🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1035 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
93a07027-1068-41fa-bd6b-74ccc0441a16
< 1.3.2.3
MEDIUM 5.5 The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key' parameter in versio… wordfence
938d24c2-24f5-42d4-9a8f-f25b65a312f1
< 5.9.110
MEDIUM 5.5 The Special Text Boxes WordPress plugin through 5.9.109 does not sanitise or escape some of its settings, which could al… wordfence
9311b20b-daad-408f-a1a0-d1e42573ab97
< 1.7.0
MEDIUM 5.5 The Gravity Forms WebHooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and … wordfence
92880588-a733-43df-adf6-74fe6291822d
< 1.5.0
MEDIUM 5.5 The Click to Call or Chat Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i… wordfence
926827a5-4231-4188-bece-fd37c1829412
< 1.2.11
MEDIUM 5.5 The DPD Baltic Shipping plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shipping terminal para… wordfence
9202cb4d-7fd4-444d-ab44-8f6d9e68d869
< 5.7.2
MEDIUM 5.5 The AutomateWoo plugin for WordPress is vulnerable to SQL Injection via bulk actions in versions up to, and including, 5… wordfence
91aaf15f-dc47-4f7f-b5f7-aba7c67f7233 MEDIUM 5.5 The Ultimate Multi Design Video Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versio… wordfence
9195ac7e-2995-44d0-b5c6-8ffb47395f24
< 1.1.0
MEDIUM 5.5 The CPO Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its content type sett… wordfence
91898465-55fa-417c-8f00-ffe118232516 MEDIUM 5.5 The Advanced Youtube Channel Pagination plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘you… wordfence
9116cfea-eef8-480c-b75a-c6825d14f37a
< 1.2.0
MEDIUM 5.5 The Uploading SVG, WEBP and ICO files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown p… wordfence
90ebe593-6511-4998-a45e-795f3597b191
< 5.4.13
MEDIUM 5.5 The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in t… wordfence
90c0eb3e-b3f1-483c-9afd-2bbc4ff0cdf3
< 5.5.6
MEDIUM 5.5 The miniOrange's Google Authenticator plugin for WordPress vulnerable to Stored Cross-Site Scripting via the ‘Add Refe… wordfence
90706a16-cd71-4040-ab0e-be8649110d3c MEDIUM 5.5 The Fancier Author Box by ThematoSoup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin s… wordfence
90333dc7-8bdf-4a59-8001-7eb76b4bc61d
< 1.7.5
MEDIUM 5.5 The Archivist – Custom Archive Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin s… wordfence
9016822f-f167-4225-8216-e74cd687443c MEDIUM 5.5 The SG Helper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in version 1.0 due … wordfence
8fed0fae-fdac-4bb1-a0ad-99c48f82bfc7 MEDIUM 5.5 The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all v… wordfence
8f896e4a-565a-4545-9683-045cd08ccca0
< 2.2.2
MEDIUM 5.5 Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.2.1 allow remote authenticated administrators to inje… wordfence
8ee21796-5340-4f84-b1c4-a95137a27223 MEDIUM 5.5 The WP User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in versions up… wordfence
8eda641b-eddc-4255-80e4-c77c217f979f MEDIUM 5.5 The Car Rental by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter… wordfence
8ebc05b6-89dd-4373-a632-75c783716643
< 2.1.8
MEDIUM 5.5 An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php extra_… wordfence
8eaf6dfd-bc66-466f-af80-213213fdb839
< 9.3
MEDIUM 5.5 The MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.2 d… wordfence
8e73b00e-38f7-45dc-8577-5cc47c18b9fd
< 2.2.7
MEDIUM 5.5 The BlossomThemes Email Newsletter plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up … wordfence
8e5c0282-6d13-4c83-8d1f-c49430f714d6
< 1.3.321
MEDIUM 5.5 The All in One Time Clok Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's setting… wordfence
8e33d72d-00d4-45c8-98d2-0a0a73d13b35
< 3.4.2
MEDIUM 5.5 The IgniteUp WordPress plugin through 3.4.1 does not sanitise and escape some fields when high privilege users don't hav… wordfence
8e25a511-f176-4532-bb9f-a7a3134ee29a MEDIUM 5.5 The Curtain WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high pri… wordfence
← Prev 1032 1033 1034 1035 1036 1037 1038 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top