πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1324 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
499e88e9-d915-46a7-84c9-b4099c091105 MEDIUM 4.4 The Event Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … wordfence
498a10a1-8da6-4309-833f-950f6442d5ae MEDIUM 4.4 The Smarty for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version… wordfence
4953e1b6-6ad1-41f5-b50b-43de078008ac
< 6.8.9
MEDIUM 4.4 The Easy Forms for Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Name in version… wordfence
490b48e8-bdfa-4843-89df-1f50c05a05b8
< 2.6.1
MEDIUM 4.4 The WANotifier – Send Message Notifications Using WhatsApp API plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
48ffd408-ef7b-4b78-90c3-e1645d7354b1
< 22.5
MEDIUM 4.4 The WordPress Online Booking and Scheduling Plugin – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
48ff572a-f18f-4b8d-ac58-78063919ff35
< 4.1
MEDIUM 4.4 The Easy SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versi… wordfence
489dc156-b8cb-4e08-a847-73a891398d5c
< 1.6.1
MEDIUM 4.4 The Cookie Notice & Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in vers… wordfence
4898d7c1-a784-45b6-87bf-c1949fc1414f MEDIUM 4.4 The Responsify WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
4894a24b-aaa4-4d03-a897-9074a194c07f MEDIUM 4.4 The Review Disclaimer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
48363f1f-dae8-4efa-824f-098550245ca3 MEDIUM 4.4 The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu… wordfence
481c18c1-8394-4d5d-89a1-8cfbbbc40bd4 MEDIUM 4.4 The DL Verification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions… wordfence
4810251f-7d87-4fed-8673-ff3519c7b0af
< 6.8.1
MEDIUM 4.4 The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
47f668b0-8165-4ce8-97cc-b674e708c2eb
< 9.1.3
MEDIUM 4.4 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
47eb6ca7-049c-41b8-9210-391d4d1b8b2f MEDIUM 4.4 The Popup contact form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions … wordfence
47e6840e-9f6c-44eb-a6bd-e25e4c5c0bf7
< 7.13.64
MEDIUM 4.4 The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Sto… wordfence
47e402c3-e06c-4ac9-8c60-5666cb1101ce
< 6.7.1
MEDIUM 4.4 The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress… wordfence
47c4adb7-6583-4059-85bb-bc79d917a817 MEDIUM 4.4 The Beautiful Link Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
47bcd04b-a479-49f2-94d0-df2a7684210c MEDIUM 4.4 The VideoZen plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.1. Th… wordfence
4782d4ea-3d79-40d2-850d-1a7583267616 MEDIUM 4.4 The CPT Shortcode Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in versions u… wordfence
47461b7b-e986-4048-88aa-175242305795
< 1.0.6
MEDIUM 4.4 The WP Edit Username plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
4727154c-c48f-4958-9520-cc5204927ee4 MEDIUM 4.4 The Automatic Translator with Google Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
46f7dc18-fc07-400a-bb79-0d9821299023 MEDIUM 4.4 The Exquisite PayPal Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in v… wordfence
46db2d07-66a6-4d9e-b0fd-ddf6119ba5be
< 3.3.5
MEDIUM 4.4 The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings… wordfence
46d65fed-cb21-46e1-bafe-eda11c25a467 MEDIUM 4.4 The Simple Portfolio Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
465fb289-48f7-4a67-a5df-f8994b9333af
< 0.9.9
MEDIUM 4.4 The Notif Bell plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.9.8… wordfence
← Prev 1321 1322 1323 1324 1325 1326 1327 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top