🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 686 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
425cd0be-d17e-4c2b-bf29-3b850905a88e
< 1.8.9
MEDIUM 6.4 The WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout plugin for WordPress is vulner… wordfence
425af1b6-3db9-44bc-8bea-29f2912eef87
< 3.2.9
MEDIUM 6.4 The Ni WooCommerce Cost Of Goods plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
424c23f7-73a4-4b2b-8f52-61cb45523396 MEDIUM 6.4 The Digital Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘column’ param… wordfence
424b2145-2fe2-48b8-bb4f-08fe23a6100f
< 5.8.1
MEDIUM 6.4 The WP Scraper plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5… wordfence
424a3b93-5cf6-4706-acab-0ee89f05c073 MEDIUM 6.4 The User Avatar - Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
4241118f-9bcb-4dec-abd2-7172db2cf445
< 2.2
MEDIUM 6.4 The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' … wordfence
423e840e-0bc2-4481-afff-61ace85788d3 MEDIUM 6.4 The WOW Entrance Effects (WEE!) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wee'… wordfence
41fdb3ea-1de4-4b90-a387-5932de7a5e7c
< 0.13.3
MEDIUM 6.4 The IndieBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘kind’ parameter in all ve… wordfence
41fc7e7e-c9bb-434a-9960-7f0f2292d922
< 1.2.5
MEDIUM 6.4 The Maps for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.… wordfence
41f6e826-9326-40fa-80d0-4cff1dd72536
< 9.3
MEDIUM 6.4 The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various sho… wordfence
41f6b12e-49bb-4bee-bbde-ce4e5ebd4cad
< 1.3.3
MEDIUM 6.4 The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… wordfence
41f3045f-94a3-45c4-8baa-7f198b8c24bc
< 2.1.6
MEDIUM 6.4 The BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library plugi… wordfence
41e2c557-e462-4d9e-916c-b8352a6df571
< 2.88.15
MEDIUM 6.4 The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via map titles in all … wordfence
41c54e1b-69b9-4594-8f1e-7ef17f120791
< 7.0.0
MEDIUM 6.4 The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulne… wordfence
41b2a4cc-fb23-41eb-b1a4-d793ae924d9a
< 3.3.4
MEDIUM 6.4 The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via mu… wordfence
419cf912-3187-43d7-90ab-1a20a46d86e4
< 2.1.4
MEDIUM 6.4 The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to… wordfence
41859e1c-1ae0-49f1-82d3-5af3c15994ef
< 3.4
MEDIUM 6.4 The Advanced Sermons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sermon_video_embed’ … wordfence
417f636d-1b60-413a-949e-89c113e636e6
< 1.1.1
MEDIUM 6.4 The reCAPTCHA for Asgaros Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
417b9dfe-2571-4816-af55-c7cb7dfa62c6
< 1.10
MEDIUM 6.4 The Clinked Client Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'clinked-lo… wordfence
416da317-61dc-42b5-9ade-fa41e844263b
< 4.1.2
MEDIUM 6.4 The MainWP White Label Extension plugin for WordPress is vulnerable to authorization bypass in versions up to, and inclu… wordfence
415bfddb-5223-439f-8a08-535f79631ff0
< 1.44.2
MEDIUM 6.4 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored C… wordfence
415a7201-bdff-4342-9e06-ce0e500cdc7c
< 3.11.0
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribu… wordfence
41479533-592d-4438-8162-48975b8a78a7 MEDIUM 6.4 The StorePress theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.12… wordfence
41437186-8802-4496-a79c-b01f7c93e486 MEDIUM 6.4 The WP EASY RECIPE plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
414173b9-d23e-4e44-bf8c-77a074bb09e9
< 1.6.8.32
MEDIUM 6.4 The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to S… wordfence
← Prev 683 684 685 686 687 688 689 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top