πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,404
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 29, 2026
Last Updated

40,404 vulnerabilities found (page 1301 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
99b91fb6-9e60-447d-ab43-2be231052140 MEDIUM 4.4 The Tennis Court Bookings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… wordfence
99a24c92-b6e5-4bbd-8cd8-1f95f47d3675 MEDIUM 4.4 The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
9996cdc7-4d97-4b27-b697-09bbdbcd865d MEDIUM 4.4 The YouTube Subscribe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio… wordfence
9995df77-5ccf-4734-ad96-234c82d50a02 MEDIUM 4.4 The DL Robots.txt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… wordfence
99908c52-b236-494f-aeb6-3b1dfaae1305
< 3.2.15
MEDIUM 4.4 The Nested Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2… wordfence
9985cac5-30bf-4e8b-91d5-0b3da36ed851
< 13.0
MEDIUM 4.4 The WP Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
99736b2d-c8f3-4da8-bd11-cfaf32bd53ef
< 8.69
MEDIUM 4.4 The IdeaPush plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.66 du… wordfence
996e0bca-70cb-45ab-bb94-b41250e252fc
< 2.7.3
MEDIUM 4.4 The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme – My Sticky… wordfence
996843e5-4fbc-4606-a383-2a5825fae89c
< 4.3.61
MEDIUM 4.4 The WPtouch plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.3.60 d… wordfence
9937bb50-1a84-4284-a848-bc32b45db69d MEDIUM 4.4 The Post Video Players plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
9905517f-236c-4e98-8026-8d54bf64c7c9
< 1.1.23
MEDIUM 4.4 The Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in versions up to, and … wordfence
98dcf0a0-7310-41b4-b622-092ed689159a MEDIUM 4.4 The Bonjour Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.… wordfence
98c546dd-6a63-4aaf-9e50-59419dd37e16 MEDIUM 4.4 The Lunar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.0 due … wordfence
989bd778-c7b2-41c5-ac4a-2f1a4e594f0d
< 3.2.18
MEDIUM 4.4 The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
98780ecc-fb45-4392-955d-ddecf9f7fca1 MEDIUM 4.4 The Simple Light Weight Social Share (Tweet, Like, Share and Linkedin) plugin for WordPress is vulnerable to Stored Cros… wordfence
986d16d5-f1f4-4ed9-9978-0f12ee22a543 MEDIUM 4.4 The Simple Custom Author Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i… wordfence
983a9501-cb09-436a-8b0d-392cfef8643b
< 3.2.16
MEDIUM 4.4 The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to,… wordfence
97f8549a-292d-4a6d-8ec0-550467e5cf0f
< 2.7.0
MEDIUM 4.4 The Custom Permalinks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
97d83816-5a27-4172-a7fe-724870f2ca77
< 4.7.4
MEDIUM 4.4 The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
97cb7216-fe65-46db-9ab2-62d409f056cd MEDIUM 4.4 The Smartarget Message Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
9774c999-acb6-4c5f-ad6c-10979660b164
< 3.2.87
MEDIUM 4.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all … wordfence
97696702-4d40-41dd-a25f-f2ee7681a2c9
< 1.2.9
MEDIUM 4.4 The JavaScript Notifier plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all ver… wordfence
9757afd0-0c03-491d-85c7-a661d4c42264 MEDIUM 4.4 The tli.tl auto Twitter poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
974091fa-0327-49c3-8834-e59772c310e2 MEDIUM 4.4 The Maps for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.… wordfence
96f30a22-f218-48e7-9796-b9f1d5becc2c
< 1.5.7
MEDIUM 4.4 The Site Offline Or Coming Soon Or Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… wordfence
← Prev 1298 1299 1300 1301 1302 1303 1304 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top