πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 672 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4ea939f5-8b56-44be-bd20-b69e9ded5970
< 4.2.25
MEDIUM 6.4 The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… wordfence
4ea634b5-72db-428c-96b4-15ef6025ab1d
< 1.52.2
MEDIUM 6.4 The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Adv… wordfence
4e9f16e1-9748-4f5d-84f0-19da68d4f862 MEDIUM 6.4 The Tour & Activity Operator Plugin for TourCMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
4e9e9afc-89a0-444d-ad5b-975e0f3c19d5
< 2.5.1
MEDIUM 6.4 The Bootstrap Blocks for WP Editor v2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gtb-boo… wordfence
4e97e603-b864-41ef-98c8-b0304a72ec44 MEDIUM 6.4 The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' and 'id' para… wordfence
4e9563b8-7e1b-4e87-8b56-17b75adb66c3
< 0.2.3
MEDIUM 6.4 The Markdown Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'markdown' sho… wordfence
4e8ca12e-b7a7-416a-b37d-c1672375a52d
< 2.3.9
MEDIUM 6.4 The OnePress theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.8 du… wordfence
4e780461-3fda-491d-ac77-dee52f8197b3
< 3.7.0
MEDIUM 6.4 The Insert Pages WordPress plugin before 3.7.0 adds a shortcode that prints out other pages' content and custom fields. … wordfence
4e620ae8-03fc-43b5-8e8f-5b0884e8eefb
< 6.3.1
MEDIUM 6.4 The RumbleTalk Live Group Chat – HTML5 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
4e4a605e-542b-4001-84d8-0a0aad044798
< 3.0
MEDIUM 6.4 The Simple YouTube Responsive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortco… wordfence
4e498706-3dbe-4c48-9c0d-0d90677aba0d
< 2.20.2
MEDIUM 6.4 The Gift Up Gift Cards for WordPress and WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
4e481e81-f581-48f7-b699-0be85e099c84
< 1.1.7
MEDIUM 6.4 The MAS Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
4e3d0ffd-209b-4e29-bc1d-91f2498b4632 MEDIUM 6.4 The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'PAFE Before … wordfence
4e2603e2-a89c-4fb1-b219-6cf5a7560bea
< 1.7.8
MEDIUM 6.4 The Coupons & Add to Cart by URL Links for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
4e1cd584-ffb8-43d6-a7b6-141c59ac463d
< 1.5.2
MEDIUM 6.4 The WishSuite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter of the '… wordfence
4e1c2d20-013e-4cad-865d-287924c18673
< 1.3.5
MEDIUM 6.4 The UiCore Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
4e0fd492-19ee-430e-a495-99ad28043bf9
< 1.2.24
MEDIUM 6.4 The VK Google Job Posting Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Descript… wordfence
4e0424f8-f60f-49c3-9969-a88c830dc0e2
< 3.2.13
MEDIUM 6.4 The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in vers… wordfence
4dfc237a-9157-4da9-ba8f-9daf2ba4f20b
< 2.7.0
MEDIUM 6.4 The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
4df635b8-4c56-4b24-8446-8e39e6fe7441
< 3.7.28
MEDIUM 6.4 In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files … wordfence
4df5bd44-3f72-4ca3-981e-9c11c9e6ab42 MEDIUM 6.4 The Real Estate Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
4decc923-dda8-4aed-b431-1718ad39c376
< 1.0.52
MEDIUM 6.4 The Flexible Refund for WooCommerce – EU One Click Return plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
4deb1527-0637-44f2-b336-d0cf2a48fa52
< 4.7.0
MEDIUM 6.4 The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_ulike' shortcode in … wordfence
4deae680-4829-4e24-b67b-4066ec9ce4da
< 2.0.6
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject … wordfence
4ddd9cab-f381-4343-a2e6-ef8a1be2ed4e MEDIUM 6.4 The Ultimate TinyMCE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'field' shortcode in all … wordfence
← Prev 669 670 671 672 673 674 675 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top