🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 896 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7b70b152-eb65-4273-8063-37cfec7ecefb
< 2.0.4.6
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress al… wordfence
7b604ad0-6b26-4aed-9380-bda04a8f3d17 MEDIUM 6.1 The WP Course Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
7b41a6bd-8b0c-4d00-8cc3-9589fca5e406
< 2.4.5.2
MEDIUM 6.1 The Pz-LinkCard plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.4.5.1 due… wordfence
7b3e9ff7-c33b-4e47-8dfb-120577b815f2 MEDIUM 6.1 The Dot html,php,xml etc pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… wordfence
7b3d39be-83de-46e7-9eab-57c1e94ab59a
< 2.6.54
MEDIUM 6.1 The Like Button Rating ♥ LikeBtn plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
7b3ce7e7-c816-49d3-b794-91b71cb3e9c7
< 1.2.0
MEDIUM 6.1 Stripe Add-on for iThemes Exchange before 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). wordfence
7b19b0b2-d6cb-4d92-9925-c77d517ddfb7
< 3.10.2
MEDIUM 6.1 The rtMedia for WordPress, BuddyPress and bbPress Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v… wordfence
7b1771f2-6741-410d-9544-4178a0b962eb
< 0.7.19
MEDIUM 6.1 The Job Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.7.18 due … wordfence
7b0ff45d-0514-4090-bfa3-c3b75766ac61
< 3.8.2
MEDIUM 6.1 The Slash Admin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3… wordfence
7b0d5d92-1aba-4a0a-a989-a2d797112ade
< 2.0.25
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Polldaddy Polls & Ratings plugin before 2.0.25 for WordPress allows remo… wordfence
7b0b02ad-6ab6-47f3-9cf8-fd993a8051db
< 4.5.0.4
MEDIUM 6.1 The GEO my WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
7b00f5fd-80f2-4c54-8042-fed7fab9cf0f MEDIUM 6.1 The ACL Floating Cart for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions u… wordfence
7ae90bf5-3c3f-4da1-a09f-e10c65b88e68 MEDIUM 6.1 The Find Content IDs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… wordfence
7ae5b7b8-bafc-4979-85cd-a61fa654d21f
< 2.4
MEDIUM 6.1 The WP SuperBackup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
7ad6b011-ffe0-4548-b8e8-d03508960413
< 1.2.10
MEDIUM 6.1 The Alpine Photo Tile for Instagram plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘clie… wordfence
7ac251c8-4ade-4391-aedd-f48b13045a31 MEDIUM 6.1 Reflected XSS is possible in the GamePlan theme through 1.6.4 for WordPress because of insufficient input sanitization, … wordfence
7ac15c0d-74d3-4121-a63e-97dbbe594274
< 2.0.0
MEDIUM 6.1 The WP Docs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dir' parameter in versions up … wordfence
7abd382d-7cc0-4439-a1ff-6d1c99eeb871 MEDIUM 6.1 The Run Contests, Raffles, and Giveaways with ContestsWP plugin for WordPress is vulnerable to Reflected Cross-Site Scri… wordfence
7a970323-ddfd-4a86-a5eb-f8dae5dff294 MEDIUM 6.1 The eewee admin custom plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
7a914802-0cda-4038-8828-81fd74090801 MEDIUM 6.1 The LucidLMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.… wordfence
7a7d55fb-8874-4d3a-a880-521dbfd61611
< 3.1.3
MEDIUM 6.1 The WP-BusinessDirectory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
7a6c4945-68d3-4ce9-b00c-40591fa15ada
< 0.1.2
MEDIUM 6.1 The Custom Admin Page by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up… wordfence
7a5e3d82-4722-47ff-b66f-448cb2851c1f MEDIUM 6.1 The Tiempo.com plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in versions… wordfence
7a5a33fd-ecc6-40bf-93a5-10ead1c4c1f5
< 2.4.3
MEDIUM 6.1 The Feedify – Web Push Notifications plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pla… wordfence
7a48eaf5-2d31-4f56-9669-027741c2034b MEDIUM 6.1 The ADIF Log Search Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
← Prev 893 894 895 896 897 898 899 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top