πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 949 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
40c134ed-c4b6-46f9-ba2a-9c3436d6accd MEDIUM 6.1 The Sticky Social Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
40b5d7e4-97a0-4a1c-8000-f2cfd1e751a3
< 0.34
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the 2 Click Social Media Buttons plugin before 0.34 for WordPress… wordfence
409f3a27-e94a-4298-88f4-69f69fb56ce8 MEDIUM 6.1 The Cart66 Cloud plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
4096367c-3141-4e75-97a8-6f35d15d229d MEDIUM 6.1 The Search engine keywords highlighter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … wordfence
408e14e7-5034-4f56-90b1-76f5637938df MEDIUM 6.1 The AB Google Map Travel (AB-MAP) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
40766e17-8134-44ed-888f-f725848baf00
< 1.0.1
MEDIUM 6.1 The Notify Odoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
406fe34a-0991-4653-9924-b6586091d7df
< 3.4.6
MEDIUM 6.1 Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.6 for WordPress allows an attacker to in… wordfence
4052adde-8d3f-409c-8cd3-a0170206c3fe MEDIUM 6.1 The Bet WC 2018 Russia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
404aabc5-1ff4-492d-8cab-4b83eb68157a
< 4.1.1
MEDIUM 6.1 The WP All Import Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in v… wordfence
40494f1e-d5df-4ed0-b107-aa52cb28bc0e
< 5.4.5
MEDIUM 6.1 The Jannah WordPress theme before 5.4.5 did not properly sanitize the 'query' POST parameter in its tie_ajax_search AJAX… wordfence
40371178-b04f-4360-8805-268028629755 MEDIUM 6.1 The Simple Redirect plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
401f5d57-ce3d-46c1-bfa9-c8fab99a7e31
< 2.1.7
MEDIUM 6.1 The Wysija Newsletters plugin for WordPress is vulnerable to Cross-Site Scripting via the swfupload.swf applet in versio… wordfence
401e2201-9c82-4f21-aa71-b68dc84c93f4 MEDIUM 6.1 The Nature FlipBook WordPress Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all version… wordfence
401da94d-6538-478a-bfcd-f9c91f84a3c6 MEDIUM 6.1 The Simple Finance Calculator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
4013a22a-701b-43ef-90fb-f8eddf65acf2
< 3.3.1
MEDIUM 6.1 The EELV Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' parameter in ve… wordfence
400d31ba-2cef-4558-8983-6689f7e4b93c
< 8.0.6
MEDIUM 6.1 The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (w… wordfence
4007814b-7e01-4188-8a42-9564444af95f
< 2.1.3
MEDIUM 6.1 The Easy Digital Downloads (EDD) Stripe extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.1… wordfence
3fffe8f2-9241-4a4f-8e8a-647a9e41d769 MEDIUM 6.1 The VKontakte Wall Post plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
3ffd63ca-5ea4-451c-aa97-092a754ca79f
< 2.7.3
MEDIUM 6.1 The archive-tainacan-collection theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad… wordfence
3fe91c7e-e4d4-4308-a8ca-22d7985ddb61
< 2.6.2
MEDIUM 6.1 The Payflex Payment Gateway plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.… wordfence
3fddf493-246b-4e39-99a7-503c9fab3652 MEDIUM 6.1 The WP Simple Slideshow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
3fc962d7-2301-436e-ac1f-6309cd958ecd MEDIUM 6.1 The LambertGroup - AllInOne - Content Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in ver… wordfence
3fc752bb-3f1d-4106-9df1-361564905a55 MEDIUM 6.1 The Sandbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'debug' parameter in all versio… wordfence
3fc04d8a-f551-4e91-b920-f2a8efcf61de
< 2.4.30
MEDIUM 6.1 The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnera… wordfence
3fb46633-50c5-4adf-8097-50e6aecefb5d MEDIUM 6.1 The Woocommerce Line Notify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … wordfence
← Prev 946 947 948 949 950 951 952 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top