πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1323 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4d3d76b3-9aca-46ac-acb7-353261dbec79 MEDIUM 4.4 The Post Read Time plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
4d16e945-1576-4d9b-8e1b-995ec457215b
< 13.3.1
MEDIUM 4.4 The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a… wordfence
4d10d609-eb0f-492a-be87-2ac7db9c63b4
< 1.7.5
MEDIUM 4.4 The Client Portal : SuiteDash Direct Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… wordfence
4cf894fd-37c7-4006-b868-d5d33f66cc5a MEDIUM 4.4 The Advanced Social Feeds Widget & Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin… wordfence
4cab3c9c-39c6-4279-9573-858b0592c3fa MEDIUM 4.4 The WP-Cirrus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, an… wordfence
4c8850df-e835-4068-8114-11966014e6eb
< 1.4.14
MEDIUM 4.4 The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin… wordfence
4c64ec9f-c9ca-49c1-9126-b31defb826dd
< 1.97.0
MEDIUM 4.4 The Advanced Form Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
4c293c3a-383d-4e3c-bf1b-4d64e9cd3eb5
< 2.0
MEDIUM 4.4 The WP Login and Logout Redirect plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… wordfence
4c1adf5b-5377-40a3-a53d-e93cf38d949d MEDIUM 4.4 The WP Front User Submit / Front Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
4bf456a3-3d42-42e8-b89b-dcdd8cbc7d9a MEDIUM 4.4 The BMo Expo plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.15 … wordfence
4baa79da-ae4d-4e45-855f-8c7d713fb2f9 MEDIUM 4.4 The Special Box for Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … wordfence
4ba46475-bf54-49a8-9b0e-fae3fb4e1df9 MEDIUM 4.4 The Short Comment Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Minimum Count' setti… wordfence
4b8a3e10-bdd9-4d5f-8632-bd7f0247b8f1
< 3.10.1
MEDIUM 4.4 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
4b51d69d-2026-4e2c-b031-93046c24b2dd
< 2.7.0
MEDIUM 4.4 The WP Abstracts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6… wordfence
4b5078ca-dec9-4252-8dd9-42bbb9ddef55 MEDIUM 4.4 The WooMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.12 due t… wordfence
4b334ebe-6988-4caf-aad4-b599dc6be969
< 2.4.1
MEDIUM 4.4 The IP Based Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … wordfence
4af920a9-15fb-44c9-be31-7c9ed5bc2031 MEDIUM 4.4 The binlayerpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… wordfence
4aedc055-34f7-48aa-90d4-0c16f219f599
< 1.2.62
MEDIUM 4.4 The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad… wordfence
4ada2055-3c4a-4b6f-8803-2eac8ede5ec7
< 1.50.3
MEDIUM 4.4 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored C… wordfence
4ac9262a-96a6-439a-a2b0-a05f24654d06
< 2.3.4
MEDIUM 4.4 The Button Generator – easily Button Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm… wordfence
4a7bfa47-1c83-4af7-8ddd-0b90a117b9c7 MEDIUM 4.4 The Expert Invoice plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … wordfence
4a77675b-5a31-4bc1-b4bd-36dd9a612b7c MEDIUM 4.4 The Social Feed | All social media in one place plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad… wordfence
49d0315e-fcb2-4232-8797-0421cf5d3cd8
< 2.0.7
MEDIUM 4.4 The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin sett… wordfence
49c65776-130d-4c22-b4f8-ababac8cf341
< 2.14.3
MEDIUM 4.4 The WebinarIgnition plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'appname' and 'webinar_des… wordfence
49bd0848-afc0-4aa2-86a4-1b697206b925
< 5.0.17
MEDIUM 4.4 The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a CSV… wordfence
← Prev 1320 1321 1322 1323 1324 1325 1326 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top