🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,404
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 29, 2026
Last Updated

40,404 vulnerabilities found (page 1302 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
96d03984-623a-44c7-a46f-e1aabbc566d5
< 1.0.4
MEDIUM 4.4 The Simple Custom Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color settings fi… wordfence
96b6ac2c-a732-4d9a-9060-922ca482d1b2
< 2.2.9
MEDIUM 4.4 The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi… wordfence
969c17d4-9ca2-48ff-a5a6-9139b3da99c4
< 3.19.2
MEDIUM 4.4 The FlexTable Google Sheets Connector plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
9699944e-7f1b-4d79-9dca-98472d3db48f MEDIUM 4.4 The Featured Content Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all… wordfence
96896174-3ad9-4dcf-b06b-cd5ee91a6240
< 3.0.5
MEDIUM 4.4 The Bubble Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, … wordfence
96623f61-8dfc-4b17-bee7-8b2279efcc0d
< 1.1.21
MEDIUM 4.4 The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
965b5979-9bf6-4124-86c4-e246f8f17270
< 3.3.8.3
MEDIUM 4.4 The Watu Quiz for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and inclu… wordfence
9604fccc-ed8b-480b-ab56-ffa341631b52 MEDIUM 4.4 The WordPress Ad Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers… wordfence
95ffefff-80e1-4f5a-8939-47a00f75493d
< 3.1.0
MEDIUM 4.4 The WP Content Filter – Censor All Offensive Content From Your Site plugin for WordPress is vulnerable to Stored Cross… wordfence
95f1b5ca-5110-407a-8fbb-375ac445294b
< 2.9.2
MEDIUM 4.4 The Social Media & Share Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
9589d44b-55c3-45b4-84bb-c86143de3f95
< 3.5.6
MEDIUM 4.4 The WP Content Copy Protection & No Right Click plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad… wordfence
95737062-587a-447c-b448-06dc2d22dbdf
< 1.15.33
MEDIUM 4.4 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Store… wordfence
952d3ca6-9083-4c96-9bc1-94bb87fcc19c
< 6.0.0
MEDIUM 4.4 The Simple Social Media Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
9521ad5b-83c3-487e-a69e-ca057777bc9e
< 1.2.1
MEDIUM 4.4 The Order auto complete for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin sett… wordfence
95210ed8-4606-44fa-b823-b33e1d4a4ce0
< 3.30.3
MEDIUM 4.4 The Leyka plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and in… wordfence
94f338c2-95c9-4ce8-8579-0b2b66547aa0
< 1.0.5
MEDIUM 4.4 The OneClick Chat to Order plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
94d75f18-67ab-4367-982b-73e256d5dbe2
< 0.0.5
MEDIUM 4.4 The Private Comment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Label text' setting in al… wordfence
94c3fb5a-c6bb-447f-9b37-0eadaccbf374
< 7.1.1
MEDIUM 4.4 The WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce plugin for WordPress is vulnerab… wordfence
94b98842-8c75-4623-8cc9-ad3dc0916a18
< 1.4.16
MEDIUM 4.4 The Modern Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up… wordfence
94aca046-a680-4d13-a7ba-501573aace59
< 1.1.4
MEDIUM 4.4 The Orbisius Simple Notice plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
949ea4e6-420a-437d-8e71-ee20119343f3
< 3.8.18
MEDIUM 4.4 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
9489f066-5898-4908-b3aa-cf856958cb4e
< 1.0.10
MEDIUM 4.4 The Pretty Simple Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
946add6f-4cd5-4c55-9399-a782140f217c
< 3.2.8
MEDIUM 4.4 The TriPay Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
94530e50-02ab-4e58-9230-5c6a7b6c13e5
< 3.3.0
MEDIUM 4.4 The CashBill.pl - Płatności WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
9424e6ef-c1e4-44ee-8654-b3b93d6d5403
< 3.0.4
MEDIUM 4.4 The WS Force Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
← Prev 1299 1300 1301 1302 1303 1304 1305 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top