🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 675 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4c1f4487-c684-4602-9b93-e547e2d38a64
< 3.7.11
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web scrip… wordfence
4c16841d-8878-4328-a5dc-113d213cca33
< 2.0.2
MEDIUM 6.4 The Social Post Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Threads embed handler in… wordfence
4c10d6cb-e0a7-4b8d-b50f-e23885355872
< 3.4.10
MEDIUM 6.4 The One Click Upsell Funnel for WooCommerce – Funnel Builder for WordPress, Create WooCommerce Upsell, Post-Purchase … wordfence
4c0af593-2674-484a-a6a5-715f6fb488cf MEDIUM 6.4 The CATS Job Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catsone' short… wordfence
4bfde95b-70bf-4445-a8b0-53dbdc5d2334
< 2.02
MEDIUM 6.4 The Advanced Woo Labels plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
4bf80767-4b11-49cd-acf5-7437aa89cc0f MEDIUM 6.4 The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'freshpodcaster' shortcode… wordfence
4bf45235-4ab6-4558-a7b0-cef86eca42f6
< 3.2.8
MEDIUM 6.4 The Ultimate Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
4beaa824-d3f1-499e-b4ef-3885f59e42c7 MEDIUM 6.4 The DA Media GigList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's damedia_giglist … wordfence
4be623dd-1298-4223-9eb5-d709e1e0e7d9
< 3.25.11
MEDIUM 6.4 The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
4be58bfa-d489-45f5-9169-db8bab718175
< 3.95.0
MEDIUM 6.4 The WordPress Automatic Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘autoplay’ … wordfence
4be512bd-190a-415a-bd20-a49373f63fbb
< 6.0.6.8
MEDIUM 6.4 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … wordfence
4bd9dfe6-a88c-4fe5-bf4c-91c4d950f5ab
< 5.2.3
MEDIUM 6.4 The WP Flow Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all ver… wordfence
4bd169bc-1538-400f-b2cd-0bbcf1fea7ee
< 6.4.0
MEDIUM 6.4 The BuddyPress plugin for WordPress is vulnerable to Insufficient Input Validation in versions up to, and including, 6.3… wordfence
4bae687b-5b54-4151-871e-7a9b6e56986e
< 2.2.6
MEDIUM 6.4 The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_… wordfence
4ba28184-b5c3-4a5c-a376-29b3c6a2aa20
< 1.13
MEDIUM 6.4 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the modal popup widge… wordfence
4b9fe250-3791-4808-918b-c1febbebf51b
< 4.7.0
MEDIUM 6.4 The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable t… wordfence
4b9aa41e-34bf-4bfb-a341-e101e3771f7a MEDIUM 6.4 The PDF Viewer & 3D PDF Flipbook – DearPDF plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
4b881509-572b-4e2d-9e75-defaa2cc32dc
< 8.2.4
MEDIUM 6.4 The Woodmart theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'multiple_markers' attrib… wordfence
4b7ddf44-a1d2-4042-9219-591ebc8e4250 MEDIUM 6.4 The Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cr… wordfence
4b68eed4-0d2f-441b-88be-f0e4f5d35cff
< 1.8.67
MEDIUM 6.4 The GPT3 AI Content Writer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
4b60c1e2-5a4b-4a7a-8224-f1afd3888e08
< 2.4.6
MEDIUM 6.4 The Responsive Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter i… wordfence
4b4de145-bff1-4265-97bf-4085b4112a66
< 1.0.16
MEDIUM 6.4 The Mail Picker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.… wordfence
4b4830f3-2d8d-46ab-b317-a0b45a0d3501 MEDIUM 6.4 The Responsive iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu… wordfence
4b47478f-3bd5-4eda-897f-4570aea4530a
< 2.1.2
MEDIUM 6.4 The WP Extended Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in … wordfence
4b468c0b-88ac-4ea8-97a9-08e206faf0fb
< 7.1.19
MEDIUM 6.4 The Quiz And Survey Master plugin plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and incl… wordfence
← Prev 672 673 674 675 676 677 678 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top