πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 935 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4fe0df91-21f0-4eef-8064-2b283f38b181 MEDIUM 6.1 The World Travel Information plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜$_SERVER['P… wordfence
4fd7af43-5b49-4c4c-a51c-0cce5529ea1b
< 3.12.0.1
MEDIUM 6.1 The FunnelKit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.1… wordfence
4fd4d30b-f37f-4083-acfe-8e85c075da10
< 7.13.30
MEDIUM 6.1 The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape t… wordfence
4fcd03cd-87c9-4378-ae42-3715ca3a1cb8 MEDIUM 6.1 The Social2Blog plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
4fc8deda-9fb3-41e5-850b-5109d4018027
< 1.44
MEDIUM 6.1 The AdPush plugin for WordPress is vulnerable to multiple Cross-Site Scripting in versions up to, and including, 1.43 du… wordfence
4fc82778-0493-456f-bc73-3d70e3a2b1bf
< 1.2.7
MEDIUM 6.1 The Popularis Extra plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg… wordfence
4fbfec7f-2e96-432c-ade4-c9b96adcaf88 MEDIUM 6.1 The Social Media Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
4fbeee29-751a-48c9-a875-393441f62dde
< 1.1.9
MEDIUM 6.1 The Lingotek Translation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜sm’ parameter… wordfence
4fb06315-30ad-4d98-af75-b04933583be7 MEDIUM 6.1 Multiple plugins for WordPress by KlbTheme are vulnerable to Reflected Cross-Site Scripting in various versions due to i… wordfence
4faf5d1f-604d-4174-8b83-8779cc83ac4c MEDIUM 6.1 The Post Carousel Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
4fa979e8-2569-4d6c-9eee-344972000aab MEDIUM 6.1 The Trendy Travel theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
4fa5f0a2-30e9-4e89-a509-25a7fe8a643b MEDIUM 6.1 The Contact Form Builder, Contact Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in version… wordfence
4fa3de8b-3d51-46b4-92ef-fbebadd4e708 MEDIUM 6.1 The CopyLink plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.… wordfence
4f9e0328-6d38-4512-a233-82e37950eb80 MEDIUM 6.1 The GB Gallery Slideshow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
4f98d50a-51cb-479b-be4c-566a72f0f221
< 0.7
MEDIUM 6.1 The supportflow plugin before 0.7 for WordPress has XSS via a ticket excerpt. wordfence
4f856b92-a090-4974-a256-d1022b10014a
< 1.9.0
MEDIUM 6.1 The Cool Flipbox – Shortcode & Gutenberg Block plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… wordfence
4f7fa392-e192-40db-9275-6da668d5a493
< 4.8
MEDIUM 6.1 The Team Rosters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
4f7bc717-8b6a-41f2-9587-33b44d51996a MEDIUM 6.1 The ZenphotoPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
4f5b048d-3a00-4337-8a85-97740449f1a5 MEDIUM 6.1 The Formatted post plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
4f5919eb-ac74-4926-9ede-e651bb4463b2
< 3.13
MEDIUM 6.1 The Atarim plugin for WordPress is vulnerable to Cross-Site Scripting via the new_task parameter in versions up to, and … wordfence
4f510772-d1f6-4751-bfff-addb51bf27c6 MEDIUM 6.1 The WP tarteaucitron.js Self Hosted plugin for WordPress is running a vulnerable dependency (version 20210310 of tarteau… wordfence
4f49eaf0-1273-41e8-9087-4d4ed978fce4
< 1.2.2
MEDIUM 6.1 The Sharebar plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.1 due to i… wordfence
4f4934be-db95-4b4d-92df-f0d493f56f25 MEDIUM 6.1 The QMean – WordPress Did You Mean and Search Suggestion Like Google plugin for WordPress is vulnerable to Reflected C… wordfence
4f406c82-14e7-468b-8bba-400aefe687b5 MEDIUM 6.1 The Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.9.… wordfence
4f3a01fe-8c84-4219-98fe-14e4ac74b7f7
< 2.13.5
MEDIUM 6.1 The Infility Global plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
← Prev 932 933 934 935 936 937 938 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top