πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 940 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4ac71fdb-4f1e-4177-a9a2-3776f22e4400
< 4.7
MEDIUM 6.1 The SERPed.net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.… wordfence
4ac68b80-31ce-4e61-b3ab-0f43cda64125
< 1.7
MEDIUM 6.1 The Simple Mail Address Encoder plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions before… wordfence
4ab78b31-fce5-44e6-8613-b53f16077a95 MEDIUM 6.1 The ImageMeta plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
4aad3bc3-6b8e-41c4-b362-77834ae98bfa
< 3.1.6
MEDIUM 6.1 The PlainInventory – Inventory Management Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
4aa9387d-5a6b-4016-98c7-025feab3d45b MEDIUM 6.1 The ClipArt plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 0… wordfence
4aa0e496-3dcd-49ac-a519-16b1648c5871
< 8.2.2
MEDIUM 6.1 The Quick Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
4a9fce6d-d5c2-4ab7-87ea-8dd6e4d92e07
< 2.790
MEDIUM 6.1 The Post Pay Counter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'orderby' parameter in… wordfence
4a9df582-0ead-45ff-aeaa-1bee9d470b41
< 4.5.3
MEDIUM 6.1 wordfence
4a984bd8-ca43-4676-9985-b111111c17ab MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the Thank You Counter Button plugin 1.9.3 for WordPress allow rem… wordfence
4a85de70-7cb1-45d1-b872-0677ef8134be
< 2.6
MEDIUM 6.1 The Interactive Medical Drawing of Human Body plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t… wordfence
4a71fda4-3c67-4053-ac1e-9cf3f5feb8c8
< 2.6.3
MEDIUM 6.1 Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arb… wordfence
4a66b704-2f85-47df-83e7-12058b85d86b MEDIUM 6.1 The Listify theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.5 … wordfence
4a4d58f3-fbd6-4237-a226-c14439546c58
< 4.27.5
MEDIUM 6.1 The Sonaar theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.2… wordfence
4a3f1e3d-8b34-4e6a-90f3-da50201fe896 MEDIUM 6.1 The First Comment Redirect plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
4a2c11bb-88cb-43ae-b9b7-5b6262a315e0
< 1.3.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 Premium for WordPress a… wordfence
4a1d6657-d8bc-4145-96b0-f85e752060f4 MEDIUM 6.1 The Auto FTP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.… wordfence
49fe6b97-2c5d-4829-a72f-2bcbc10550b5 MEDIUM 6.1 The Free MailClient FMC plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
49fe478e-b553-4eb5-851b-69319eb4dbc3 MEDIUM 6.1 The Customizable Captcha and Contact Us plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions… wordfence
49f572ab-befe-44a3-b4bd-01b39d4209ca MEDIUM 6.1 The WP-Banners-Lite plugin for WordPress is vulnerable to Cross-Site Scripting via the 'cid' variable in versions 1.29, … wordfence
49e82146-e8ad-4bc5-94a7-a4ae694b7039
< 5.5.6
MEDIUM 6.1 The bbp style pack plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in vers… wordfence
49e741c9-0cc7-4a62-a920-4fd997bee280
< 2.3.2
MEDIUM 6.1 The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t… wordfence
49cba28f-43dc-4947-b4bb-8556cc0409ee
< 1.0.28
MEDIUM 6.1 The Table & Contact Form 7 Database – Tablesome plugin for WordPress is vulnerable to Reflected Cross-Site Scripting i… wordfence
49c717eb-3320-41aa-8dfe-eb23ac7544d6 MEDIUM 6.1 The Stray Random Quotes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … wordfence
49c6e8bb-4470-4602-a884-ac61c4e64976
< 2.0.1
MEDIUM 6.1 The Backend Localization plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'kau-boys_backend_… wordfence
49bdd84a-05c0-4c7c-9d12-8a8eec91908d
< 5.1
MEDIUM 6.1 The Network Publisher plugin for WordPress is vulnerable to Cross-Site Scripting via the 'networkpub_key' parameter in v… wordfence
← Prev 937 938 939 940 941 942 943 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top