🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 677 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4a8ac027-f376-4f02-a085-f05f1fa749f0 MEDIUM 6.4 The Elemenda plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up t… wordfence
4a89c812-a643-47c0-bd33-cfb2389a7646
< 1.10.3
MEDIUM 6.4 The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute … wordfence
4a75444e-b1e4-41e0-9209-07ded65c1498 MEDIUM 6.4 The Go Night Pro | WordPress Dark Mode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'… wordfence
4a7345a1-ceb5-4f93-a6ba-13e8b8fb6c7d
< 4.0.3
MEDIUM 6.4 The MainWP Clone Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, … wordfence
4a4e1d08-a61d-40b8-bfbb-c112c77dd412 MEDIUM 6.4 The best bootstrap widgets for elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
4a4c745b-f489-417c-8004-ead131a7a6c6
< 6.4.23
MEDIUM 6.4 The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Stored Cr… wordfence
4a433565-0896-4ba9-a718-9507c6c4ba58
< 1.1.6
MEDIUM 6.4 The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vodsChan… wordfence
4a2ef416-4354-4e09-b9be-e36c1f655110
< 4.1.11
MEDIUM 6.4 The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fol… wordfence
4a1e77de-0207-412d-857d-ab6947116669
< 2.5.1
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in WordPress 2.5 allows remote attackers to inject arbitrary web script or HTML… wordfence
4a13c7a1-f904-41b1-ab7f-2df95c9b2880
< 2.7.2.1
MEDIUM 6.4 The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sett… wordfence
4a13b13e-72d3-43c9-b5ec-d499f3b22091
< 1.0.6.5
MEDIUM 6.4 The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Store… wordfence
4a0c744a-d4b0-45f4-9434-06ce3dec4d75 MEDIUM 6.4 The Spotify Embed Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spotify' s… wordfence
49f01cc7-6e64-45cc-bc54-b263e47fe1a3 MEDIUM 6.4 The Ronneby Theme Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
49ef0bfe-9bdf-4117-81f7-1ec73b5247ae
< 2.14.24
MEDIUM 6.4 The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
49e9436b-c5b1-4373-bca5-60f718abba26 MEDIUM 6.4 The AnyClip Luminous Studio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
49cf047f-4e8c-4f37-b8c0-d931c02fda7c
< 3.8.2
MEDIUM 6.4 The Fruitful Theme for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters stored via the frui… wordfence
49cb8324-2245-4f7d-b289-d2313af4642e
< 5.3.7
MEDIUM 6.4 The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
49b76f5f-03f7-48bc-b848-9ab55d875639 MEDIUM 6.4 The ZoomSounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and i… wordfence
49a9ade1-fca7-48c1-bb87-75fc3528e234
< 1.2
MEDIUM 6.4 The Easy SVG Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio… wordfence
4999bbf3-3dbd-4c9a-b648-744192c9586c
< 5.0.3
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_button sh… wordfence
49958e9e-7f9b-48fb-bfe2-5b1b437171d6
< 1.2.0
MEDIUM 6.4 The BMLT Tabbed Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_tabbed_map'… wordfence
49945253-b631-47b2-9cbd-42c9effc60f4
< 2.2.7
MEDIUM 6.4 The Donation Thermometer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
498c0080-ae5e-492b-b75f-6ce3227f3ca0
< 3.1.2
MEDIUM 6.4 The Paytium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'get_field_data_html()' function i… wordfence
49816cc8-fc97-4ba2-88b6-3fe6f7bf562e
< 2.1.2
MEDIUM 6.4 The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… wordfence
497e0784-8953-4726-929a-7d5ef129e98e
< 1.6.8
MEDIUM 6.4 The Formzu WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all ver… wordfence
← Prev 674 675 676 677 678 679 680 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top