🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 892 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7fd8277c-b096-4cee-bd13-fcb8c8b00ca0
< 4.8.1
MEDIUM 6.1 The wp-slimstat plugin before 4.8.1 for WordPress has XSS. wordfence
7fc6b0d0-a872-4491-894e-54258b062ab2
< 2.3
MEDIUM 6.1 The Bricks theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9.2 d… wordfence
7fb5496e-6d2a-467f-b4cc-8c9d61283462
< 1.2.18
MEDIUM 6.1 The Fast Flow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2… wordfence
7fa34f23-a319-46ec-baea-dd9753ccc5ba MEDIUM 6.1 The Cobwebo URL Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
7f9b9d94-92c8-477f-8b35-78cae2e07558 MEDIUM 6.1 The Pre Order Addon for WooCommerce – Advance Order/Backorder Plugin plugin for WordPress is vulnerable to Reflected C… wordfence
7f9b86a3-c68a-443f-a2f3-5f31f3280a6f
< 4.22.10
MEDIUM 6.1 The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad… wordfence
7f89ce1c-3f5e-43cb-9dd2-7ab5880d78d3 MEDIUM 6.1 The Advanced Image Sitemap WordPress plugin through 1.2 does not sanitise and escape the PHP_SELF PHP variable before ou… wordfence
7f73d0a6-2eae-4d85-96ce-db5902bd6e3a
< 2.0.2
MEDIUM 6.1 The WooCommerce Pre-Orders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
7f690ea9-b773-49d4-9fa4-2a8bb7593d62 MEDIUM 6.1 The Forms by CaptainForm plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘REQUEST_URI’ … wordfence
7f447d25-1a38-48fe-8079-5ff425382046
< 3.0.70
MEDIUM 6.1 The eCommerce Product Catalog plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ param… wordfence
7f33bc98-167d-4913-8de5-b80296955673
< 6.2.04
MEDIUM 6.1 The WP Live Chat Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in v… wordfence
7f2d3acb-5931-4629-8f03-4ab40fadf7c7
< 1.8.3
MEDIUM 6.1 The Kama SpamBlock plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST values in all version… wordfence
7f25f001-cbb7-4d73-b37d-47bc1681c690
< 1.2.5
MEDIUM 6.1 Multiple themes by gavias for WordPress are vulnerable to Reflected Cross-Site Scripting in various versions due to insu… wordfence
7f192811-378b-422d-8086-9a957b464bb7
< 0.20.5
MEDIUM 6.1 The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.20… wordfence
7f13a432-e37d-4183-85ff-e2a04b40cda8
< 2.1.7
MEDIUM 6.1 The WP Crowdfunding plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘postid’ parameter … wordfence
7f0458ad-fe21-43ac-ac8a-4ad0f3c957a8 MEDIUM 6.1 The Responsive Flickr Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
7efe0cd8-e8a0-43e8-b797-ddb690ba9e51 MEDIUM 6.1 The AdPush plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.50 d… wordfence
7eccbf15-db22-439b-a733-1ce9b991728f
< 8.5.5
MEDIUM 6.1 The WP eStore plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Customer Editing in all versions … wordfence
7ecc92c7-619d-442a-811f-4606e6d85d48 MEDIUM 6.1 The cSlider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.2. Th… wordfence
7ec15c74-5188-4769-ab16-98d9c85bb0c2 MEDIUM 6.1 The All In One Redirection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
7ebd4936-9d68-42cb-a427-a1db894b49ec
< 5.4.3
MEDIUM 6.1 The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
7eb8a509-9acd-457c-8cb9-725f615148ce MEDIUM 6.1 The Advanced Reorder Image Text Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … wordfence
7eae5d83-1443-4682-9e97-dfbc08146b18
< 1.2
MEDIUM 6.1 The DK White Label plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
7eaa196b-429a-4d15-903b-16f33cc0bd6f
< 1.8.30
MEDIUM 6.1 The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php. wordfence
7e577828-4368-4781-877b-badb4dc50763 MEDIUM 6.1 The Link Shield plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0… wordfence
← Prev 889 890 891 892 893 894 895 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top