🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 948 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
41fadee9-ced6-4743-898f-d02d0b6f7f39
< 5.8.0
MEDIUM 6.1 The wProject theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 5.8.0 due to insuffic… wordfence
41f8b229-dada-4460-b394-04502f62a75f
< 2.1.3
MEDIUM 6.1 The Hesabfa Accounting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
41ef545a-7de1-406c-8686-57216e697a1b
< 5.4
MEDIUM 6.1 The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting v… wordfence
41edf49a-18a2-4cf0-b498-738e77287b90
< 3.9.2
MEDIUM 6.1 The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & El… wordfence
41c2edae-9788-47ad-bf0b-aa944893c4e2
< 4.14.3
MEDIUM 6.1 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scrip… wordfence
41bbb772-9a2c-4c69-bdac-a5ce4f50d3ec MEDIUM 6.1 The WP Stacker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
419df0c4-1e78-47da-b28d-5ab1cb66729a
< 1.3.6
MEDIUM 6.1 The Maps by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
4197dd30-bfd8-4d6c-80f5-b13e3844adf8
< 1.2.11
MEDIUM 6.1 The Favicon Rotator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
4196b8d1-23a7-4b90-8e6b-f51849d44f9c MEDIUM 6.1 The Featured Posts Scroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
4187f559-87ba-46ab-9b45-7a36dd98d71d
< 2.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in js/wp-seo-metabox.js in the WordPress SEO by Yoast plugin before 2.2 for Wor… wordfence
4186fe8d-ca09-4b82-9500-7b16bd10b044
< 4.1.0
MEDIUM 6.1 The WP MAPS – Easiest & Most Advanced WordPress Plugin for Google Maps plugin for WordPress is vulnerable to Reflected… wordfence
4186a609-84f1-4852-8ed9-e8ba6263b635
< 1.6.2
MEDIUM 6.1 The Robokassa payment gateway for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in ve… wordfence
417ff4fd-e514-4366-b9a6-c04d7434eac1 MEDIUM 6.1 The AMP+ Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
417fb507-a414-4bc2-ab01-d6f2fc554350 MEDIUM 6.1 The Custom Admin-Bar Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menuObject'… wordfence
416fc00d-2e72-41aa-9023-0c098ca32192
< 3.0.4.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in login-with-ajax.php in the Login With Ajax (aka login-with-ajax) plugin befo… wordfence
4148b37e-c5dd-43a1-aecf-085ce4fb2473
< 2.4.0
MEDIUM 6.1 The Portfolio by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’… wordfence
414013e9-5baa-4f4f-bf67-f0e821ece807
< 5.7.0
MEDIUM 6.1 wordfence
41307a48-d49d-402f-bd3f-96b99afe6a42
< 2.4.2
MEDIUM 6.1 A Cross-site scripting (XSS) vulnerability in /inc/class-search.php in the Sell Media plugin v2.4.1 for WordPress allows… wordfence
41219c9d-a10d-4006-9edc-1387dfdc8b8d
< 2.6
MEDIUM 6.1 The yolink Search for WordPress plugin for WordPress is vulnerable to Cross-Site Scripting via the 's' parameter in vers… wordfence
410cc5f0-265a-46c1-a334-115142318d10 MEDIUM 6.1 The Hot Linked Image Cacher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an several paramete… wordfence
410ae0f1-a4ed-4631-9f80-86b7a403ce0d
< 1.7.6
MEDIUM 6.1 The Loginizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘name’ parameter in versi… wordfence
40f79195-23e7-4091-9dcb-8b787f0606f4
< 0.8.5
MEDIUM 6.1 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Cross-Site Scripting in ve… wordfence
40ec1b62-5eff-4a93-9730-9a5602b7e00f
< 1.7
MEDIUM 6.1 The Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
40dc5db4-0907-48bf-a483-0da40589107d
< 1.4
MEDIUM 6.1 The LeadBoxer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
40c20b9d-9a7d-46ca-81d1-c58150dae2cf
< 2.4.2
MEDIUM 6.1 The Discount Rules for WooCommerce WordPress plugin before 2.4.2 does not escape a parameter before outputting it back i… wordfence
← Prev 945 946 947 948 949 950 951 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top