🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1303 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
946add6f-4cd5-4c55-9399-a782140f217c
< 3.2.8
MEDIUM 4.4 The TriPay Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
94530e50-02ab-4e58-9230-5c6a7b6c13e5
< 3.3.0
MEDIUM 4.4 The CashBill.pl - Płatności WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
9424e6ef-c1e4-44ee-8654-b3b93d6d5403
< 3.0.4
MEDIUM 4.4 The WS Force Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
93cb3b29-b1a0-4d40-a057-1b41f3b181f2
< 4.23.5
MEDIUM 4.4 The WP RSS Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the RSS feed source in all v… wordfence
93bda572-2acf-4a1b-93ac-72dc9537cb4d
< 5.5.2
MEDIUM 4.4 The MailPoet – Newsletters, Email Marketing, and Automation plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
93ba8247-ed6b-47fd-a0af-4d5121825969
< 6.7.0.89
MEDIUM 4.4 The Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.7.0… wordfence
93b5bc57-3bfa-4477-a9d4-f0563008cf94
< 1.3.13
MEDIUM 4.4 The Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
93ab9f1a-26ce-466a-a5d3-d2046ec8f94d
< 8.4.12
MEDIUM 4.4 The Simple Share Buttons Adder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a… wordfence
938a896d-90a0-4f29-942f-df8d6ed3613e MEDIUM 4.4 The DigitalOcean Spaces Sync plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
936d2714-4ace-4685-b3ff-6adac76495a3
< 2.1.4
MEDIUM 4.4 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
936803ab-93d5-4808-8758-6b8f7c01b3c2 MEDIUM 4.4 The Pickup | Delivery | Dine-in date time plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin se… wordfence
9350fba0-2cb3-43dd-9ea5-214dc631267a MEDIUM 4.4 The Shipyaari Shipping Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
93385acc-aede-4948-b64e-d1ab23167d17 MEDIUM 4.4 The PrePost SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, … wordfence
9302ed6a-1725-4215-ba75-e5cb10da292e
< 1.24.1
MEDIUM 4.4 The My WP Customize Admin/Frontend plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings … wordfence
92ab1f56-5ca6-48e8-b380-ac2e302d63d2
< 6.0.3
MEDIUM 4.4 The WP Delete Post Copies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… wordfence
92a20a1f-6403-4561-acd8-5b076fe2999f MEDIUM 4.4 The DevBuddy Twitter Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versio… wordfence
927696bd-bf0c-4f15-9b06-21c3d0a11aed
< 1.8.1
MEDIUM 4.4 The File Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
92749a6c-388c-4b4e-b29f-f35aada96367
< 3.4.8
MEDIUM 4.4 The Terms descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
92705581-9a0d-4d23-9118-fec9100e4ce1 MEDIUM 4.4 The Custom Logo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
92484681-e677-4a7b-b2df-40aad49baf44
< 3.2.2
MEDIUM 4.4 The Save as PDF Plugin by Pdfcrowd plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings … wordfence
9240aa50-f8b4-47c9-bedd-cffd4e1b4d58
< 1.7.7
MEDIUM 4.4 The Better Find and Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
923ee3a7-a591-4132-8fbe-bd0edf8b7bb8
< 9.8.4
MEDIUM 4.4 The MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.8.3… wordfence
922d851a-906c-4413-b6a9-a7b35a547db2 MEDIUM 4.4 The Better Random Redirect plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
91d5d052-d219-4c2f-9341-19f415ff90c4
< 1.4.7
MEDIUM 4.4 The WP Table Builder – WordPress Table Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an… wordfence
91c0c738-37f9-476b-9d54-e01c721ca9bc MEDIUM 4.4 The User Role plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 du… wordfence
← Prev 1300 1301 1302 1303 1304 1305 1306 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top