πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1072 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9d6dd532-008b-4ce9-beca-baf5b3678a0b
< 2.20.29
MEDIUM 5.4 The Seraphinite Accelerator plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.… wordfence
9d3b4315-05cd-4349-8dd9-ea6792048a9d
< 3.0.3
MEDIUM 5.4 The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitize some of its block settings, allow… wordfence
9d1e498a-ddcb-4c67-bf0d-bb45b6fe0e9d
< 4.5.4
MEDIUM 5.4 The WP Meta SEO plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability ch… wordfence
9cf2d3bd-359c-4334-ad28-b6b9722edd1c
< 3.0.15
MEDIUM 5.4 The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to author… wordfence
9cceca0e-5411-4b8c-a261-91098a8bc7fa
< 1.3.6
MEDIUM 5.4 The WP Reactions Lite WordPress plugin before 1.3.6 does not properly sanitize inputs within wp-admin pages, allowing us… wordfence
9c159237-1a3a-4d42-9a2e-fbd6ca98f38e
< 4.5.6
MEDIUM 5.4 The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in… wordfence
9bd6c6f7-a535-4e3a-8d72-01007d00d6be
< 9.6.3
MEDIUM 5.4 The Salon booking system plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Mobile Phone' parame… wordfence
9b5bc030-7739-4eb4-b85d-99e5d0f2643a
< 1.17
MEDIUM 5.4 The Enhanced Plugin Admin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
9b26604b-2423-4130-b0ef-8f63a392c760
< 2.18.17
MEDIUM 5.4 The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… wordfence
9b2083f9-79d0-43f6-b7ae-a5817dc561b0
< 2.1.6
MEDIUM 5.4 The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL parameter of … wordfence
9af929a3-6e17-40c7-9fce-1ce0eb72bc7b
< 3.3.10
MEDIUM 5.4 The Zephyr Project Manager plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 3.3.9. … wordfence
9aeb996c-723a-402a-a0f8-4212391c64eb
< 2.16.0
MEDIUM 5.4 The WooCommerce PDF Invoices & Packing Slips plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th… wordfence
9a4c327c-f756-4f50-8121-363791c6bd8c
< 1.4.5
MEDIUM 5.4 The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result … wordfence
9a09ec65-32e4-4841-a365-f67c15b80bf9
< 7.8.5.11
MEDIUM 5.4 The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is… wordfence
99e8017a-346e-42d8-b9c1-29ed15da1156
< 1.30.0
MEDIUM 5.4 The Ultimate Addons for Elementor WordPress Plugin before 1.30.0 has several widgets that are vulnerable to stored Cross… wordfence
9945c85b-a97a-4ad0-9d0a-69faf157563a
< 2.0.8
MEDIUM 5.4 The Simple 301 Redirects plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
991327f0-8bb9-4fdf-9c2a-b266ead962a3
< 4.1.13
MEDIUM 5.4 The The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP… wordfence
99051b12-5a24-4108-9ea4-81f37a1c1b35
< 2.0.99
MEDIUM 5.4 The Quads Ads Manager for Google AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
98f87769-d4e4-4e27-9acf-a4e52bdbf734
< 5.10.2
MEDIUM 5.4 The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via sho… wordfence
98361cfd-1277-43fd-b0da-db2549628383
< 1.8.3.3
MEDIUM 5.4 Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did … wordfence
9831d7d4-14ba-4db5-99ea-72f366eda4d5
< 1.4.12
MEDIUM 5.4 The Custom Post Carousels with Owl plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up … wordfence
982be9d7-fe9f-40c6-a474-fcc2d6455839
< 9.2.2
MEDIUM 5.4 The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
97985b75-6ac9-4aba-8f76-5633418e7907
< 2025.7
MEDIUM 5.4 The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in … wordfence
97628ee2-f7d9-4be5-8230-c38e531d1974
< 1.0.9
MEDIUM 5.4 The Polls CP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.… wordfence
97396207-4892-4d1a-8740-3000484f1317
< 2.1.0
MEDIUM 5.4 The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, whi… wordfence
← Prev 1069 1070 1071 1072 1073 1074 1075 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top