🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 944 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
45cf9e0e-3a8a-400a-b766-7b352e739b7c MEDIUM 6.1 The Bizapp for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error' paramete… wordfence
45c08d51-ed01-4f92-9290-1964c4f3657c
< 2.2.9
MEDIUM 6.1 The weeklynews theme before 2.2.9 for WordPress has XSS via the s parameter. wordfence
45ba8203-a8a0-4330-a264-c2f555d09ef0
< 3.8.8
MEDIUM 6.1 The Import Export All WordPress Images, Users & Post Types plugin for WordPress is vulnerable to Reflected Cross-Site Sc… wordfence
45a1490f-1cfe-4a88-a5a2-ff01e794d7d3 MEDIUM 6.1 The HTML5 Video Player with Playlist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up… wordfence
4598202a-f883-44c9-83bf-e8b72e418e3a
< 1.8.8
MEDIUM 6.1 Persistent Cross-Site Scripting (XSS) vulnerability in Vsourz Digital's Advanced Contact form 7 DB plugin <= 1.8.7 at Wo… wordfence
4591fb15-a280-42d2-91f6-6c33bbe64e22 MEDIUM 6.1 The Hotspots Analytics plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
45873654-bf0d-4538-b07c-56ed8db3bafb
< 1.15.20
MEDIUM 6.1 The Booking Activities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
456f038c-85a4-426e-b9e0-3acf91f9b93a
< 1.8.7
MEDIUM 6.1 The Easy Digital Downloads Plugin for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before … wordfence
456bae19-6626-4505-828e-dbf3e576ad10 MEDIUM 6.1 The vooPlayer v4 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
45671cab-f719-4ee6-af81-7c19b37b8d91 MEDIUM 6.1 The Restrict Categories plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘rc-search’ par… wordfence
455d7ee8-9a5a-41f6-b0ae-c55f04b41e52
< 1.30
MEDIUM 6.1 The AdPush plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the custom email filed in versions u… wordfence
4553a7e7-6f87-4e23-b96e-2cf845d6ba60 MEDIUM 6.1 The User Referral plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
4541ab5d-5c99-46e8-bc78-fa2c5cffd09b
< 1.0.9
MEDIUM 6.1 wordfence
4541a7e1-4e46-4681-83e3-1c2e38396204 MEDIUM 6.1 The Scribble Maps WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the map parameter in the ~/includ… wordfence
453c0267-c69c-4f70-86f7-eda320a3da05
< 1.1.3
MEDIUM 6.1 The MediaView plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1… wordfence
453b246f-7e39-4adb-9506-77d96146ab50 MEDIUM 6.1 The 4stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9.… wordfence
4532547d-9077-47cc-80ba-bf855cd3f22b MEDIUM 6.1 The Ni WooCommerce Bulk Product Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versi… wordfence
452ed03a-2f02-417d-93c9-d883a616a153
< 0.4.10
MEDIUM 6.1 The CallRail Phone Call Tracking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… wordfence
4528a772-6758-4a6e-a325-5f9fd9f1b71d MEDIUM 6.1 The WooCommerce myghpay Payment Gateway WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the clientre… wordfence
45260858-0a18-48c0-a3a9-2d5c4649ae5a
< 1.11.4
MEDIUM 6.1 The URL Shortify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
4522480a-dfbf-4ff4-93c2-68b8cc15367c
< 1.5.6
MEDIUM 6.1 The Google Analytics Top Content Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unes… wordfence
451d4ecd-f3d7-4029-8d39-85d2a7ed459c
< 2.10
MEDIUM 6.1 The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab'… wordfence
4517bd04-20ce-4686-a933-d34464a5b691
< 1.26
MEDIUM 6.1 The RokStories plugin for WordPress is vulnerable to Cross-Site Scripting via the 'src' parameter in the 'thumb.php' fil… wordfence
4515507c-a0a4-4e45-8112-fedd117e425f
< 1.2.66
MEDIUM 6.1 The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_ed… wordfence
45104ab0-4a07-4b0f-9d98-04857a5f01a8
< 8.59
MEDIUM 6.1 The UNIVERSAM plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 8.59 due to insuffi… wordfence
← Prev 941 942 943 944 945 946 947 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top