🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 893 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7e392355-ff56-47c3-a836-04ef8ae84602
< 2.3.0
MEDIUM 6.1 The Kapost plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.9.… wordfence
7e391830-ca46-4aa2-b31d-0a1985e138e5 MEDIUM 6.1 The Super Interactive Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
7e3069d4-12b8-4949-9daf-0e01590799da
< 2.3.3
MEDIUM 6.1 The WP Inventory Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramete… wordfence
7e1ec075-5971-46e3-ba2c-e01ab30a1767 MEDIUM 6.1 The Track Page Scroll plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
7e1cdaf3-76fe-4b73-b30b-4554f0d34d11
< 3.16
MEDIUM 6.1 The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the lang parameter … wordfence
7e19a144-55b9-4a32-b2d6-cb70be241d10 MEDIUM 6.1 The CK and SyntaxHighlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
7e0f903a-e882-4de9-953a-c377b591004e
< 0.1.5
MEDIUM 6.1 The Help Center by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 0.… wordfence
7e0cbef8-223a-44c0-a07f-28de2670da99
< 0.8.9
MEDIUM 6.1 The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the type parameter in all… wordfence
7e0b9dd4-d882-4f56-9f6b-2f2955690a05 MEDIUM 6.1 The Bonuspressx plugin for WordPress is vulnerable to Cross-Site Scripting via the 'n' parameter in the 'ar_submit.php' … wordfence
7e0abbd5-fe2d-49b5-9a7e-859ea3a64496 MEDIUM 6.1 The CMC MIGRATE plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
7dff9b5f-def3-420b-a28f-e0d225747c52
< 6.4.3
MEDIUM 6.1 The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Open Redirect in version 6.4.2. This is due… wordfence
7dfcc252-1da3-4504-9b63-75bbd6a9765a MEDIUM 6.1 The WP DeskLite – Helpdesk and Support Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in … wordfence
7df7f541-b8aa-46fa-bfca-b333beea27f9 MEDIUM 6.1 The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all version… wordfence
7df2996f-bc0e-4608-a80e-6167ac26469a
< 5.8.3
MEDIUM 6.1 The Premium Packages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
7df1901f-fb18-4d1b-ac80-38b676efb64f
< 1.3.0
MEDIUM 6.1 The Donate Me plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2… wordfence
7ddd27ba-ae65-4bb4-989d-0d677e15077a
< 4.7.2
MEDIUM 6.1 The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
7dd95956-d86b-4198-a3b9-d5d9308f36dd MEDIUM 6.1 The Cryptocurrency Pricing list and Ticker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … wordfence
7dcd0c5a-757d-4256-ac0a-36620914bc45 MEDIUM 6.1 The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.p… wordfence
7dc9c0ed-a77c-4ad8-8e6e-75c1a2998fe6
< 1.6.1
MEDIUM 6.1 The Slideshow Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘order’ parameter… wordfence
7dc9973a-4b5f-4efb-8df5-df1cbf9fe3b0
< 1.0.2
MEDIUM 6.1 The EZ Portfolio (Unmaintained) plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in ver… wordfence
7dc267d5-ecea-4732-b716-dfaf63167b81 MEDIUM 6.1 The Claptastic Clap! Button plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in version… wordfence
7dbd3b23-cebc-4212-bcae-c6f23031c040
< 21.1.2.1
MEDIUM 6.1 The Contest Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in ver… wordfence
7dbca642-c7ee-4c43-b8b5-99784a6f58f1 MEDIUM 6.1 The Content Manager Light plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
7dbb6c21-8a70-44b9-9915-3f146a2066ce
< 1.01
MEDIUM 6.1 Reflected XSS in wordpress plugin heat-trackr v1.0 via id parameter. wordfence
7da41c7c-31c4-4e95-ac5a-25bd17e507b9 MEDIUM 6.1 The Pingmeter Uptime Monitoring plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wpnonce' … wordfence
← Prev 890 891 892 893 894 895 896 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top