ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1088 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
499483a0-957b-459e-b2f5-fc39c4f86c9e
< 4.16.3
MEDIUM 5.4 The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does … wordfence
498f539a-f824-42fb-9df8-c1f82c4b3947
< 1.2.0
MEDIUM 5.4 The Pootle Button plugin before 1.2.0 for WordPress has XSS via the assets_url parameter in assets/dialog.php, exploitab… wordfence
497c2f5f-ed7d-486e-baf2-aefbe3dc412f
< 1.8.0
MEDIUM 5.4 The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
49333c6b-58f6-4d5a-a605-46484160175a
< 1.3.2.5
MEDIUM 5.4 The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.… wordfence
490f5939-a990-4fb7-9515-f8dcee53d75a
< 3.1.9.1
MEDIUM 5.4 The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote a… wordfence
482c4986-3677-4754-992b-ea9be7573d2e
< 2.0.2
MEDIUM 5.4 The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Border He… wordfence
47cb48aa-b556-4f25-ac68-ff0a812972c1
< 2.2.0
MEDIUM 5.4 The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to unauthorized access of data and modification… wordfence
479f7e9c-8918-4b87-b33d-a396276fb637
< 1.1.45
MEDIUM 5.4 The OOPSpam Anti-Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
474494ad-6713-4167-b40d-c29c533f169e
< 3.0.4
MEDIUM 5.4 The Etsy Shop plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.3. … wordfence
4736d139-814e-4eeb-91e8-5ee41fc35a8f
< 4.16.8
MEDIUM 5.4 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
472cdbc4-3bfa-4254-b35a-be7ae10782e6
< 1.12.8
MEDIUM 5.4 The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
4688c1ee-335c-4adb-bd68-894ff34d001d
< 3.10.5
MEDIUM 5.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in … wordfence
46828b2a-ed76-4074-9fb4-c36bf0fd012c
< 3.4.2
MEDIUM 5.4 The Logo Carousel WordPress plugin before 3.4.2 does not validate and escape the "Logo Margin" carousel option, which co… wordfence
462fcf4d-3ece-48d7-b06f-9a5de9372f5c
< 1.8.0
MEDIUM 5.4 The Cooked – Recipe Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
46271ab0-5f24-4cdb-9e1f-12db7bcbea6c
< 1.6
MEDIUM 5.4 The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an… wordfence
4625072b-815d-41d2-bf8f-ac290efde369
< 3.6.17
MEDIUM 5.4 The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to Stored Cross-S… wordfence
45f32160-36eb-4d66-a6a6-a3d6f2f7bf1a
< 2.4.1
MEDIUM 5.4 The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘website’ parameter in… wordfence
45d3f82b-9e19-4678-8995-7fe265606fd2 MEDIUM 5.4 The IP Blocker Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
45adeeba-22b0-4758-bc21-afc019653ce8
< 3.6.1
MEDIUM 5.4 WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to … wordfence
45a49dca-2ed2-44cf-a0fe-0f1440a78cc2
< 4.4.0
MEDIUM 5.4 The package loader-utils before 1.4.1, from 2.0.0 and before 2.0.3 is vulnerable to prototype pollution via the function… wordfence
45851efe-2584-4b5e-8e4c-24f289d3bc32
< 1.2.5
MEDIUM 5.4 The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.4… wordfence
457c4e56-c2a0-451f-a4a6-e7fb7bf7b0e0
< 9.1.1
MEDIUM 5.4 The WP Recipe Maker plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 9.1.… wordfence
453c656a-c26d-44c3-bc7d-7fc502a00b03
< 2.4
MEDIUM 5.4 The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output … wordfence
45180c8e-0625-4a21-b3a1-673abe52d78f
< 1.3.0
MEDIUM 5.4 The ARI Stream Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
44e70eb9-f411-49da-b169-a5af8a9ace0c
< 5.11.2
MEDIUM 5.4 The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from la… wordfence
← Prev 1085 1086 1087 1088 1089 1090 1091 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top