πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1044 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4e94683d-2cf3-4e43-8ab0-f797bfaaeee4
< 1.16.11
MEDIUM 5.5 The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.16… wordfence
4e731110-473b-4f0c-8eb1-7b964a0f9aed MEDIUM 5.5 The Product Time Countdown for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… wordfence
4e51eb56-e2f7-433c-8db7-bcf7539aee29
< 0.20220219
MEDIUM 5.5 The Books & Papers WordPress plugin through 0.20210223 does not escape its Custom DB prefix settings, allowing high priv… wordfence
4e4f2725-6c93-40df-93ee-51997a4ad189
< 1.3.3
MEDIUM 5.5 The Social Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its settings paramete… wordfence
4e3e3bf4-7b95-4c0b-b660-d29796b643ed
< 3.14.2
MEDIUM 5.5 The Seriously Simple Podcasting plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to,… wordfence
4e0ad29a-b7a0-407e-8fb0-0917b8671afb
< 6.0.0
MEDIUM 5.5 The Actueel Financieel Nieuws – Denk Internet Solutions plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
4dcb4afc-14e1-43ce-87c4-8f24f1a0d682
< 2.7.4
MEDIUM 5.5 The Tutor LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.3 … wordfence
4dbba653-e23e-43e6-9dc5-83a6c99f8dc6
< 1.8.0
MEDIUM 5.5 The Zeno Font Resizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions u… wordfence
4d8d15be-6a7b-485e-a338-ccf1a6eb226c MEDIUM 5.5 The User Language Switch plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in… wordfence
4cf2af62-2b5a-4c0a-9e82-f80dde204a9d
< 3.0.8
MEDIUM 5.5 The Ninja Forms Webhooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in… wordfence
4c2a88c3-5c11-4b42-b8f8-aafecf6c4c74
< 4.9
MEDIUM 5.5 The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'single' module i… wordfence
4bd16698-2c44-4031-b8e0-f9d6e8feaff0 MEDIUM 5.5 The SEO Backlink Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in… wordfence
4baf9b27-a06e-412f-8227-6b418e709ff1
< 1.6.6
MEDIUM 5.5 The Page Generator plugin is vulnerable to Cross-Site Scripting in versions up to, and including, 1.6.4. This allows aut… wordfence
4ba416c5-47d6-4b05-8a31-af9137e04d2b
< 1.2.1.5
MEDIUM 5.5 The Codup WooCommerce Dynamic Pricing Table View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via s… wordfence
4ba3b414-82a0-4793-9702-cec64d92271e
< 1.12.2
MEDIUM 5.5 The WP-CommentNavi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the navi options 'pages_text', … wordfence
4b9741c6-4038-45ad-a7b4-fa8f65664f4a
< 2.1.8
MEDIUM 5.5 An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php form_f… wordfence
4a5262d8-d9cd-4bd9-a95e-f60782095173 MEDIUM 5.5 The Sticky Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜ popup_title' parameter in… wordfence
4939b053-2d62-428e-84ff-0de3416466ef
< 1.13.4
MEDIUM 5.5 The Login using WordPress Users (WP as SAML IDP) plugin by MiniOrange is vulnerable to Cross-Site Scripting in versions … wordfence
49023c6b-a236-42c1-ab24-072fa4a72967
< 1.3.3
MEDIUM 5.5 The Chained Quiz plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,… wordfence
4890ec6f-ba73-48bd-8dd7-f896d6b4a140
< 2.0.46
MEDIUM 5.5 The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several of the plugin's fo… wordfence
48758ada-4c7f-4a7f-8b43-535f820e6b3c
< 2.2.43
MEDIUM 5.5 The Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via parameter keys through accordion imp… wordfence
47f04985-dd9b-449f-8b4c-9811fe7e4a96
< 5.6.1
MEDIUM 5.5 The FileBird plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported folder titles in all version… wordfence
47a99115-3e7b-4666-a00e-2b94d7d62e1a
< 2.0.3
MEDIUM 5.5 The Seed Social plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Facebook App Id and App Secret… wordfence
472a98fe-9cce-4e9f-b353-ccc1389506fd
< 1.9.18
MEDIUM 5.5 Cross-site scripting (XSS) vulnerability in admin/manage-images.php in the NextCellent Gallery plugin before 1.19.18 for… wordfence
46ca2967-5b75-49f5-8b0c-1e9274423c93
< 1.2.13
MEDIUM 5.5 WP Subscribe versions up to 1.2.12 is vulnerable to Cross-Site Scripting. This allows authenticated attackers to inject … wordfence
← Prev 1041 1042 1043 1044 1045 1046 1047 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top