🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 586 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9fbbdbba-ac65-4714-bc36-6d4831ca177d
< 6.0.13
MEDIUM 6.4 The Genoo plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.0.10 due… wordfence
9fbb5ed0-ed76-44fe-88c4-eb05ad87e510
< 1.1.0
MEDIUM 6.4 The Sign In Scheduling Online Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
9fbb31a5-9ed2-445a-b309-a9835128eb44
< 2.0.0
MEDIUM 6.4 The SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster plugin for WordPress is vulne… wordfence
9f9bbe9a-faac-4f41-b2be-ddf6ff80d9c7
< 2.8.6
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticate… wordfence
9f97bc19-c600-4819-ae75-d80b119a7575 MEDIUM 6.4 The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the… wordfence
9f96a607-a655-413d-9faf-304249edefe8
< 1.0.2
MEDIUM 6.4 The CanadaHelps Embedded Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'… wordfence
9f805982-1141-4e28-b28c-93483646cf99 MEDIUM 6.4 The TwentyTwenty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'twentytwenty' short… wordfence
9f665099-d1c3-43a9-b37b-c9f42c9172ad
< 4.24.6
MEDIUM 6.4 The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s… wordfence
9f65661b-be33-4a84-9432-7f1ff7fd722c
< 2.2
MEDIUM 6.4 The Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
9f57ce91-52f9-47a6-8ed8-815dd55cb92b
< 2.2.3
MEDIUM 6.4 The GutenKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.2 d… wordfence
9f51258a-e228-412f-9d97-28ab679136d7
< 3.2.91
MEDIUM 6.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packag… wordfence
9f4a939c-ba6c-4401-8139-a57e727ceb0f
< 0.9.9.2
MEDIUM 6.4 The Send PDF for Contact Form 7 for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes i… wordfence
9f4302f8-e9da-436f-9b4b-d01d3dbe9f31
< 1.2.0
MEDIUM 6.4 The ACF Onyx Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all… wordfence
9f3a4258-2f45-4617-a5ca-9b28835ef405
< 2.3.3
MEDIUM 6.4 The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Att… wordfence
9f2ae1ff-c76e-4997-b860-f1e0b94a437d
< 4.0.2
MEDIUM 6.4 The SoundCloud Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s)… wordfence
9f21f4a4-4b50-4396-8d94-26d68c0eb3a3
< 3.22
MEDIUM 6.4 The Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
9f1fb33e-38d7-44eb-a536-1f4268659a13
< 2.18.1
MEDIUM 6.4 The MPL-Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
9f06b745-8968-41cb-96b0-ff0f42af114d
< 5.0.5
MEDIUM 6.4 The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in versi… wordfence
9f0294c2-40ac-48aa-8377-e724e9cfc6c9
< 2.1.8
MEDIUM 6.4 The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
9efce080-9f7a-40a0-b084-513e07afe1c9
< 1.1.1
MEDIUM 6.4 The Nexa Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Google Maps widget in… wordfence
9efb7dc8-d0a1-4707-a465-6a55b2d4a426
< 2.16.3
MEDIUM 6.4 The Elements Plus! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widget link URLs in al… wordfence
9ef6272a-19f5-45eb-8083-f439b20119d1 MEDIUM 6.4 The Browsing History plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
9ef3297d-8686-44aa-ac73-793b644be3f2
< 4.9.2
MEDIUM 6.4 The WP Links Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in ver… wordfence
9ef081fa-429d-41fa-baba-96f0820dd1f0 MEDIUM 6.4 The Luzuk Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
9ef01973-c6f7-447b-933c-ae8bc3ebac5d MEDIUM 6.4 The Home Services theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2… wordfence
← Prev 583 584 585 586 587 588 589 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top