🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 945 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
44fd7e13-f48a-43c6-a735-15036aa03005
< 0.10.2
MEDIUM 6.1 The CodeColorer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in 'cc' comm… wordfence
44f64753-920f-4099-9cb1-018b24f972eb
< 1.0.2
MEDIUM 6.1 The On Page SEO + Whatsapp Chat Button Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a … wordfence
44f18ae8-0c4b-44b2-a069-47644432eff6
< 3.5.9
MEDIUM 6.1 The Gulri Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
44f164fc-d8a6-4e31-9fec-54ae22246c50
< 2.5.5
MEDIUM 6.1 The LaTeX2HTML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.… wordfence
44e156f8-be5b-40b7-894b-5cb85f6be936 MEDIUM 6.1 The WP Find Your Nearest plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
44df0f6f-0765-4627-b553-3c51ea95cf59 MEDIUM 6.1 The occupancyplan plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
44d25846-42ad-4f85-a7c4-be1f5743bab6
< 10.0.7
MEDIUM 6.1 The Elite Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
44cbaa25-7e91-4b2e-81c4-ba1d7ba02350
< 6.20.3
MEDIUM 6.1 Multiple miniorange Plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'appId' parameter due … wordfence
44cb21f9-467a-4119-99fb-5cd21166a334
< 2.10
MEDIUM 6.1 The Add Shortcodes Actions And Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … wordfence
44c31db3-6dfa-4d42-9c3b-73dde9bc49b9
< 2.9.52
MEDIUM 6.1 The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action … wordfence
44af8ced-5ea4-4bdb-a664-c5b58d683d23
< 1.3.4
MEDIUM 6.1 The Google +1 by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’… wordfence
44ad9dae-f0ee-471a-b023-0c10365b3198 MEDIUM 6.1 The Custom Author URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
4487391e-baa4-4320-a23d-b52a42e2de90
< 4.9.50
MEDIUM 6.1 The WooCommerce Follow-Up Emails plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… wordfence
447f4bfb-2362-48ad-bd49-27872178f616 MEDIUM 6.1 The Timeline Event History plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
447b95d4-8db4-497a-9c09-de8edb350688 MEDIUM 6.1 The WP Fiddle plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0… wordfence
44780988-cadf-4ff2-9ba9-148b7b6650df MEDIUM 6.1 The Kodex Posts likes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_a… wordfence
447453ef-f65f-4229-b34d-48c073febd32 MEDIUM 6.1 The Grid Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.3… wordfence
44735a35-c99e-445f-a117-2fbe203e9171 MEDIUM 6.1 The Social Pug: Author Box plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
444d69f5-8b8d-4e4b-bb6c-ad1ddcc7a867 MEDIUM 6.1 The Annie plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. … wordfence
44407fad-6ad4-4437-930f-b25a6c6203aa MEDIUM 6.1 The WP-WebAuthn plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the `wwa_auth` AJA… wordfence
443c57bf-2f3d-4b8f-9dae-b11142a74341
< 2.12.14
MEDIUM 6.1 The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the us… wordfence
44209ff3-bccb-4bf6-b36b-c691404b236d MEDIUM 6.1 The Page Health-O-Meter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … wordfence
441f5764-eab6-40fe-80cd-65da327b39b2
< 10.3.4
MEDIUM 6.1 The Newspaper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 10.… wordfence
441a97ff-cf87-44bd-a84a-d6b889c37104 MEDIUM 6.1 The Quote Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
4414cabb-765d-4ba9-be7a-acaf9ea6e45f
< 3.36
MEDIUM 6.1 The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
← Prev 942 943 944 945 946 947 948 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top