πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1087 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4edf2487-00e3-422b-ae9d-21a790b69133
< 3.6.0
MEDIUM 5.4 The Trustpilot Reviews plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
4ea4ca00-185b-4f5d-9c5c-f81ba4edad05
< 1.11.8
MEDIUM 5.4 The Easy Google Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
4e944a08-b6c1-456f-921a-501ab4b59f31
< 5.0
MEDIUM 5.4 The phpinfo() WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.… wordfence
4e8ad3c1-549b-4401-8cf4-a8b7f81fbc11
< 7.6.4
MEDIUM 5.4 The wpDiscuz plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check o… wordfence
4e8822cd-5ced-42d5-907e-72066d8fb835
< 2.9.9
MEDIUM 5.4 The Elementor Website Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user … wordfence
4e7f310e-1e10-44dd-9928-23e63af21fef
< 1.9.10.69
MEDIUM 5.4 The Better Messages plugin for WordPress is vulnerable to Authorization Bypass resulting in a block bypass on messaging … wordfence
4e704333-ad88-42c9-b632-babc9d54cb13
< 5.0.6
MEDIUM 5.4 The Dynamic Visibility for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a mi… wordfence
4e361a98-94c5-4775-a306-b343997e1cde
< 3.10.5
MEDIUM 5.4 The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_… wordfence
4e343489-4969-4a16-9741-34de93c8b06e
< 3.1.5
MEDIUM 5.4 The ShareThis Dashboard plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on … wordfence
4dfa825c-b0f7-4588-9bf8-cd186a5fc0ff MEDIUM 5.4 The 3D Tag Cloud plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
4dcf1133-d437-4f0a-b2cf-c91e0f6b6ca9
< 2.4.4
MEDIUM 5.4 The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' p… wordfence
4d7b8570-96d2-46dc-983c-3933c3fd74cb
< 1.2.2
MEDIUM 5.4 The Group Documents plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.2.1 via the… wordfence
4d64253b-5803-470d-81ba-d5629406b019
< 1.2.70.4
MEDIUM 5.4 The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerabl… wordfence
4d425843-a68e-40fd-93de-04c1c46af88f
< 4.4.0
MEDIUM 5.4 The WP OAuth Server (OAuth Authentication) plugin for WordPress is vulnerable to Open Redirect in all versions up to, an… wordfence
4c20db2d-f73d-4e52-a275-ab1975ae4b17
< 1.2.5
MEDIUM 5.4 The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.4… wordfence
4c1203ce-7582-447f-b011-905b274e1e20
< 7.3.7
MEDIUM 5.4 Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticate… wordfence
4bc4ba2c-32eb-46c5-bb40-7c0150fc1ca4
< 4.3.1
MEDIUM 5.4 The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sever… wordfence
4b8ce6c8-c563-405e-8e67-1bec27150a64 MEDIUM 5.4 The The Target Video Easy Publish plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up… wordfence
4b5ba815-ce92-4d7b-aa80-29d6fddd7f63
< 9.1.6
MEDIUM 5.4 The The Global Gallery - WordPress Responsive Gallery plugin for WordPress is vulnerable to arbitrary shortcode executio… wordfence
4b225e5e-7207-4af4-b023-ad23fd540d56
< 2.3.2
MEDIUM 5.4 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
4af4b971-7304-47c9-8d01-eae36e40c45c
< 2.0.14.5
MEDIUM 5.4 The ListingPro theme before v2.0.14.5 for WordPress has Persistent XSS via the Good For field on the new listing submit … wordfence
4ad32ff7-0557-439d-aa0f-49c5ea4271ab
< 1.6.0
MEDIUM 5.4 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
4acc1fd2-0024-4c35-b8c6-94203b91e985
< 1.4.6
MEDIUM 5.4 The Crelly Slider plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl… wordfence
4a992bb2-67b9-48db-a536-c3af79e93af4
< 0.3.24
MEDIUM 5.4 The Tilda Publishing plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to mi… wordfence
49a0c45e-781e-4d2e-a9e8-a54ff8ef6131 MEDIUM 5.4 Stored Cross-Site Scripting (XSS) vulnerability in Andrea Pernici News Sitemap for Google plugin <= 1.0.16 on WordPress,… wordfence
← Prev 1084 1085 1086 1087 1088 1089 1090 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top