πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1299 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a02ec9a2-6449-4975-9a68-2c8df5e28b31 MEDIUM 4.4 The Stellissimo Text Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver… wordfence
9fcdc458-783b-4ad5-8484-fdef4d814d71
< 5.0.3
MEDIUM 4.4 The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0… wordfence
9fcb65a0-4218-4728-9c29-0d1a03f438a6
< 1.3
MEDIUM 4.4 The Visual Footer Credit Remover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'selector' pa… wordfence
9fc46de4-af1c-4e38-9caa-55b7b18a69ae MEDIUM 4.4 The WP Not Login Hide (WPNLH) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in al… wordfence
9fc18fee-5813-4134-8c4d-44710665857a
< 1.7.7
MEDIUM 4.4 The My Content Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versio… wordfence
9f93ee42-c21d-47cf-b140-65809da75653 MEDIUM 4.4 The Squirrels Auto Inventory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all… wordfence
9f79fe15-65a1-44ab-a43e-1410ce1f1d77
< 1.1.11
MEDIUM 4.4 The WordPress Affiliates Plugin β€” SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
9ef9b22f-a0dc-43e5-9597-5dcc6ca3fc23 MEDIUM 4.4 The Exifography plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.… wordfence
9eb1c2b3-527c-45b6-a1bd-dc9c553b8aa8
< 3.25
MEDIUM 4.4 The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
9ea21bf9-9e2a-45d1-8cb7-db821ca13e70
< 1.6.3
MEDIUM 4.4 The DN Footer Contacts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
9e9e0214-b88e-4125-8c10-850ca736e920
< 20240216
MEDIUM 4.4 The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
9e8346a4-4077-469f-9182-d6cf12f60776 MEDIUM 4.4 The EC Stars Rating plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
9e1a2de1-f153-40fb-81b6-4b7c1c374839 MEDIUM 4.4 The DP ALTerminator - Missing ALT manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
9df97805-b425-49b1-86c1-e66213dacd2b
< 4.5.6
MEDIUM 4.4 The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, a… wordfence
9dd75955-3c9e-4cac-b952-f705a2129707 MEDIUM 4.4 The Real WP Shop Lite Ajax eCommerce Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
9dc640c8-3740-4770-b729-fb45ecec2b45 MEDIUM 4.4 The Column-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions … wordfence
9dc3c8e7-464e-4742-bc96-5a1dc8b27ae3
< 4.5.14
MEDIUM 4.4 The WP Meta SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.5.… wordfence
9d8e0ad2-3cfb-443f-9958-9639d0745dd7
< 1.2
MEDIUM 4.4 The Peadig's Like & Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… wordfence
9d79ce22-33ef-4dfb-a842-591cd7cedc94
< 1.16
MEDIUM 4.4 The Web Accessibility By accessiBe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings … wordfence
9d70294c-e2a4-4a34-8341-fb2361cb0819
< 4.7.5
MEDIUM 4.4 The WP ULike – All-in-One Engagement Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm… wordfence
9d431b21-10df-485b-9d6d-b72363681fd5
< 1.12.17
MEDIUM 4.4 The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin f… wordfence
9d21191c-32ef-4de6-8e95-ad66779e42f9
< 1.2.5
MEDIUM 4.4 The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includin… wordfence
9d0b1e05-0e28-4cf5-a278-ea91b6c9d253
< 1.1.1
MEDIUM 4.4 The CPO Content Types plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions u… wordfence
9cb6384a-f9dc-454c-be39-c2c681e57d36
< 2.2.0
MEDIUM 4.4 The Contact Form Builder by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setting… wordfence
9c657ea2-ff7b-4ef2-a7dd-a330484dd821 MEDIUM 4.4 The Sailthru Triggermail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver… wordfence
← Prev 1296 1297 1298 1299 1300 1301 1302 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top