πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 671 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4fcd2eb4-6cec-4fe8-b506-9a3970ed284a MEDIUM 6.4 The Advanced Element Bucket Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… wordfence
4fa4167a-686f-4fd0-a53d-eb61d57228a1
< 7.11.1
MEDIUM 6.4 The LayerSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ls_search_form shortc… wordfence
4f9fb3a5-b669-4f3b-981d-face13a9a7c8
< 1.2.3
MEDIUM 6.4 The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin f… wordfence
4f9a0341-5479-4b83-8ce8-eb838a34a448
< 1.0.7
MEDIUM 6.4 The Currency Converter Widget ⚑ PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… wordfence
4f88cbad-9b45-4fd9-a268-c4ad42b3547f MEDIUM 6.4 The TempTool [Show Current Template Info] plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… wordfence
4f86d75b-f75e-4d5b-b0b8-a17a68e17048 MEDIUM 6.4 The Simple Youtube Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embed_youtube' s… wordfence
4f83e20b-b763-4ef7-b703-4b37f679838b
< 2.34
MEDIUM 6.4 The PiwigoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.33… wordfence
4f7cca0c-6055-491d-be5e-b2c0abf26f7b
< 2.3
MEDIUM 6.4 The SKT Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2 d… wordfence
4f6c69ca-eb1e-445a-af72-5f03dfa07f9b MEDIUM 6.4 The Elementor Button Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
4f687775-89fe-4ca6-bc83-c4f1649fa794
< 2.6.3
MEDIUM 6.4 The Namaste! LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6… wordfence
4f65a7df-acb5-4b5b-8867-986ce9930e3f
< 2.4.28
MEDIUM 6.4 The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widg… wordfence
4f5bff23-61ff-4c38-8334-a16a24a0a8aa
< 15.3
MEDIUM 6.4 The Responsive Posts Carousel Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
4f459c38-6362-4131-890c-ad2cbd3e5903
< 1.4.1
MEDIUM 6.4 The ARI Fancy Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
4f417d54-5aa6-4ef4-870a-12a9fa73050d
< 1.4.0
MEDIUM 6.4 The RLM Elementor Widgets Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
4f0499db-009a-4c45-86c7-9bbb34d6373e
< 10.0.10
MEDIUM 6.4 The The Moneytizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
4f031293-2bc6-4459-95cb-22d216c57381
< 1.2.3
MEDIUM 6.4 The Travelfic Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
4f01eb23-af49-4f1e-a5c7-1932a4119e6b MEDIUM 6.4 The Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera plugin for WordPress is vulnerable to Stored… wordfence
4ee2051a-1c89-44e1-be6a-c63ec7090db8 MEDIUM 6.4 The BBCode Deluxe plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 20… wordfence
4ede558d-272d-4f18-b2e0-97f5c2cb958b MEDIUM 6.4 The Lightbox slider – Responsive Lightbox Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
4ed50ad7-a31b-488e-85fc-ff521488f62a
< 2.9.1
MEDIUM 6.4 The Real Estate 7 WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the template-edit-listi… wordfence
4ed506e1-9e77-4a0d-a33f-b783c0de410f MEDIUM 6.4 The My Restaurant Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
4ed23318-3b47-4336-a3aa-6b09f3911926
< 1.1.11
MEDIUM 6.4 The AMP for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up… wordfence
4ec73a61-9ae2-4e6f-b1fa-2d61f27d6809
< 2.2.6
MEDIUM 6.4 The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slide… wordfence
4eb296af-547a-44aa-b804-833204b75256
< 4.15.5
MEDIUM 6.4 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
4eaf4c05-9393-4e44-abd1-8f529b7848b5
< 5.6.3
MEDIUM 6.4 The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordP… wordfence
← Prev 668 669 670 671 672 673 674 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top