πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 938 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4d1e1b68-5c70-465b-ab54-069cc6b492a8 MEDIUM 6.1 The Upload Scanner plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
4d1c6daf-1799-4f8a-81e3-ef3968f41b8e MEDIUM 6.1 The Gravity Forms Toolbar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter i… wordfence
4d13ae87-f632-4eb0-bc71-5132ba6a9b13 MEDIUM 6.1 The AdFoxly – Ad Manager, AdSense Ads & Ads.txt plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v… wordfence
4d00b9b4-3822-465b-84e4-1721e2cb387c MEDIUM 6.1 The Limit Bio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
4cfee2e2-3486-4be8-954f-6d7f9b6d54ec
< 1.10
MEDIUM 6.1 The Classima theme for WordPress is vulnerable to Reflected Cross-site Scripting in versions up to 2.1.11 due to insuffi… wordfence
4cfb2dd0-d8f8-48ce-bcf4-be4763cabb02 MEDIUM 6.1 The CNZZ&51LA for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
4cf7befb-2b55-44f2-8401-f9823ead3f56 MEDIUM 6.1 The Tennis Court Bookings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
4ce8258f-64f7-4d5e-870a-973500eed0eb
< 1.1.1
MEDIUM 6.1 The Easy Digital Downloads (EDD) Conditional Success Redirects extension for WordPress, as used with EDD 1.8.x before 1.… wordfence
4cc568b3-cb1c-4d17-87ad-b8b2fdf45391
< 3.0.0
MEDIUM 6.1 The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPr… wordfence
4cad38bf-99b9-4bca-b1c0-d90bd2c60a28
< 1.5.6
MEDIUM 6.1 The CM E-Mail Blacklist – Simple email filtering for safer registration plugin for WordPress is vulnerable to Reflecte… wordfence
4ca15d79-86eb-4425-a2e0-22735305c12f MEDIUM 6.1 The Time Sheets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2… wordfence
4c9b61e4-1fa8-4908-a218-7402a7e47f31 MEDIUM 6.1 The AtaraPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in version… wordfence
4c929ac5-bd12-4aa3-8797-96ad140daf3e
< 1.0.2
MEDIUM 6.1 The Demo Awesome plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
4c878e15-8139-48bc-93db-9b3c5cbf0185
< 3.19
MEDIUM 6.1 The Kalium theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.18.3 … wordfence
4c82f6fe-1d6a-4d19-8234-6e27d70f9749 MEDIUM 6.1 The Content Security Policy Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
4c7fa6ca-a573-4c84-af44-d9d799741728
< 1.0.1
MEDIUM 6.1 The Easy Pie Coming Soon plugin for WordPress is vulnerable to Cross-Site Scripting via the 'tab' parameter in versions … wordfence
4c6e444a-3737-46ab-b5e8-b0c1f215050a
< 2.1.2
MEDIUM 6.1 The WordPress Multisite User Sync/Unsync WordPress plugin before 2.1.2 does not sanitise and escape the wmus_source_blog… wordfence
4c5dc867-c169-4adb-8d75-9617e6813af4
< 3.2.2
MEDIUM 6.1 The Sprout Clients plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
4c5a6436-1a08-4b3d-ab85-e5f75f216ab8
< 10.0
MEDIUM 6.1 The StageShow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg wi… wordfence
4c478d96-7735-4fbb-968b-4bd1d1268cd9
< 6.5.1
MEDIUM 6.1 The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'afirstname' para… wordfence
4bfeff72-27de-46a9-b947-f60255b5d062 MEDIUM 6.1 The Subitem AL Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']… wordfence
4beb01c1-2144-4b1f-9d32-cf2725a8d4ae MEDIUM 6.1 The Pollin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'question' parameter in all vers… wordfence
4bde3103-76c1-42f0-87b7-cb6b4f6d3204 MEDIUM 6.1 The Protect Your Content plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
4bd90ca2-85ae-42e3-b2a0-fae6ec28d6b3
< 5.0.3
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the WP Photo Album Plus plugin before 5.0.3 for WordPr… wordfence
4bd344ad-2259-408f-9867-a004b1f960ea
< 3.2.6
MEDIUM 6.1 The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 3.2.6 due to insuffic… wordfence
← Prev 935 936 937 938 939 940 941 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top