πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1304 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
91b06d7d-7e92-49f0-b161-9b25318edfeb MEDIUM 4.4 The Image vertical reel scroll slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set… wordfence
919d31a8-932e-438b-a039-89a24781524c
< 3.2.3
MEDIUM 4.4 The IURNY by INDIGITALL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions… wordfence
9198ffe4-2f9e-4d80-9f5d-cf967b3feb43
< 0.3
MEDIUM 4.4 The Feed Changer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to,… wordfence
918fbf35-7ef8-455d-af3c-23da415860b2 MEDIUM 4.4 The wordpress login form to anywhere plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
91552a9b-d46b-4a75-b096-8f28bdd9fb56
< 2.45.1
MEDIUM 4.4 The Simple Giveaways plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple form fields in versi… wordfence
914d6f7a-053a-4555-9cbc-98bd0789bcd9
< 1.4.6
MEDIUM 4.4 The WP Search Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions… wordfence
91291608-5aa4-4fa1-b0d8-2b94d3d46f9c
< 4.15.15
MEDIUM 4.4 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
90e8a6e1-438b-432b-8d01-ca494e307079 MEDIUM 4.4 The AnyClip Luminous Studio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
90e4fb13-e007-4278-aee4-c61b6612544d
< 1.0.3
MEDIUM 4.4 The Category Icon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
90c1fd9c-eb5c-45fb-b641-75cb3fdad87a
< 2.5.9.2
MEDIUM 4.4 The Namaste! LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Certificate Title value in ve… wordfence
90b991f7-d936-44f2-8b9c-155b6af5e898 MEDIUM 4.4 The Widgetize Pages Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
906dcf2a-6be1-4966-9a70-1ef9a8f1017d MEDIUM 4.4 The Custom Admin Login Page | WPZest plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setting… wordfence
905cb57b-70ec-4324-ae66-9c06d1737939 MEDIUM 4.4 The CMS Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, an… wordfence
9053995a-b1de-427f-b16d-31fa8cd026b2 MEDIUM 4.4 The Wp-Adv-Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a quiz title in all versions up to… wordfence
902c017d-c907-4335-9e1e-1d23580d9caf
< 1.7
MEDIUM 4.4 The WP Secure Maintenance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… wordfence
8ffde2ce-2857-473f-8956-ddce81001070
< 1.7.1
MEDIUM 4.4 The Safety Exit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
8fb3c416-10d2-48b1-a158-74613be2fd21
< 10.9.4
MEDIUM 4.4 The Salon Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver… wordfence
8fa6d1f2-17d3-4fc3-b8cc-c5b246a07be5
< 7.3.21
MEDIUM 4.4 The AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth plugin … wordfence
8f8e6ca4-ceeb-4d0c-8b05-86c2abe435a2
< 1.12.17
MEDIUM 4.4 The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin f… wordfence
8f4f2317-945e-4fd8-8a0b-981b88a8412c
< 2.0.0
MEDIUM 4.4 The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Stored Cro… wordfence
8f220293-9789-4824-b736-ead014c45366
< 1.1.2
MEDIUM 4.4 The Multiple Post Passwords plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … wordfence
8f1866d6-79ac-444c-ab73-eab081786c93
< 2.3.0
MEDIUM 4.4 The Preferred Languages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers… wordfence
8f105002-a19a-4376-af65-7e9416175174
< 32.0.6
MEDIUM 4.4 The PPOM for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in ve… wordfence
8ef0934a-ee5b-4f94-af9f-edd841256396
< 3.8.6
MEDIUM 4.4 The Ultimate Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.8.6 due to … wordfence
8ec9b8f4-0531-4d3b-8416-ba6dd41a3bac
< 2.5.10
MEDIUM 4.4 The Link To Bible plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
← Prev 1301 1302 1303 1304 1305 1306 1307 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top