πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 520 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d9af843e-dcbb-4b09-b131-4e470c006d38
< 3.3.1
MEDIUM 6.4 The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block at… wordfence
d9a8d95c-e426-45e4-a071-f1c06e606387
< 1.2.1
MEDIUM 6.4 The PuzzleMe for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
d9a77b4f-46a3-45d3-bf2b-448584125874
< 2.1.2
MEDIUM 6.4 The Variation Swatches for WooCommerce WordPress plugin is vulnerable to Stored Cross-Site Scripting via several paramet… wordfence
d9a19e96-2ca4-4072-aa2e-ab01f1685911 MEDIUM 6.4 The SpiceForms Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spiceforms' short… wordfence
d99d4b9a-aa09-434d-91a8-7afaa0e8b5db
< 2.4.9
MEDIUM 6.4 Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScrip… wordfence
d992b9dd-dfd1-497c-b09f-cca02dc87e34
< 4.2.0
MEDIUM 6.4 The NACC WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nacc' shor… wordfence
d9906492-971c-48c3-adb4-e408a7550fff
< 8.3.2
MEDIUM 6.4 The WoodMart theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 8.3.2 due to insufficien… wordfence
d982a16d-d100-4d62-9914-fa91e917aece MEDIUM 6.4 The Gmap Point List plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
d97eb079-5b19-461c-8a80-d00ab45e2bff
< 3.0.1
MEDIUM 6.4 SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8.7 and earlier for WordPress allow… wordfence
d97e1ec3-321b-4d69-ab69-e3ecab0937b3
< 1.4.23
MEDIUM 6.4 The PCRecruiter Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'PCRecruit… wordfence
d97b09a1-3305-431b-9cbf-1dbed01b6efb
< 1.2.2
MEDIUM 6.4 The Able Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.… wordfence
d97761cb-8645-474d-9f9a-15ecdd426db4 MEDIUM 6.4 The Theme Blvd Responsive Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… wordfence
d96e5986-8c89-4e7e-aa63-f41aa13eeff4 MEDIUM 6.4 The WP Post Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'column' shortcod… wordfence
d964c99c-6ab6-453c-969f-66d5cd00dc8e
< 2.4.7
MEDIUM 6.4 The EthereumICO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ethereum-ico shortcod… wordfence
d9526a8b-fefe-4ca6-871f-1ead3f498679
< 2.2.15
MEDIUM 6.4 The BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library plugi… wordfence
d94cd171-c2a4-4ef0-bc9a-5fdd2b704b5b MEDIUM 6.4 The Simple Pricing Tables For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stor… wordfence
d9456921-e56a-402f-a80a-fd5659b9aac6
< 7.12.1
MEDIUM 6.4 The ExactMetrics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via unspecified block options in post… wordfence
d93c9c2d-1216-44e6-bdb8-d419a9ba6c6e
< 2.10.5
MEDIUM 6.4 The Mediavine Control Panel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
d938b867-a29a-460b-bfc2-1ba4490ee105
< 3.7.2
MEDIUM 6.4 The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7.1.… wordfence
d9363db7-4535-427d-a6ae-2580f215b965 MEDIUM 6.4 The Shortcodes Bootstrap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' parameter in t… wordfence
d9345eaa-c8c0-4830-a9af-48305a2f80fd
< 2.0
MEDIUM 6.4 The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
d92fc04e-201e-4fc3-bbf0-4f2f3de3ee95
< 1.3.5
MEDIUM 6.4 wordfence
d9297d02-e408-4630-a36a-f7ea9e09319b
< 0.5.3
MEDIUM 6.4 The Slick Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.5… wordfence
d9207baf-348c-4d3b-a6f0-cbfcd2624f78
< 1.1.1
MEDIUM 6.4 The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
d916e320-e78b-4305-a4da-10c6fb8db41a
< 3.3.2
MEDIUM 6.4 The NGG Smart Image Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hr_SIS_ne… wordfence
← Prev 517 518 519 520 521 522 523 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top