πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 674 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4d25e292-b62b-493e-976c-a5eb95505065
< 0.2.1
MEDIUM 6.4 The Ketchup Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spacer' short… wordfence
4d21febd-e206-4f7c-a6a2-0fa65150ed29
< 2.3.1
MEDIUM 6.4 The Portfolio for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode… wordfence
4d0973e2-394f-435b-821b-54ab3384b383
< 5.3.3
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
4cf68644-d144-462f-adc7-687fac3ec412
< 2.1.8
MEDIUM 6.4 The PDF.js Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versi… wordfence
4cf4e22b-423c-49e6-ac00-99adf997aebe MEDIUM 6.4 The iFrame Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.1… wordfence
4cebd997-4bfb-46f2-9670-0ab8e40f632b
< 1.36.3.1
MEDIUM 6.4 The Hubbub Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.36… wordfence
4cd8ef87-5c7c-432c-af72-14876086dd18 MEDIUM 6.4 The WP Ultimate Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
4cd82b65-eadd-4a81-a8e4-72ce58dd360d
< 1.4.7
MEDIUM 6.4 The iPages Flipbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its shortcode in versions up t… wordfence
4cd69b73-4892-4ae3-9e22-5ec8d756e0cd
< 2.4.5
MEDIUM 6.4 The JetBlog plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.4.1 … wordfence
4ccf0e70-7e0e-4efc-879a-cda883c6394e
< 1.1.1
MEDIUM 6.4 The Product Carousel For WooCommerce – WoorouSell plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
4cca872a-7215-4bc0-b4f9-550a020d5071 MEDIUM 6.4 The Dropdown Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
4cc038af-c4c8-4141-bbe3-81bcf0a2bace
< 1.0.4
MEDIUM 6.4 The Post Carousel & Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-cs' … wordfence
4cb410aa-3941-4e19-8de4-622a94766ee8
< 2.2.12
MEDIUM 6.4 The Printful Integration for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio… wordfence
4cb3f111-4ac3-4c57-aa62-569b71143fec
< 1.4.9.9
MEDIUM 6.4 The Landing Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in… wordfence
4cafec05-c275-475d-91cf-ed65cd191b0e MEDIUM 6.4 The Bon Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt-map' shortcode in… wordfence
4c9c110b-8e30-48ca-8439-59818ecbe80f MEDIUM 6.4 The Prezi Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
4c91caaa-9bdd-4170-98f1-0d686d3ffcba MEDIUM 6.4 The Laybuy Payment Extension for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
4c90fd3e-24f1-493e-a306-d083086070d4 MEDIUM 6.4 The Simple Map No Api plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
4c8971e0-befd-47ac-8cb5-064f9cd757d7
< 3.19.20.1
MEDIUM 6.4 The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ulti… wordfence
4c73fe0b-59d7-4393-bc93-f4a3a3fa7b75
< 6.30.06
MEDIUM 6.4 The WP Compress for MainWP plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and … wordfence
4c5b2ce5-d3bf-4412-b329-470a1115260b
< 1.9.1
MEDIUM 6.4 The Apollo13 Framework Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sho… wordfence
4c570533-1a67-46ad-9d29-35f70ae3bb6a MEDIUM 6.4 The e.nigma buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcod… wordfence
4c42cc4e-34e7-4f14-b850-7ba5dd2ae099
< 8.7
MEDIUM 6.4 The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS module in … wordfence
4c38ca9a-895b-4d59-94c9-c7d5ba3b1b7d MEDIUM 6.4 The Geopost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter of the 'geopost… wordfence
4c33c640-0876-4b07-829e-35cae445b420
< 3.8.0
MEDIUM 6.4 The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
← Prev 671 672 673 674 675 676 677 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top