πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,404
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 29, 2026
Last Updated

40,404 vulnerabilities found (page 1300 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9cb6384a-f9dc-454c-be39-c2c681e57d36
< 2.2.0
MEDIUM 4.4 The Contact Form Builder by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setting… wordfence
9c657ea2-ff7b-4ef2-a7dd-a330484dd821 MEDIUM 4.4 The Sailthru Triggermail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver… wordfence
9c640bcb-b6bf-4865-b713-32ca846e4ed9
< 1.0.16
MEDIUM 4.4 The Hotjar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the hotjar_site_id in versions up to, a… wordfence
9be5e54c-286a-4fec-95fb-27e3517f3eb8
< 2.3.8
MEDIUM 4.4 The Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
9bd1fe45-8518-429b-94d3-cc0ea06ca1b4
< 2.3.0
MEDIUM 4.4 The Tracking Code Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… wordfence
9bcc1965-c409-40ba-a942-175646ad8fda MEDIUM 4.4 The No CAPTCHA reCAPTCHA for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set… wordfence
9bb50e66-2849-458b-9e2d-fc3f487d47cb
< 2.4.1
MEDIUM 4.4 The Make Section & Column Clickable For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in v… wordfence
9b620481-8f45-4616-9b22-2dd14733325c
< 3.1.0
MEDIUM 4.4 The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website … wordfence
9b4f6b93-ecfe-4298-a744-21a4bb403366
< 1.5.3
MEDIUM 4.4 The Basticom Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
9b409e3f-51e0-4d66-a04c-a0d54259bd2e
< 1.5.1.8
MEDIUM 4.4 The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress… wordfence
9b39c360-f267-4f9a-8d9d-fa0d7e300129
< 1.1.23
MEDIUM 4.4 The MJM Clinic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t… wordfence
9b28b0f5-8157-40a7-8661-c8ba0b8eba1b
< 2.5.7
MEDIUM 4.4 The Advanced Cron Manager – debug & control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admi… wordfence
9af963ed-8bc5-4b5e-bacd-30a2ef429ce8
< 1.7.1
MEDIUM 4.4 The ANAC XML Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions… wordfence
9ad2acce-1285-46e6-9bb0-64f215698373
< 2.0.0
MEDIUM 4.4 The Sticky Side Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 2.0.0 due to… wordfence
9ad00419-e9fa-4f78-b0d9-02cfb412a04d
< 4.17
MEDIUM 4.4 The Usersnap plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.16 du… wordfence
9ac9c146-5065-46fc-b2ae-20b820a8016b
< 2.3
MEDIUM 4.4 The Category Specific RSS feed Subscription plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl… wordfence
9ac2c929-2188-4818-880d-8793984e8df1
< 1.1.6
MEDIUM 4.4 The Simple Posts Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions… wordfence
9aa5247a-b85b-4a0d-ac3e-4b4ef8ccd8ed
< 1.2.8
MEDIUM 4.4 The Themify Event Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
9a96ac4c-9c29-4649-a756-d258f1db26e5 MEDIUM 4.4 The BP Social Connect plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
9a88330e-fbeb-4ac7-a143-a59766accbeb
< 2.6.2
MEDIUM 4.4 The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… wordfence
9a87a18b-814b-4b94-959e-a9aafe5015bc
< 3.1.32
MEDIUM 4.4 The Icegram Engage – Ultimate WP Popup Builder, Lead Generation, Optins, and CTA plugin for WordPress is vulnerable to… wordfence
9a85b549-f6a4-4dc3-9f2a-35d783099f96
< 2.6
MEDIUM 4.4 The Inline Tweet Sharer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin setting options par… wordfence
9a15946b-c4df-43e8-9e1d-7a8367cfda6b
< 2.6.3
MEDIUM 4.4 The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via field values in versions up… wordfence
99e43091-7699-4746-b6da-ab60a15175ce
< 5.7.45
MEDIUM 4.4 The Email Subscribers by Icegram Express – Affordable, Powerful Email Marketing for WordPress & WooCommerce plugin for… wordfence
99ce64cf-3f7a-4bc0-aa06-00f0fb3bfc4c MEDIUM 4.4 The Aklamator INfeed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
← Prev 1297 1298 1299 1300 1301 1302 1303 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top