ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 419 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4e381ad7-efe6-48c4-af3a-22d01d73a065
< 1.7.5
HIGH 7.1 The Archivist – Custom Archive Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
4d154587-e396-45ba-80ad-b532b612823a
< 3.0
HIGH 7.1 The Change Table Prefix plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
4d153095-9f72-438e-84bb-07a5ad7bdb48
< 4.4.0
HIGH 7.1 The Careerfy for WordPress is vulnerable to Reflected Cross-Site Scripting in versions before 4.4.0 due to insufficient … wordfence
4c425635-b1a1-4085-a68c-2c159a38623f
< 1.1.0
HIGH 7.1 The Track That Stat plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 1.1.0 due to insuffici… wordfence
4a198600-9c47-46bc-97b6-d7f90493d43e HIGH 7.1 The Minterpress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on a f… wordfence
49e4dc41-dd5a-4689-9818-e742d1def2f0 HIGH 7.1 The WordPress HTTPS (SSL) plugin is vulnerable to authenticated settings change in versions up to, and including, 3.4.0 … wordfence
49b466a2-9f6d-431f-8118-7522394d2eed
< 1.0.3
HIGH 7.1 The GroupDocs.Comparison for Cloud plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in … wordfence
48e30af6-d28c-4547-aef9-d216064c9829
< 0.10
HIGH 7.1 Cross-site scripting (XSS) vulnerability in the Hybrid theme before 0.10 for WordPress allows remote attackers to inject… wordfence
477c6fa2-16a8-4461-b4d4-d087e13e3ca7
< 3.4
HIGH 7.1 The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized arbitrary file u… wordfence
461d5d5a-7bc2-4855-bc40-0edb9c538c33
< 1.3.0
HIGH 7.1 The Ultimate Member plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in … wordfence
45323807-c347-44ac-bf22-11b4feda02e6 HIGH 7.1 The Eunice theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an unspecified parameter in all known… wordfence
42a642a8-fee3-497f-9fcf-7e888838af0b
< 4.0.5
HIGH 7.1 The MainWP Post Dripper Extension extension for WordPress is vulnerable to authorization bypass due to a missing capabil… wordfence
429fe34a-5fa9-4032-9b21-4de114dbc9d1
< 2.4.1
HIGH 7.1 The Broken Link Checker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query… wordfence
416803bc-7851-4489-85f9-dbff0838d35b
< 2.0
HIGH 7.1 Cross-site scripting (XSS) vulnerability in the Random Banner plugin 1.3 for WordPress allows remote attackers to inject… wordfence
413fa88f-1f06-4386-9cc1-53009da939d7 HIGH 7.1 Cross-site scripting vulnerability in Fudousan plugin ver5.7.0 and earlier, Fudousan Plugin Pro Single-User Type ver5.7.… wordfence
3fc5e9b3-a121-40f0-a7e8-32979254f52e HIGH 7.1 The Register Plus Redux plugin for WordPress is vulnerable to Cross-Site Scripting in up to, and including 4.3 due to in… wordfence
3f5ff15d-2436-48d4-a31d-6bfd9704149f HIGH 7.1 Multiple cross-site scripting (XSS) vulnerabilities in yupdates_application.php in the Yahoo! Updates for WordPress plug… wordfence
3f2c97f4-0a6e-4693-a6c8-bd81ca76988c
< 3.2.5
HIGH 7.1 The JetEngine plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up… wordfence
3f11416c-c981-4c85-822c-497ecfaa842d
< 2.5.6
HIGH 7.1 The Campaign Monitor Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… wordfence
3dd8dac6-b969-498a-a1f8-2a00009ae1d8 HIGH 7.1 Cross-site scripting (XSS) vulnerability in embedded-video.php in the Embedded Video plugin 4.1 for WordPress allows rem… wordfence
396a7101-e6da-49c1-87a3-25792f3a7b76 HIGH 7.1 Cross-site scripting (XSS) vulnerability in css/gallery-css.php in the Slideshow Gallery2 plugin for WordPress allows re… wordfence
379408c3-399d-4aff-9a6b-43913aaa52b7
< 2.8.10
HIGH 7.1 The WP Members plugin for WordPress is vulnerable to Multiple Cross-Site Scripting via several parameters in versions be… wordfence
36fa1b11-911d-4235-b3b0-568b27f251c4
< 1.18.1
HIGH 7.1 The Import Excel to Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions u… wordfence
36aecabd-4982-426d-be47-075c23a452a2
< 4.29.5
HIGH 7.1 Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 … wordfence
35767133-28d7-47e9-bcda-5d761262cdad
< 4.1.1
HIGH 7.1 The MainWP Post Plus Extension plugin for WordPress is vulnerable to authorization bypass due to a missing capability ch… wordfence
← Prev 416 417 418 419 420 421 422 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top