ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 942 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
488bba29-5586-4969-9816-ddef5eee034a
< 1.2.1
MEDIUM 6.1 The Bopo – WooCommerce Product Bundle Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in … wordfence
4888a1dc-ed12-41c0-910b-6c9740a54ef0 MEDIUM 6.1 The Twitter Friends Widget WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the pmc_TF_user and pmc_… wordfence
4881f21c-a8ab-4a20-aaab-4b44804d3709 MEDIUM 6.1 The Advanced Custom CSS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
487e5add-726c-4cfc-b86e-bb4eeec168a3
< 1.3
MEDIUM 6.1 The Embed videos and respect privacy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'v' pa… wordfence
487a6c5e-226b-4b30-a402-bd5132d17ea8 MEDIUM 6.1 The Copyright Proof WordPress plugin through 4.16 does not sanitise and escape a parameter before outputting it back via… wordfence
485cf8c9-493b-441f-a741-fccb09250052 MEDIUM 6.1 The Skillate theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2.1… wordfence
485a716a-4541-44e0-98b1-1a607439c66c
< 2.4.10
MEDIUM 6.1 The Small Package Quotes – Unishippers Edition plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… wordfence
4852bd93-032f-4e11-ac30-7268684f08e2
< 2.2.0
MEDIUM 6.1 The Yoo Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.… wordfence
484d8d14-049d-4fd5-adb8-ad9942bba794 MEDIUM 6.1 The Mighty Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
481dc27b-0d64-49cc-8d67-50fa53636398 MEDIUM 6.1 The WP AutoBuzz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
48173a09-302c-49a1-8c6c-ac4ecacea080 MEDIUM 6.1 The Theme Switcher Reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … wordfence
47feeeef-07ff-42a1-a94d-b90c25cce2e6
< 5.5.4
MEDIUM 6.1 The WooThumbs for WooCommerce by Iconic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions… wordfence
47cc9978-6074-4e8a-a471-d8483890d161
< 1.0.31
MEDIUM 6.1 The plugin does not sanitise and escape its StoryChief Key setting before outputting it in an attribute, leading to an A… wordfence
47c2bf75-fba1-4c37-b33a-f5e0e093fb78
< 1.5.5
MEDIUM 6.1 The SpiderVPlayer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versio… wordfence
47b687f4-8798-4cd9-b0d0-11c54df8ff46 MEDIUM 6.1 The Widget4Call plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, … wordfence
47941722-acaf-4f72-a64d-d01dc5e84adf
< 6.4.7
MEDIUM 6.1 The Complianz plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in version… wordfence
47906575-b88a-4e12-b134-accf47a264a0
< 1.5.0
MEDIUM 6.1 The time-sheets plugin before 1.5.0 for WordPress has XSS via the old timesheet list. wordfence
478b67e3-bd66-4f38-8a37-e677e5db875d MEDIUM 6.1 The Resim Ara plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'kelime' parameter in the ‘… wordfence
478723c4-cc45-4241-af45-21ee537f1dfa MEDIUM 6.1 The Better WordPress reCAPTCHA plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cerror’… wordfence
47765ab9-1df6-4457-8d94-6e2092e6a5a4
< 2.0.22
MEDIUM 6.1 The Distance Based Shipping Calculator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versi… wordfence
475c9bec-0fd5-4de7-a8a3-8aea5dd4c68d
< 1.8.16.0
MEDIUM 6.1 The WP Mailster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
4744edff-d130-4f45-93a0-a67ec91dbe10
< 7.11.35
MEDIUM 6.1 The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity … wordfence
4739ec47-9434-4342-a25f-43b8ef568fec MEDIUM 6.1 The Youneeq Recommendations plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
4735dfe7-ad24-4427-8760-64ff4acd95ed MEDIUM 6.1 The WP User Stylesheet Switcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
47304b6e-6fea-4acd-bd5b-a4a65e15db9b MEDIUM 6.1 The Anything Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
← Prev 939 940 941 942 943 944 945 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top