πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 946 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
440ff558-d304-4c2e-b9e2-988b31dcbcb6 MEDIUM 6.1 The Alfie – Feed Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'naam' parameter in … wordfence
440664ef-39c6-4b4b-99af-b9e6c9868a99
< 5.2.10
MEDIUM 6.1 The Generate Images – Magic Post Thumbnail plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all… wordfence
4401cb36-a42f-4dfc-8992-ebb9d3002579
< 1.9.4
MEDIUM 6.1 The AEC Kiosque plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
43ede544-2c83-4ff7-a0d0-78d9cbbd86d3 MEDIUM 6.1 The Twitter Card Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
43ea0665-2c6e-4c78-8bc5-056f47f190ab MEDIUM 6.1 The Contact Form Builder, Contact Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in version… wordfence
43e72eef-4e66-4789-959b-163c9cbea584
< 3.4.0
MEDIUM 6.1 The flickr-justified-gallery plugin before 3.4.0 for WordPress has XSS via several parameters. wordfence
43e50125-1cf6-4039-a385-1f52b62bad33 MEDIUM 6.1 The WordPress/Plugin Upgrade Time Out Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… wordfence
43d0fe39-595c-4805-949c-6fa1930f14a7
< 0.9.5
MEDIUM 6.1 The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
43cc1dfa-4419-4958-bb26-a554cf2ad06c
< 2.4
MEDIUM 6.1 The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
43b5a321-c82e-4d0b-9def-b74c3cf439d3
< 2.0.4
MEDIUM 6.1 core/lib/upload/um-image-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerabil… wordfence
43b0cb21-ba81-4d54-90d1-a2f25297e719
< 1.0.6
MEDIUM 6.1 The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜… wordfence
43a6bc40-fbba-4b6c-80fc-65b619f73414
< 2.0.0
MEDIUM 6.1 The SEO Pyramid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
43a1e5b7-9361-406e-97b7-776b831acc33
< 1.8.0
MEDIUM 6.1 The Contact Form DB - Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'form_id' … wordfence
438f98f7-b966-4e07-a62e-a918cce3f6c0 MEDIUM 6.1 The Easy Digital Downloads (EDD) PDF Stamper extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before … wordfence
43886697-bf31-4466-b2bb-b932937eb187 MEDIUM 6.1 The Social Share And Social Locker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up t… wordfence
43810a17-89b4-44f5-887e-1ad0989ea5b4
< 8.4.0
MEDIUM 6.1 The WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions before 8.4.0 due to… wordfence
43799089-3552-4138-b7f8-84fa4478406a MEDIUM 6.1 The SOPA Blackout plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
434f823d-17fb-4ea5-9506-0229d8375437 MEDIUM 6.1 The Vasaio QR Code plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
43472813-1d0d-4f25-8ae6-408cda8ce519 MEDIUM 6.1 The Backwp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0.2 … wordfence
43443789-4ebe-49b9-a3fe-ba7e5a8d3a7d MEDIUM 6.1 The Preloader Quotes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
434433bc-e93a-435b-9d1c-8174df7970a5 MEDIUM 6.1 The Download, Downloads – WordPress Download plugin By Edmon plugin for WordPress is vulnerable to Reflected Cross-Sit… wordfence
43412c79-3612-4e73-ba79-cb8688e776fe
< 2.0.1
MEDIUM 6.1 The WP Header Images WordPress plugin before 2.0.1 does not sanitise and escape the t parameter before outputting it bac… wordfence
433e5ba3-c07e-48a1-a28b-781121d892ae MEDIUM 6.1 The Multi Video Box plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'video_id' and 'group_i… wordfence
432c1241-b264-49b7-9f6d-b9adcc1557b6 MEDIUM 6.1 The Google Map on Post/Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … wordfence
432b71ea-dd81-4536-abda-33da8185abb6 MEDIUM 6.1 The St-Daily-Tip WordPress plugin through 4.7 does not have any CSRF check in place when saving its 'Default Text to Dis… wordfence
← Prev 943 944 945 946 947 948 949 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top