4-37e681ed5285
< 4.1.7
MEDIUM 6.4 The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file_modifie… wordfence
07a31d5c-b8c5-4523-8883-ba1e919c0ab1
< 3.2.62
MEDIUM 6.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, … wordfence
0788659e-be5b-413d-b4fb-d60df07075e1
< 3.7.19
MEDIUM 6.4 In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embe… wordfence
0782bc16-7d21-4205-af01-97e3ad3db40b
< 2.0.2
MEDIUM 6.4 The Contact Form 7 – Repeatable Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
0782046b-2475-4fda-be91-4866253bf1b7
< 1.0.5
MEDIUM 6.4 The Ultimate Flipbox Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
077a31e7-de4b-418f-ac90-5c51a690bc65
< 1.1.2
MEDIUM 6.4 The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw… wordfence
0778c676-92e6-4813-a564-06463fc84eec MEDIUM 6.4 The Gosign – Posts Slider Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'posts-slide… wordfence
07775638-270b-4424-8e2a-3ead1d752c88
< 1.9
MEDIUM 6.4 The WP-Force Images Download plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpfid' shortcode… wordfence
07729c28-a73a-46f4-853e-116792d612f5 MEDIUM 6.4 Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to … wordfence
075f328b-e854-4312-98d1-634acd6b1c22
< 1.18.4
MEDIUM 6.4 The Masteriyo - LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
075d6557-8fb4-4e69-924f-feff3d2827ed
< 1.1.28
MEDIUM 6.4 The Bradmax Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
0752b4f3-b9f0-4c39-8e4c-2db188600087
< 1.24
MEDIUM 6.4 The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
074d9712-9b26-47da-9e24-49854fd7257c MEDIUM 6.4 The ER Swiffy Insert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [swiffy] shortcode in all… wordfence
0745c9a7-3972-4089-81ae-835dfeb4dc48
< 2.6.0
MEDIUM 6.4 The Simple Google Calendar Outlook Events Block Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
074393ae-ff1e-4477-aaaa-24a6976dd2c2
< 3.1.47
MEDIUM 6.4 The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
0741bbf2-1098-41f4-a6d4-7e5c8f75f30b
< 1.0.12
MEDIUM 6.4 The WP Dashboard Notes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
07380092-6fe9-4f9e-ae13-3219e355dbd5 MEDIUM 6.4 The WP Github Gist plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0… wordfence
07361278-7abb-4d22-a8df-218d3f982483
< 2.6.4
MEDIUM 6.4 The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Title in all versions up… wordfence
0728b42b-5ec7-46a2-a9a5-3316107e9324
< 8.7.0.139
MEDIUM 6.4 The Bread & Butter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'breadbutter-customevent-bu… wordfence
07287a85-df00-408a-8b02-978fd3116155
< 2.21
MEDIUM 6.4 The Seraphinite Accelerator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and… wordfence
0725a122-9ad3-45bf-bf80-80881520634a
< 2.1.24
MEDIUM 6.4 The Author Avatars List/Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
07244763-3482-4cfb-8ae4-d19f312011aa MEDIUM 6.4 The Elfsight Telegram Chat CC plugin for WordPress is vulnerable to unauthorized modification of data to a missing capab… wordfence
0716485b-e94b-4e09-9c01-1059017bfcc8
< 1.2
MEDIUM 6.4 The Raisely Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's raisely_don… wordfence
070f6a8e-a06d-4f48-9703-933515a3098c MEDIUM 6.4 The Youtube Channel Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode… wordfence
← Prev 746 747 748 749 750 751 752 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top