🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 587 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9eeee18d-a035-4de6-a2fc-19479387c4df
< 2.24
MEDIUM 6.4 The AJAX Login and Registration modal popup + inline form plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
9eeec949-e440-4df3-8c26-db92498cada3
< 2.0.65
MEDIUM 6.4 The Contests by Rewards Fuel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'update_rewards_f… wordfence
9ed80507-f3e5-45a8-9498-8cebf97155ff
< 4.10.37
MEDIUM 6.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Coun… wordfence
9ec4bd64-f13f-4e13-9829-8ccf2b8fd196
< 1.1.5
MEDIUM 6.4 The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in … wordfence
9ebd4586-bddc-4669-957b-2bab7a35adee
< 3.3.2.2
MEDIUM 6.4 The SimpLy Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3… wordfence
9e7f858c-945c-4d12-a2a6-113449ad890a
< 3.3.8
MEDIUM 6.4 The Editor Custom Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads i… wordfence
9e661d3c-8acf-48c2-9e54-6913c65a46aa
< 1.5.48
MEDIUM 6.4 The Page Builder: Live Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
9e63fb84-a16b-447f-be73-e01f30881445
< 3.14
MEDIUM 6.4 The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all ver… wordfence
9e5a6158-03d4-4ac7-8a4b-666cedabb433
< 9.112.2
MEDIUM 6.4 The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_cta… wordfence
9e57a85b-3ea8-46df-ab60-ce835268b1f6
< 2.1.0
MEDIUM 6.4 The Divi Carousel Maker – Image, Logo, Testimonial, Post Carousel & More plugin for WordPress is vulnerable to Stored … wordfence
9e47a2d3-ab79-417d-b36b-2f8a8c515bc3 MEDIUM 6.4 The Simple Sort&Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘indexurl’ paramete… wordfence
9e3e698e-0f98-43ca-b4c1-d45fe3c9b284 MEDIUM 6.4 The Urdu Formatter – Shamil plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
9e394bb2-d505-4bf1-b672-fea3504bf936
< 2.8.7
MEDIUM 6.4 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… wordfence
9e34b3df-ac18-4409-b8fe-b27c931f3aa3
< 1.8.12
MEDIUM 6.4 The Muslim Prayer Time-Salah/Iqamah plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Masjid ID … wordfence
9e2cc3b5-8eb7-42ef-be25-f778560b6e58
< 2.0
MEDIUM 6.4 The HashThemes Demo Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
9e1514c8-3752-4d0a-87a3-3f245a7cb914
< 3.11.19
MEDIUM 6.4 The Easy Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ea_full_calend… wordfence
9e105e89-3884-465e-8565-2fec7cc894da
< 2.4.8
MEDIUM 6.4 The Embed PDF Viewer plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includ… wordfence
9e008a72-c948-48eb-814d-52ec6bc9f8d2
< 1.7.8
MEDIUM 6.4 The Turbo Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
9dffc99e-6dbc-415b-91d1-a85a30168526
< 2.24.0
MEDIUM 6.4 The NextMove Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
9dfc5868-1215-465f-8a4e-3703c18d7dca
< 3.2.3
MEDIUM 6.4 The IMPress for IDX Broker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
9df00907-c95e-445c-b424-78a1e5e00e4f
< 3.4.10
MEDIUM 6.4 The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-… wordfence
9de3dd8e-8529-496c-99ff-aa13d484135c
< 1.6.84
MEDIUM 6.4 The Bricksable for Bricks Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
9dd85315-fb4d-40fa-9478-4b09154c688a MEDIUM 6.4 The Live Streaming Video Player – by SRS Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in v… wordfence
9dd6828b-6235-4284-bce6-be23b79ac70e
< 1.3.0
MEDIUM 6.4 The Post Meta Data Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$meta_key’ par… wordfence
9dd6433f-cc12-47c7-a641-3da8a6b0f15b MEDIUM 6.4 The iWR Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `iwrtooltip` shortcod… wordfence
← Prev 584 585 586 587 588 589 590 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top