πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 936 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4f32d1fe-17ea-48c0-b276-36c8fcaad4a6
< 1.8.2
MEDIUM 6.1 The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, not includ… wordfence
4f2fdc9d-891e-49c6-9427-620772336854
< 2.29.4
MEDIUM 6.1 The SureCart plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.29… wordfence
4f2eccc6-8e66-4235-aec3-9948b8753bf6
< 0.0.7
MEDIUM 6.1 The TNIT Filter Gallery Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting … wordfence
4f23bec2-6079-41f6-99c1-80b0b47797ce MEDIUM 6.1 The Facebook Page Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the inclusio… wordfence
4f14e464-cf48-4f8a-a1db-a8adced8321f MEDIUM 6.1 The WP-T-Wap WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the posted parameter found in the ~/wa… wordfence
4f0ea05c-b170-438e-a767-aa57b5a34df8
< 4.3.1
MEDIUM 6.1 The Jobify theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.3.0 d… wordfence
4f0025dc-a072-4e01-bea8-6e93948f00d8
< 6.3.5
MEDIUM 6.1 The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting… wordfence
4efc2b96-4810-4e25-b150-c6c96246d7c5 MEDIUM 6.1 The WP SexyLightBox plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
4ee9f9c6-5725-41aa-85ad-9a7f43aa3a1b MEDIUM 6.1 The Custom Product Stickers for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in vers… wordfence
4edd7624-aa1e-49a5-a8c4-c15baea7bc3c
< 1.5.9
MEDIUM 6.1 The MyDecor theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 1.5.9 due to insuffici… wordfence
4ecf04a7-1f3c-41d6-a86b-282f020de088
< 1.9.8
MEDIUM 6.1 The NextGen Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via swfupload.swf in versions u… wordfence
4ec30511-40cb-433e-977c-df5be8c3d8f2
< 4.4.4
MEDIUM 6.1 The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripti… wordfence
4eaefe2d-b7f8-49ed-8ba1-833e888857b8 MEDIUM 6.1 Cross-site Scripting (XSS) in the spreadshirt-rss-3d-cube-flash-gallery plugin through version 1.3 for WordPress allows … wordfence
4eab9a5e-ca51-4952-9fd4-3d0046402e29
< 6.1.5
MEDIUM 6.1 The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider par… wordfence
4ea19d9e-c327-4d4d-bd6e-6cd05ccfc508 MEDIUM 6.1 The LikeBot – Decentralized like-system plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
4e89329d-5eef-4128-a871-544dc0498aba MEDIUM 6.1 The Dental Optimizer Patient Generator App plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all v… wordfence
4e7e4601-337f-4e4e-b265-63f68f8f8d73
< 1.17.7
MEDIUM 6.1 The Interactive Content – H5P plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
4e79461b-871c-4ce3-bb85-bfbc2af4f639 MEDIUM 6.1 The Simplistic SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
4e6ef932-975c-423b-b780-b38449eec577
< 1.7.9
MEDIUM 6.1 The Loginizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜limit_session[count]’ pa… wordfence
4e6d4ad1-0fcc-43d9-b997-126782718c28 MEDIUM 6.1 The Short URL plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
4e6c63de-a1cc-4b43-903e-b0a78c614184 MEDIUM 6.1 The Advanced Angular Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions u… wordfence
4e648f65-3eeb-405d-b243-26354f3843c8
< 8.2
MEDIUM 6.1 The SEOPress – On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_… wordfence
4e63a30d-a071-40f4-b603-f4fea73a51c4 MEDIUM 6.1 The WP Contest plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… wordfence
4e57e1c8-0b4c-4e94-a6ac-b8972389510f MEDIUM 6.1 The SoundSt SEO Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
4e575468-6f39-478c-972f-e73bef76dad5 MEDIUM 6.1 The Adsmonetizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
← Prev 933 934 935 936 937 938 939 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top