🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 676 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4b42ba6a-b618-4633-9372-879c3253a956
< 4.1.4
MEDIUM 6.4 The WC Marketplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4… wordfence
4b3380a1-ef0f-471f-b016-16f3431fb619 MEDIUM 6.4 The SimaCookie plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.2… wordfence
4b32e8b6-0365-411c-b262-12fe46521b73
< 4.2.4
MEDIUM 6.4 The افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) plugin for … wordfence
4b2fa1b7-a5af-4ea6-9bee-19a6cdfd7701
< 28.1
MEDIUM 6.4 The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cros… wordfence
4b1944a9-4bc4-4ac2-83c3-55d6d61f405c
< 1.1.4
MEDIUM 6.4 The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Stor… wordfence
4b1568d6-4fea-4ed3-9931-f293932eaa3a
< 0.9.32
MEDIUM 6.4 The Power's WHOIS Domain Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters … wordfence
4b0f0db2-13bc-48fd-b78c-9e0eb644aec1 MEDIUM 6.4 The GMap Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
4b002e40-712d-4c3f-b168-9132e7b77e60
< 1.3.2
MEDIUM 6.4 The Easy!Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyappointmen… wordfence
4afc8de7-0d7e-4dee-972e-3eb707cd7b2b MEDIUM 6.4 The Beek Widget Extention plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions u… wordfence
4afbe34b-121e-41d2-ab12-c3d70a0d80d5
< 1.5.6
MEDIUM 6.4 The Better Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nickname' field in all ve… wordfence
4afa0148-ad08-493d-9642-0edbde5e8349
< 1.3
MEDIUM 6.4 The Ragic Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ragic' shortcode… wordfence
4af9c623-1539-4afc-9dcd-3f97d29aa4f3
< 1.11.16
MEDIUM 6.4 The Easy Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feat… wordfence
4af762d6-bc93-4724-b27d-4873a8bb4f38
< 7.8.1
MEDIUM 6.4 The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to Stor… wordfence
4af66bb2-febe-4022-9526-39b1ecd8b01d
< 2.1.7
MEDIUM 6.4 The Site Search 360 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ss360-resultbloc… wordfence
4af2f136-5806-4d5e-a72d-486c4839a695
< 2.1.5
MEDIUM 6.4 The The Pack Elementor addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slider_options… wordfence
4af04219-26c5-401d-94ef-11d2321f98bf
< 3.5.1
MEDIUM 6.4 The Sponsors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sponsors' shortcode in … wordfence
4aebd497-d3c7-4a85-bde4-07e8eade836f
< 2.16.10
MEDIUM 6.4 The Seraphinite Post .DOCX Source plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t… wordfence
4ac7c825-aa5e-42fb-b1df-8be72945941c MEDIUM 6.4 The Catch Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catch-popup' shortco… wordfence
4ac57705-24ce-44b5-95d9-972bf58e4cd1
< 2.8.2
MEDIUM 6.4 The Page Builder: KingComposer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown paramete… wordfence
4ac29d1c-0aae-4355-90df-24c99d23c411
< 3.1.1
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in WordPress before 3.1.1 allows remote attackers to inject arbitrary web scrip… wordfence
4ab53ebb-c18e-4791-b4dc-84b84aea65c6
< 3.0.0
MEDIUM 6.4 The Nepali Date Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
4aa09e5b-fc3d-4409-bf2c-dd8aae69eeda MEDIUM 6.4 The quote-posttype-plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Author field in all … wordfence
4aa04db0-8878-42b7-a923-03257230a7c1 MEDIUM 6.4 The PhotoShelter for Photographers Blog Feed Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
4a920dd5-e4a0-4bc3-8eb8-58069d0ae336 MEDIUM 6.4 The Font Awesome WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
4a9021b4-54f8-4ba3-bc81-49271dde1b44 MEDIUM 6.4 The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
← Prev 673 674 675 676 677 678 679 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top