🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 937 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4e54613a-24c7-4e2d-a14b-07912acfb69a MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in admin/admin_show_dialogs.php in the WP Consultant plugin 1.0 and earlier for… wordfence
4e4dab1c-357f-440f-b3c7-598834a16599
< 6.2.6
MEDIUM 6.1 The wp-file-download plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… wordfence
4e3cb44c-ed14-42d5-9e26-0904978bd2a4 MEDIUM 6.1 The Media Category Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
4e383235-8f61-46f2-bd54-cc41e3ec189e
< 1.5.4
MEDIUM 6.1 The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the p… wordfence
4e376fce-48a7-4b33-8a5a-9402625d24c0 MEDIUM 6.1 The MapFig Studio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
4e30c4fd-91fd-4f05-85fa-73e445de3c6e
< 5.9.12.30
MEDIUM 6.1 The link-library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘'successimportcount’ … wordfence
4e262772-06b7-4490-a342-5b1abc421b67 MEDIUM 6.1 The BMI BMR Calculator WordPress plugin through 1.3 does not sanitise and escape arbitrary POST data before outputting i… wordfence
4e054485-71cc-47c2-9bd6-4f060dc76738 MEDIUM 6.1 The WPB Show Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fileList’ parameter … wordfence
4e04b161-3cd0-454d-869c-56f42bd8afb0
< 22.6
MEDIUM 6.1 The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and i… wordfence
4e018ce5-ec78-42a9-ab70-4fb3eaa347b9 MEDIUM 6.1 The pushBIZ – Push Notification plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions u… wordfence
4dee07a1-9f48-4e8f-89dc-99270f55f17c
< 2.3
MEDIUM 6.1 The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting i… wordfence
4deca6fe-561e-41a9-aaf6-308fde0b0d1b MEDIUM 6.1 The CF7 Spreadsheets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
4dea175f-3728-4aee-9296-1bb595c83925
< 5 alpha 3
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in ui_stats.php in the bSuite plugin before 5 alpha 3 for WordPress … wordfence
4db5d4ec-0f49-40fb-97b3-f0146cbbbe52
< 3.1.8
MEDIUM 6.1 The WP-Members plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 3.1.8 due to insufficient i… wordfence
4d902dfe-f16d-4795-9fcf-ee454b3d8c56
< 9.7.1
MEDIUM 6.1 The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7… wordfence
4d8056cb-58e5-468b-9316-c862c6d8c930
< 1.0.2
MEDIUM 6.1 The WooFramework Tweaks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in versions up to… wordfence
4d7f4d17-8318-4ab3-b4a2-81d7a017c397
< 3.1.42
MEDIUM 6.1 The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerabl… wordfence
4d63c11c-edf8-4b37-9701-e21d5f7b5a9b MEDIUM 6.1 The Google Map With Fancybox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… wordfence
4d5ed607-4ab4-4e98-975b-e3043014d847 MEDIUM 6.1 The Site PIN plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3 … wordfence
4d5a7f60-0850-4322-a7d8-8e5c144efe51
< 5.4.18
MEDIUM 6.1 The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘walbum’ parame… wordfence
4d4ce8ce-2630-4f8b-9438-38c6b7b0caa9
< 3.9
MEDIUM 6.1 The BSK Forms Blacklist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
4d3e6c49-e686-463c-bc50-b0ce94702075
< 1.1.0
MEDIUM 6.1 Authorize.net Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). wordfence
4d32eae6-f49f-403b-b295-c72b1486c71c
< 2.5.2
MEDIUM 6.1 The Greenmart theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'callback' parameter in the 'a… wordfence
4d2b8bc2-68c2-40aa-b8b0-a0584549f303
< 3.4
MEDIUM 6.1 The Secure HTML5 Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the flowplayer-3.… wordfence
4d1e9de3-da94-4f90-b72a-b38d5d131246
< 1.1.7
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Floating Social Bar plugin before 1.1.7 for WordPress allows remote atta… wordfence
← Prev 934 935 936 937 938 939 940 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top