πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 673 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4ddcb9e7-506d-408d-812b-b95610b636f1 MEDIUM 6.4 The Countdown Timer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'countdown_l… wordfence
4dcc3f47-8504-4aa6-af60-03edeaa39fd7
< 4.1.0
MEDIUM 6.4 The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
4dbd8cac-9e4b-4353-9c62-9cabb60b927c
< 3.2.5
MEDIUM 6.4 The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
4dbb0ca4-169a-4f51-a196-5f138744c54d
< 1.26.3
MEDIUM 6.4 The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Stored Cross… wordfence
4da52b6a-38dd-4a66-bcaf-8a77f96377fe
< 1.3.6
MEDIUM 6.4 The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
4d9f7832-3dff-4cb8-a6be-a16449164363
< 1.9.5
MEDIUM 6.4 The PageLayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.4 … wordfence
4d982416-ac4b-4d14-bf2b-d43fc92550b1
< 1.2.4
MEDIUM 6.4 The Coupon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.2 due… wordfence
4d8fb548-0737-4b69-bf64-838bfc6d409a
< 2.0.8
MEDIUM 6.4 The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in … wordfence
4d89a4ca-c867-43bf-aace-295de8533fcd
< 2.4.27
MEDIUM 6.4 The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cros… wordfence
4d7f94b4-8d8a-496a-bc59-aa0619175fa2
< 4.8.1
MEDIUM 6.4 The Jobmonster theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.8.0 … wordfence
4d7b12e5-0de7-45f4-84e0-083818912623
< 8.7
MEDIUM 6.4 The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rev_slider… wordfence
4d73cc31-f65d-4df3-a14e-8ec2839d5bf2 MEDIUM 6.4 The AtomChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.6 d… wordfence
4d72a57f-9acc-43e4-af81-024bc6e0d3fd
< 1.4.2
MEDIUM 6.4 The Image Hover Effects – Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl… wordfence
4d6f9c80-ef86-4910-a88e-98f2b444ee30 MEDIUM 6.4 The PDF Viewer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the render function i… wordfence
4d6e9cb0-6b90-4a5b-8626-0b3f378fbc92
< 3.14.25
MEDIUM 6.4 The 12 Step Meeting List plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in… wordfence
4d6d8879-3a78-4c99-aea5-754ac80f9c68 MEDIUM 6.4 The DZS Ajaxer Lite – Ajaxify Your WordPress Site and Comments plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
4d678e97-f466-4640-83ee-a3a24550e8d8 MEDIUM 6.4 The Twittee Text Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribut… wordfence
4d62b087-b0ca-4fa8-921b-5eeb3fa76596
< 2.6.23
MEDIUM 6.4 The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for … wordfence
4d5dcec8-fa36-43ab-9a35-0b391fe1d88e
< 1.26.7
MEDIUM 6.4 The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Stored Cross… wordfence
4d565196-592d-415c-b37c-e54456aa9ed8
< 1.3.976
MEDIUM 6.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
4d4ecc01-7969-4ff6-8210-530835a43dbc MEDIUM 6.4 The Simple Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜slideshow’ para… wordfence
4d4568c8-f58c-4c37-94b9-6154e5c46928
< 3.9.9
MEDIUM 6.4 The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & El… wordfence
4d419d9e-73c5-4d14-8da0-27a90924e0b5
< 2.4.1
MEDIUM 6.4 The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
4d3b1a76-febc-4037-b31e-5987f8a23e92
< 2.6.1
MEDIUM 6.4 The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via elements in versions up to, and… wordfence
4d3191b0-829f-4d35-b8f6-323e7ea6f80b
< 3.7.9
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary… wordfence
← Prev 670 671 672 673 674 675 676 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top