πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1322 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
503a44ed-25c2-4178-aeec-756c5b533e04
< 3.2.2
MEDIUM 4.4 The Dashboard Widgets Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
5022e15e-6c1d-4e9d-a27a-961516f392f8
< 1.0.7
MEDIUM 4.4 The N360 | Splash Screen plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
4ff558bb-7c5a-4e17-a3f5-bc9aa2332af1
< 2.0.0
MEDIUM 4.4 The IDonate – blood request management system plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad… wordfence
4ff21c04-b615-417a-a640-e17c3211f449 MEDIUM 4.4 The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… wordfence
4fb5bd77-2841-4d41-aaa7-387bdb1f50b1 MEDIUM 4.4 The Email Notification on Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
4f549272-4112-4cfe-a61e-6982f87e5cb0
< 3.5
MEDIUM 4.4 The MWW Disclaimer Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
4f504434-2de9-4d2e-848d-6c7fc0880672
< 1.2
MEDIUM 4.4 The Custom Field For WP Job Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
4f42b59e-42a3-4c1d-805d-dfe8c692223e
< 1.6.6
MEDIUM 4.4 The Enhanced Text Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget options in all ver… wordfence
4f3a57ce-eead-4631-93da-ba1a0a33ec2d
< 1.0.5
MEDIUM 4.4 The WP Custom Author URL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version… wordfence
4f2040a1-1b17-4279-bc19-61dfad0a7a76
< 1.8.1
MEDIUM 4.4 The Plugin Oficial – Getnet para WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm… wordfence
4f040075-83a0-4c9a-8d93-99aa36606b31 MEDIUM 4.4 The Cookie Monster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up t… wordfence
4eb2437f-9827-4900-9e23-d223403ec9bb MEDIUM 4.4 The WP Last Modified plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
4eacf7b7-100b-423d-920f-14f3e33f5f60 MEDIUM 4.4 The TP2WP Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Watched domains' textarea … wordfence
4ea357cf-1619-42ab-929f-b2dd5deed555 MEDIUM 4.4 The WebinarPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3… wordfence
4e8f03f4-f7a6-408c-a79e-f9cd03d77a76
< 1.5.14
MEDIUM 4.4 The WP Admin UI Customize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… wordfence
4e7de990-4a6b-4bae-89a2-4a417071fe20
< 1.0.22
MEDIUM 4.4 The Template Kit – Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
4e6b39da-26d4-4615-b6c7-68909bdf0a61 MEDIUM 4.4 The Dynamically Register Sidebars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin setti… wordfence
4e576c6e-6a9b-439d-bde3-8657435596f6 MEDIUM 4.4 The Prenotazioni plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… wordfence
4e4fe4b6-cc1e-40be-bd2e-bf2745244892
< 1.2.1
MEDIUM 4.4 The WC Builder – WooCommerce Page Builder for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
4e190fe3-5947-4da3-95ef-aa4973419696
< 5.7.45
MEDIUM 4.4 The Email Subscribers by Icegram Express – Affordable, Powerful Email Marketing for WordPress & WooCommerce plugin for… wordfence
4d9b6efa-b82e-4fe5-bf56-4ca49e9ebe71 MEDIUM 4.4 The Survey plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, a… wordfence
4d8cfcdc-6258-4629-a3b4-d65e44ac82f1
< 1.7.8
MEDIUM 4.4 The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… wordfence
4d8bd9bc-5062-4966-bc44-bfe033d5fc9b
< 3.6.10
MEDIUM 4.4 The WordPress Page Builder – Zion Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settin… wordfence
4d70cd0a-5c30-4a9b-81e8-e465d1e8f2b0
< 6.2.5
MEDIUM 4.4 The Login Page Styler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions u… wordfence
4d6c37ec-4a17-41b8-a29e-2a9adb382cea MEDIUM 4.4 The Login Screen Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version… wordfence
← Prev 1319 1320 1321 1322 1323 1324 1325 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top