πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 894 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7d90dad3-d7ef-4060-8328-fd551cee92e2
< 3.8.2
MEDIUM 6.1 The Custom 404 Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜page’ parameter in … wordfence
7d8bee60-33f8-465b-80a9-90bc7a4d2054
< 1.3.18
MEDIUM 6.1 The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input. wordfence
7d770e25-3b76-49a1-896b-adbdd91d1e47
< 3.5
MEDIUM 6.1 The Configure SMTP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all … wordfence
7d623840-30d1-4599-a52d-08c28e190699 MEDIUM 6.1 The WhatsApp πŸš€ click to chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'manycontac… wordfence
7d567665-543c-4a6b-bb07-9388fea09ee9
< 0.6.9
MEDIUM 6.1 The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
7d563826-5b84-4fc9-a6e5-d6d1562de09b
< 1.9.1
MEDIUM 6.1 The Client Power Tools Portal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
7d546f05-4aad-49c8-aefd-9f5d10529be5
< 7.95
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Vide… wordfence
7d3c44eb-ef25-43f5-a872-6ef52c3d9c1f
< 2.7.3
MEDIUM 6.1 The Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin for WordPre… wordfence
7d30adc5-27a5-4549-84fc-b930f27f03e5
< 5.1.1
MEDIUM 6.1 The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. Th… wordfence
7d262a3b-6205-45b3-8d8e-da541e07de46 MEDIUM 6.1 The Same but Different – Related Posts by Taxonomy plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
7d0bc838-3653-408d-8be3-b9d910b30f67 MEDIUM 6.1 The WP Discord Post plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
7cfbaa87-1af7-4f5d-820b-1f2194765121 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in facture.php in the WPCB plugin 2.4.8 and earlier for WordPress allows remote… wordfence
7cf3e557-5964-4a76-920f-1936d2225437 MEDIUM 6.1 The Custom Field Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
7cf28b29-6e09-4359-9fe9-739d46fa5c2d
< 2.1.6
MEDIUM 6.1 The Stars SMTP Mailer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
7ce8ae7d-c2a5-4da3-8bdd-20dfdb5ce700 MEDIUM 6.1 The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
7ce32ecf-6995-4794-8559-2f84533ecf50
< 1.7
MEDIUM 6.1 The GD Security Headers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via error message in versio… wordfence
7cd8ea73-81f3-41fe-bb1e-403d2645ff39
< 1.7
MEDIUM 6.1 The shibboleth_login_form function in shibboleth.php in the Shibboleth plugin before 1.7 for WordPress is prone to an XS… wordfence
7cce2f9f-5f47-4e10-a846-0aab4bcad616 MEDIUM 6.1 The Donations Made Easy – Smart Donations plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in vers… wordfence
7cc7ec8b-4480-4422-8831-97f20a5d8d67
< 6.9.5
MEDIUM 6.1 The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitise and escape the wpcargo_tracking_number paramet… wordfence
7cb95ee1-5c21-407f-aa8c-c3ec1c97015a MEDIUM 6.1 The WoWPth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.… wordfence
7cb81956-856a-49cc-a437-a2094d958b5d
< 1.2.4
MEDIUM 6.1 The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not properly sanitise the keyword_search, searc… wordfence
7cb428db-b56b-4c21-b119-ca7a1a95181e
< 8.8.3
MEDIUM 6.1 The BackupBuddy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting several parameters in versions up t… wordfence
7ca83efe-298c-4ce9-a726-dbe76607aebf
< 2.9
MEDIUM 6.1 The SEO Redirection Plugin – 301 Redirect Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
7c9820d1-e9f6-4875-842f-9d6565273515
< 2.0.0
MEDIUM 6.1 The Blue Captcha plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
7c911773-79f5-4d91-b0f9-a05bc17516b2 MEDIUM 6.1 The Event Easy Calendar plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up… wordfence
← Prev 891 892 893 894 895 896 897 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top