ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1034 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9acf80aa-8354-4430-9836-18fa17854521
< 4.10.1
MEDIUM 5.5 The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
9a7f738e-21f3-42f3-bf33-1d93ff0d1364
< 3.27.9
MEDIUM 5.5 The "Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Plugin" plugin for WordPress is vulnerable to … wordfence
9a4488c8-7138-4046-88ea-84f9462eec93
< 2.2.24
MEDIUM 5.5 The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privi… wordfence
99e61ed1-df56-4e95-b4f9-3027ee7b7793
< 5.7.26
MEDIUM 5.5 The Quick Paypal Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings through s… wordfence
999cf54e-2ea8-474d-984c-1c4f729198aa
< 2.2
MEDIUM 5.5 An issue was discovered in the read-and-understood plugin 2.1 for WordPress. XSS exists via the wp-admin/options-general… wordfence
9985627d-9ba4-4a5b-94fb-06bcc769acfd
< 2.1.6
MEDIUM 5.5 The Notibar – Notification Bar for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm… wordfence
994a044d-db69-4f2d-9027-cf3665446ed3
< 1.8.22
MEDIUM 5.5 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
993f6505-918c-45fd-8afa-4d567cc79e9e
< 3.0.6
MEDIUM 5.5 The ImageBoss WordPress plugin before 3.0.6 does not sanitise and escape its Source Name setting, which could allow high… wordfence
990b3318-e3e1-4a19-875c-80d5d639ca4a
< 1.2.8
MEDIUM 5.5 The Meks Easy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its paramete… wordfence
98c2d04d-c401-411f-8bf0-4aebb1779e8d
< 1.1.0
MEDIUM 5.5 The Analytics Cat – Google Analytics Made Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
988f102e-08b6-4436-be03-fc37a4084ca1
< 2.4.4
MEDIUM 5.5 The All-in-One Addons for Elementor - WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
986f158e-1960-4105-b477-9587850aa0aa MEDIUM 5.5 The Message ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9… wordfence
98553e47-f121-4300-b6d9-ab309516cf1d
< 4.4.0
MEDIUM 5.5 The WP MAPS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up… wordfence
97c7b0bc-4c73-4330-851a-2d6d6d0b62c9
< 3.1.4
MEDIUM 5.5 The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget be… wordfence
97b10f88-1911-4416-a5cd-83b4c991e6c9
< 1.0.83
MEDIUM 5.5 The Loading Page with Loading Screen WordPress plugin before 1.0.83 does not escape its settings, allowing high privileg… wordfence
978c13e5-d30c-4caa-ab6d-256f2517fd79 MEDIUM 5.5 The Auto Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
978159d3-39b2-49b7-a59a-2da72f1792fd MEDIUM 5.5 The CPO Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
9694c8b6-3e2f-499f-bdac-eed78d89e08a
< 1.6.6
MEDIUM 5.5 The WP Last Modified Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Custom Message to… wordfence
9642be85-2817-4a3b-831b-0f1535106897
< 3.0.0
MEDIUM 5.5 The Page Loading Effects plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version… wordfence
961b2b60-2026-42fc-be55-e7023e8ef3df MEDIUM 5.5 The Event Geek WordPress plugin through 2.5.2 does not sanitise or escape its "Use your own " setting before outputting … wordfence
95f1e3eb-da87-417e-8e8c-e5035e072950
< 3.62
MEDIUM 5.5 The Qwizcards – online quizzes and flashcards WordPress plugin before 3.62 does not properly sanitize and escape some … wordfence
94d682bb-ed94-40fc-98b4-2f404d6cd8ea
< 6.6.0
MEDIUM 5.5 The WooCommerce plugin for WordPress is vulnerable to Stored HTML Injection via payment gateway titles in versions up to… wordfence
94cbd525-de3b-448a-b65b-21c63208b8b8
< 1.4.6
MEDIUM 5.5 The Business Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation … wordfence
94384812-fa6e-48db-a84a-b1769e62ca58
< 3.9.31
MEDIUM 5.5 The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and in… wordfence
93a07f4e-8359-4ca2-a1cc-ca0ba2b7c0de
< 2.0.4
MEDIUM 5.5 The Seed Social plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of the plugin's settings in v… wordfence
← Prev 1031 1032 1033 1034 1035 1036 1037 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top