🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 494 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f4f0bb58-d904-4bf4-9e15-4ee6289c2df4
< 1.5.3
MEDIUM 6.4 The Kaya QR Code Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's qrCode att… wordfence
f4eb61dd-f28e-4d8a-8f97-958b6a356309 MEDIUM 6.4 The azurecurve BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode… wordfence
f4ea5c2e-594d-4835-9f29-bdfce6bb4750 MEDIUM 6.4 The Pretty file links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
f4e6fd53-0c97-4490-ab7a-9f6d195912b2 MEDIUM 6.4 The SVGMagic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up t… wordfence
f4e43d66-04f4-4adb-93da-75e02d1c714e
< 10.11.2
MEDIUM 6.4 The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpbc shortcod… wordfence
f4b36468-319a-4de3-9112-bd4a3cf7d637 MEDIUM 6.4 The CI HUB Connector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the `ci… wordfence
f4986bc3-ee34-43a6-bad2-9f6665adb35c
< 4.15.6
MEDIUM 6.4 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
f492dcb6-0aa7-476d-bb85-c81a136d02a6 MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_raw_conte… wordfence
f4895692-3851-4672-85ea-c703e44309d5
< 1.700
MEDIUM 6.4 The raindrops theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.6… wordfence
f47a2ff1-627f-4d1c-b0b6-684be51526f1
< 3.5.8
MEDIUM 6.4 The Simple Sitemap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in vers… wordfence
f479d889-2c79-43eb-bb9b-f876839c4e07
< 4.4.1
MEDIUM 6.4 The Starter Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
f4505b5a-de80-41e2-852f-d2290c1e42e4
< 1.9.10
MEDIUM 6.4 The Compact WP Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fileurl’ para… wordfence
f44bb823-bbf3-413b-82b5-a351609270bf
< 1.6.29
MEDIUM 6.4 The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hfe_s… wordfence
f443846f-4d70-4ca0-beeb-d2e839b14765 MEDIUM 6.4 The BJ Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `filter_images()` function in… wordfence
f43e1eed-09f8-44b3-b6fa-d0344f331dd7
< 3.10.4
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Photo … wordfence
f43b996a-646d-4ebc-bb91-49f5c448deb0 MEDIUM 6.4 The WoW Guild Armory Roster plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
f439718e-4a3d-4dc9-a16c-6b655480dde6 MEDIUM 6.4 The Post Category Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'postcatego… wordfence
f433edb4-a8df-4548-a401-0089b605bbe5
< 4.9.6
MEDIUM 6.4 The Spiffy Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in a… wordfence
f430835a-135f-4a09-b9c6-42c7b484cbee MEDIUM 6.4 The Arcade Ready plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1… wordfence
f424b35d-fdd7-49d2-bf47-04b81888996a
< 0.3.0
MEDIUM 6.4 The tarteaucitron.js for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up … wordfence
f4230c76-8a6e-45e5-9d18-e9e9456630c2 MEDIUM 6.4 The Simple Text Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
f419d14a-90d1-445a-b629-c2e978c3ab81 MEDIUM 6.4 The Advanced Blocks Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ve… wordfence
f40a1dd8-af66-4b97-af5b-0954dd6316a8 MEDIUM 6.4 The Cookie Nonsense for YT plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
f40956e0-6e5c-4965-84f8-2420ad14a299
< 2.6.9.1
MEDIUM 6.4 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown T… wordfence
f4026b41-29c3-4e0a-bf75-ae4ba47edb4f MEDIUM 6.4 The Station Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width' and 'height’ param… wordfence
← Prev 491 492 493 494 495 496 497 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top