🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 941 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
49b2e332-4359-4dac-8a9e-1d71f39d509c MEDIUM 6.1 The Widget Bundle plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
49ad558f-57a5-4055-a0fc-3a991dbe2b8c MEDIUM 6.1 The Killer Theme Options plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
49a0e79c-b8cd-4ad4-8e59-615ffab5d355 MEDIUM 6.1 The WP SpaceContent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
4989a3b1-eb76-42b1-b84e-6c4553aedb89 MEDIUM 6.1 The Blubrry PowerPress Podcasting plugin MultiSite add-on plugin for WordPress is vulnerable to Reflected Cross-Site Scr… wordfence
496249cf-f75e-42e6-a189-332dd73d14bd MEDIUM 6.1 The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX act… wordfence
49618d9f-e6d8-40d5-b19f-7ce987939172 MEDIUM 6.1 The Custom Banners plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg … wordfence
495df695-864e-4a77-bcd1-d1845c55a6c9
< 2.6.2
MEDIUM 6.1 The WP Abstracts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'login' and 'key' paramete… wordfence
494f5c9f-ef5b-48d8-8f3a-27e5ed4bea5e MEDIUM 6.1 The Wonder FontAwesome plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
494dc869-6f4d-428b-99a8-87212f3007be
< 5.3.8
MEDIUM 6.1 The WooCommerce Multilingual & Multicurrency with WPML plugin for WordPress is vulnerable to Reflected Cross-Site Script… wordfence
4919eb4d-fed8-42b3-8283-7dbf6c1abf12
< 2.1.3
MEDIUM 6.1 The Organici Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
48f69a86-1007-4565-8311-9e542bd4d66b
< 3.2
MEDIUM 6.1 The Advanced Sermons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s' parameter in ver… wordfence
48ee0d97-40c1-451f-8a5f-b32ff032e8b0
< 2.2.15
MEDIUM 6.1 The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do no… wordfence
48ebeb6a-c585-4ddc-92ab-144f66193991
< 1.7.6
MEDIUM 6.1 The Coming Soon by Supsystic WordPress plugin before 1.7.6 does not sanitise and escape the tab parameter before outputt… wordfence
48dd4beb-73c3-476b-b06c-cfa2e078fd8d MEDIUM 6.1 The Comments On Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
48db673c-f978-45f4-9d7b-eddd81cee62e
< 2.2.5
MEDIUM 6.1 The Schema App Structured Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad… wordfence
48c9f263-29d8-4db4-879d-1b8bd59191f7
< 11.7
MEDIUM 6.1 The CSS3 Compare Pricing Tables for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in ve… wordfence
48c4372c-1c27-4261-b0ae-85b9117c5dde
< 3.7.4
MEDIUM 6.1 The Raptive Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3… wordfence
48c40f60-d919-41d9-a2d9-8dad1f03db5c
< 3.4.1
MEDIUM 6.1 The InJob theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘iwj_tab’ parameter in version… wordfence
48b6b9a3-c80d-4fde-9e8c-1f60781b7484
< 4.0.5
MEDIUM 6.1 The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and fil… wordfence
48b4214f-b722-405e-9bb7-a1faa68f0429
< 3.0.7
MEDIUM 6.1 The Cardinity Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t… wordfence
48b31324-c6a3-4550-939e-06f7b3c7067a
< 1.1.9
MEDIUM 6.1 An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filt… wordfence
48b1c1e6-a3bc-469b-aadc-fe15ce877c67 MEDIUM 6.1 The A5 Custom Login Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
48b0d7ad-f4d6-45b5-8694-e41551728e83
< 5.4.8
MEDIUM 6.1 The Eduma plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 5.4… wordfence
48a572f1-a583-4f77-8719-b553654f021e MEDIUM 6.1 The Legacy Admin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
4891055a-04b2-453d-a2ea-2fb793705ff8
< 1.9.5
MEDIUM 6.1 The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is ac… wordfence
← Prev 938 939 940 941 942 943 944 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top