πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1033 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a07ca145-9349-4961-9e66-4c59ea9b5069 MEDIUM 5.5 The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the … wordfence
a07bd233-902c-402c-9055-f3085246da78
< 4.2.2
MEDIUM 5.5 The WP OAuth Server plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the client ID parameter in ver… wordfence
a03f0780-796c-41a3-8f06-04f76e0da2da
< 4.8.2
MEDIUM 5.5 The Download Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including,… wordfence
a018ba2b-8188-41f9-bdab-64cae3362e0e
< 3.4.0
MEDIUM 5.5 The Easy Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
9fe2a19a-b6ed-409f-a496-a005f87d06e6
< 1.0.12
MEDIUM 5.5 The Simplified Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu… wordfence
9fae8288-898a-4acd-bbdf-c2fd4f1be1c6
< 7.2.4
MEDIUM 5.5 The AGCA – Custom Dashboard & Login Page plugin for WordPress is vulnerable to Server-Side Request Forgery in all vers… wordfence
9f76e294-1b17-4125-b85c-af7957de1c13
< 1.3.8
MEDIUM 5.5 The Login with phone number WordPress plugin through 1.3.7 do not sanitise and escape plugin settings which could allow … wordfence
9f6fd068-3f72-4015-b2d8-a47cd86df073
< 1.1.23
MEDIUM 5.5 The MJM Clinic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and… wordfence
9f699d49-738f-49f0-ab1a-f43645a32c90
< 2.0.7
MEDIUM 5.5 The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the hashtag parameter in ve… wordfence
9f5a77d1-b575-4e7c-bf27-fc78260de302 MEDIUM 5.5 The Reaction Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
9ec83425-c756-450e-ac46-c897ad72714c MEDIUM 5.5 The Woocommerce Tip/Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings i… wordfence
9eb829f2-c05f-4f81-85d0-2429fb515d33
< 1.1.19
MEDIUM 5.5 An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admi… wordfence
9e9fcaf5-d531-4b14-b8b1-d8090243cf0c
< 2.3.20
MEDIUM 5.5 The SVG Support WordPress plugin before 2.3.20 does not escape the "CSS Class to target" setting before outputting it in… wordfence
9e6434fb-390d-439d-bf3e-9afe8644fd58
< 5.4.7
MEDIUM 5.5 The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
9e2214d8-b22d-4e51-a0cf-cca1af8e761c
< 2.6.9
MEDIUM 5.5 The Responsive Starter Templates – Elementor & WordPress Templates plugin for WordPress is vulnerable to stored cross-… wordfence
9e1ae8f2-dd2e-46f9-bef1-aaaee26435a1
< 2411.1
MEDIUM 5.5 The Table of Contents Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
9d879fc6-97ec-4ecb-99c8-7fc0b91692ef MEDIUM 5.5 The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_met… wordfence
9d5ed6cf-ae12-4da5-809f-6a8c61eeb4f6
< 1.4.4
MEDIUM 5.5 The Assistant plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.4.3 … wordfence
9d389098-d428-48f2-b012-207b55497b0b
< 4.3.7
MEDIUM 5.5 The Paytium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paytium_live_api_key' option and … wordfence
9d1fcdb9-215c-415b-bd47-4cbf9258685b
< 1.32.0
MEDIUM 5.5 The Advanced Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title parameter in versions u… wordfence
9c3dc5fe-b1c8-4581-8100-68d313c3ac20
< 4.8.7
MEDIUM 5.5 The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several paramet… wordfence
9bbcd280-25c3-4bc3-88bf-d109cfd1e855 MEDIUM 5.5 The Hotjar Connecticator WordPress plugin through 1.1.1 is vulnerable to Stored Cross-Site Scripting (XSS) in the 'hotja… wordfence
9b8042b0-83d3-417f-a5e0-43ff4f7648fb
< 0.4.6
MEDIUM 5.5 The reSmush.it plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in … wordfence
9b0cc3a0-5a80-4a56-abeb-13046d9eaf3f
< 1.4.10
MEDIUM 5.5 The Slideshow CK WordPress plugin before 1.4.10 does not sanitize and escape Slide's descriptions, which could allow hig… wordfence
9ae9b5c7-0d76-4772-973b-be48e520c837
< 1.6.0
MEDIUM 5.5 The Testimonial WordPress plugin before 1.6.0 does not escape some testimonial fields which could allow high privilege u… wordfence
← Prev 1030 1031 1032 1033 1034 1035 1036 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top