ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 895 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7c8529fc-9995-45c5-ad21-c960eb796fb3
< 1.3.2
MEDIUM 6.1 The WP Post Styling plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
7c80c04a-5637-45f3-b875-5cc6c56ba40d MEDIUM 6.1 The StatPressCN plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
7c781c8a-1ffb-438b-bf78-9d386fbd16eb
< 2.4.18
MEDIUM 6.1 The Quick License Manager – WooCommerce Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi… wordfence
7c77259a-cdf3-4fa0-b468-9e98645293fe
< 1.5.3
MEDIUM 6.1 The WPFactory Helper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the item_slug parameter in… wordfence
7c6e233f-c612-4625-8097-0637e976190d
< 2.0.9
MEDIUM 6.1 The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter … wordfence
7c63bb98-5bfb-471f-a612-cc7634cd6dc5 MEDIUM 6.1 The iXML – Google XML sitemap generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '… wordfence
7c562a8f-e2c7-4452-ae15-fab369933712 MEDIUM 6.1 The CtyGrid Hyp3rL0cal Search WordPress Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in a… wordfence
7c4797a6-43c1-4183-95ec-4e150a1d774a MEDIUM 6.1 wordfence
7c4787ea-dc40-4eeb-a827-1fddb4ad1055
< 1.3.7
MEDIUM 6.1 The FormFacade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
7c3726fa-e3ee-4c5d-a727-b33d0d077ef1
< 1.5.12
MEDIUM 6.1 Reflected XSS in wordpress plugin infusionsoft v1.5.11 via the 'ContactId' parameter. wordfence
7c307d66-11f9-4593-9ada-252d034fd421
< 1.3.2
MEDIUM 6.1 The Quotes and Tips by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘categ… wordfence
7c248e3d-b6b2-4064-9006-3ddd85079308 MEDIUM 6.1 The Apply with LinkedIn buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
7c0ed22d-6102-47d6-9afb-fed8515ea74c MEDIUM 6.1 The MapMap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. T… wordfence
7c0a6e1a-1cf1-438f-ba6b-63202c392b3c MEDIUM 6.1 The CBX Accounting & Bookkeeping plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up… wordfence
7be669db-eb70-4cdd-9705-cb68781254e0
< 2025r3
MEDIUM 6.1 The Store Locator Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
7be3688d-61f5-457d-a38b-0560205b2f8d MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in wp-1pluginjquery.php in the ZooEffect plugin 1.11 and before for WordPress a… wordfence
7be214ef-8111-435a-9191-d4b8389972ff
< 1.0.27
MEDIUM 6.1 The GoodBarber plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.0.26. This is… wordfence
7bd931a9-18ec-48fa-9382-d4c2d99258c5
< 8.18
MEDIUM 6.1 The Impreza – WordPress Website and WooCommerce Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scr… wordfence
7bacf821-d993-4ece-960c-ceadacd19fce MEDIUM 6.1 The Dyn Business Panel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and incl… wordfence
7bacae6f-d23d-414c-8d8a-0f1702eafd84
< 1.9.4
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in js/tabletools/zeroclipboard.swf in the WP-Table Reloaded module before 1.9.4… wordfence
7bab6db1-771b-4459-a8c9-d4a9d1bc9394 MEDIUM 6.1 The Shipmozo Courier Tracking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
7b9dea34-d500-4b52-b020-1e278151cb44 MEDIUM 6.1 The Multiple Admin Emails plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
7b8ea76e-1519-4b6a-b73e-af95cc3d1fcb MEDIUM 6.1 The BU Section Editing plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
7b86a774-a420-41a8-85ad-44fe8b32d4c2
< 1.8.3
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remot… wordfence
7b795352-fad8-485e-bd1b-68c0913555e2
< 7.5.3.727
MEDIUM 6.1 The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parame… wordfence
← Prev 892 893 894 895 896 897 898 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top