πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1326 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
43c66948-c751-45d5-a413-a606f96dcd09 MEDIUM 4.4 The WP Post to PDF Enhanced plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
43b59e94-047e-4bdf-abe1-538f2f043ffe
< 3.2.8.2
MEDIUM 4.4 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin… wordfence
438689aa-3b85-4dd7-ac3e-a37906efd79c MEDIUM 4.4 The WP Repost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, an… wordfence
4360a04c-4e94-41a3-9553-aeb67e9682e0
< 1.6.6
MEDIUM 4.4 The Store Locator WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.6.6 du… wordfence
434755f8-b2af-4f35-9af9-f0b9578718c8 MEDIUM 4.4 The UserAgent-Spy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions … wordfence
4325d9ce-35a2-4ee8-99cc-39c04d624e81 MEDIUM 4.4 The Related Post Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
42aa9614-3403-422c-a4b7-0f4b2d17b371
< 2.6.23
MEDIUM 4.4 The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
429acb91-4846-45be-8f39-d8584a70c131
< 5.4
MEDIUM 4.4 The YouTube Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.… wordfence
4278e9d7-aa1e-47a5-b715-09dae5156303
< 2.78
MEDIUM 4.4 The Advanced Woo Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version… wordfence
4278b8f6-ce3e-4b6d-ae69-dee24a2177e7 MEDIUM 4.4 The PVN Auth Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … wordfence
42665ffd-e2fa-4883-9275-5e0b54943d3c
< 2.0.6
MEDIUM 4.4 The Highlight plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.2 … wordfence
423e10b3-5b1d-4162-ade4-3f6d69a9703e MEDIUM 4.4 The Web Accessibility with Max Access plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
4204209b-054f-4249-87d0-a0837ac172d6
< 1.5.3
MEDIUM 4.4 The Woo Viet – WooCommerce for Vietnam plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set… wordfence
41d39fe4-b114-4612-92f6-75d6597610f7
< 2.23.5
MEDIUM 4.4 The Internal Link Juicer: SEO Auto Linker for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
41d09e93-8503-41e8-85d3-8550dc8f85bd
< 4.5
MEDIUM 4.4 The Social Share Boost plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
41c71f86-a2f7-4e0e-9145-ba50830f6dba
< 1.9.1
MEDIUM 4.4 The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti… wordfence
41adfb58-d79f-40a3-8a7e-f3f08f64659f MEDIUM 4.4 The Amazonify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to… wordfence
4195dbd4-7b6b-4201-887f-6da9bda618b8
< 3.0.6
MEDIUM 4.4 The Top Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, … wordfence
416c13ff-15ae-4ba4-8a95-7c07bec75c22
< 2.5.1
MEDIUM 4.4 The SureCart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to… wordfence
413e5515-6cc9-4fa9-908e-2dc68778f5cb
< 6.0
MEDIUM 4.4 The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
410f232f-610b-4de6-85bf-56f66b5b217e
< 1.3.9.9
MEDIUM 4.4 The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
40c7ce1f-3a81-4d49-9202-2d118f30639a MEDIUM 4.4 The TT Custom Post Type Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … wordfence
40b5a241-3cf4-476c-8fd9-d0b953234d39 MEDIUM 4.4 The Reward Video Ad for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i… wordfence
406f3eaf-44a7-4e32-a620-8799eb74742a
< 3.2.54
MEDIUM 4.4 The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-… wordfence
4036057c-0c43-4d9c-97db-4861d91a4daa MEDIUM 4.4 The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
← Prev 1323 1324 1325 1326 1327 1328 1329 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top