🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1009 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
09a8868e-c81c-464a-9ebf-18e77ae8173f
< 1.1.21
MEDIUM 6.1 The Radio Buttons and Swatches for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in a… wordfence
09a7b90a-9a6a-41c3-a15a-9a8d9731102f
< 1.7.5
MEDIUM 6.1 The Uix Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… wordfence
09a5f79c-d961-4903-8449-d2261c878388 MEDIUM 6.1 The TBTestimonials plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
09a0639e-4b14-4dc9-a50c-d18234faa7b1 MEDIUM 6.1 The Login and Logout Redirect plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 2.0.… wordfence
099dfb18-fc73-4a19-b017-1675c9acfa2f MEDIUM 6.1 The WordPress Tables plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the 'error_msg’ paramete… wordfence
099c8e23-31e3-47de-a33a-fe5812ca14d3
< 1.25.6
MEDIUM 6.1 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to t… wordfence
099b2244-1371-4418-b5ef-b28ac030dedd
< 6.0.1
MEDIUM 6.1 The simple-share-buttons-adder plugin before 6.0.1 for WordPress has XSS via 'url' parameter in ssba_buttons.php file. wordfence
0999a738-9fae-4043-99eb-ff222a7608fa MEDIUM 6.1 The Chilexpress woo oficial plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
09890f42-b9ee-4812-8cf2-f638ba9fb20f
< 1.2.134
MEDIUM 6.1 The Extra Product Options Builder for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
09870d90-80b1-4650-9b00-0dc005702aee MEDIUM 6.1 The NextGEN Smooth Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘galleryID’ … wordfence
0975cc9d-7130-4802-bba2-b52d4b79edcd MEDIUM 6.1 The Counterpoint theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
096ea1e3-a6c3-43c7-94f0-6c5617dd3fa9
< 4.0.4
MEDIUM 6.1 The LearnPress Export Import plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… wordfence
0963d6ee-6d27-4239-9e31-2750f5217594
< 1.3.6
MEDIUM 6.1 The Spark GF Failed Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
09618198-06fd-438b-a526-c7bf5b2570a8
< 5.2.2
MEDIUM 6.1 Cross-site scripting vulnerability in WP Retina 2x prior to version 5.2.2 allows an attacker to inject arbitrary web scr… wordfence
09467946-0ee7-45e7-969e-ec30863bfa3e
< 1.8.4.3
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPr… wordfence
093dc35d-3d7d-4fa4-af57-835b96df8984
< 6.3.12
MEDIUM 6.1 The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables… wordfence
0922d221-70c6-41d3-9da2-aa16d67e7c14
< 2.6
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Meta Slider (ml-slider) plugin 2.5 for WordPress allows remote attackers… wordfence
090c1ba1-1b73-4c83-a17f-993293c5621b
< 1.0.1
MEDIUM 6.1 The Easy Digital Downloads (EDD) htaccess Editor extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x bef… wordfence
08f59eb8-8865-401f-bb02-3192184e0415
< 2.2.9
MEDIUM 6.1 The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter b… wordfence
08ded669-7e43-4da4-87e7-c7d75fa53d8b
< 1.2
MEDIUM 6.1 An issue was discovered in the WP Mail plugin through version 1.1 for WordPress. The replyto parameter when composing a … wordfence
08d475b0-9de5-4a88-821a-af995d954435 MEDIUM 6.1 The Task Scheduler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
08d18e18-b9f2-4a4d-bf9b-4a64a7881a4f
< 4.2.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the F8 Lite theme before 4.2.2 for WordPress allows remote attackers to inje… wordfence
08b8f61d-d6e7-41c0-87ab-2d7310c8899d MEDIUM 6.1 The WP-Planification – WP-Planning plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… wordfence
08b5f8dc-bacb-4e6f-a4c0-c709fb48413f MEDIUM 6.1 The Satisfaction Reports from Help Scout plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in version… wordfence
08aa24a3-4306-4857-88ac-ecdcc578cdf5
< 1.8
MEDIUM 6.1 The WP Hide & Security Enhancer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' and … wordfence
← Prev 1006 1007 1008 1009 1010 1011 1012 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top