ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 947 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4319988c-1dcd-486e-b8d8-cc58cf36e6c1 MEDIUM 6.1 The Community Lite Video Chat plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
430c6f4b-277e-41bf-a638-fd3fea495a31 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Movies plugin 0.6 and earlier for WordPress allows remote attackers to i… wordfence
430a981c-7856-493c-bf66-11506b5963a0
< 1.4.7
MEDIUM 6.1 The Event Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
42f537db-cb30-4ac6-9cc5-835901a722be
< 2.0.5
MEDIUM 6.1 The Clearfy Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg w… wordfence
42e74152-b79d-42f5-87a2-6e9545699483
< 2.8
MEDIUM 6.1 The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attrib… wordfence
42da00cf-5fda-4ad7-ad74-0328f492abcf
< 13.2.6
MEDIUM 6.1 The Product Feed PRO for WooCommerce by AdTribes – WooCommerce Product Feeds for Google, Facebook/Meta, Bing, & More p… wordfence
42c38563-ed78-4e65-8d1f-b3aa6444923d
< 2.1.2
MEDIUM 6.1 The Related Posts for WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of unsanitized use… wordfence
42b9e16c-8e53-452d-9c0b-34c424d6f508
< 5.30
MEDIUM 6.1 The SEMA API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘catid’ parameter in all v… wordfence
42ac67c7-8ab3-4314-bd0b-ca15e4fc64c1 MEDIUM 6.1 The Quizzin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1… wordfence
42aa17f0-9c97-407f-8fbf-3c25794ac750 MEDIUM 6.1 The wp Hosting Performance Check plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… wordfence
429d2666-75c8-48cc-a7b6-05ba64ed5995 MEDIUM 6.1 The Secure Invites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
4291b5c8-cce3-46ae-b9ff-a34a0f5bcdce
< 1.6.6.24
MEDIUM 6.1 The Simply Schedule Appointments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… wordfence
4290ee15-0362-48c5-a570-4a1b6719a948
< 3.7.35
MEDIUM 6.1 WordPress before 5.5.2 allows XSS associated with global variables. wordfence
426021d3-e302-4c2a-8d5c-f2a2fc20e45b
< 1.5.0
MEDIUM 6.1 The WordPress Multisite Content Copier/Updater plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via … wordfence
42561336-e777-4a0a-af1d-dfa0cb634e6d
< 2.9.3
MEDIUM 6.1 The Yogi - Health Beauty & Yoga theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
4252da8a-26c7-41a4-944b-cb41dafa8884 MEDIUM 6.1 The Konnichiwa! Membership WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the plan_id parameter in… wordfence
424a5c60-db14-4a45-8c62-7a11ed377f1a
< 1.4.13
MEDIUM 6.1 wordfence
4240fcda-c61d-4888-8837-5012e5ba1f26
< 4.6
MEDIUM 6.1 The Min Max Control plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST data from the 'save_… wordfence
42402a14-b192-4ed0-84bf-f0327e48f32b
< 2.0.19
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for W… wordfence
423627a6-623d-462c-a767-cf021566d9e1
< 3.4.5
MEDIUM 6.1 The TaxoPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.4.… wordfence
422b127f-aa52-40ab-a1c0-9d8b70aafe94
< 2.9.64
MEDIUM 6.1 The Netgsm plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.9.63… wordfence
422190bd-0f65-4e35-a003-25aa13b1dabc
< 3.18
MEDIUM 6.1 The Hack-Info plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1… wordfence
420c29d6-e712-4891-a2f6-b18f4718b35d
< 1.6.9
MEDIUM 6.1 The CBX Bookmark & Favorite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' paramete… wordfence
42030492-5802-42db-b88b-8a0f1552de12
< 1.3.50
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in includes/metaboxes.php in the Gallery - Photo Albums - Portfolio … wordfence
41fcf001-84da-4baf-9f43-5911ad33af35
< 4.0.2
MEDIUM 6.1 The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Reflected Cr… wordfence
← Prev 944 945 946 947 948 949 950 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top