🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 588 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9dcd48b8-ec9e-44b4-b531-95940adbd100
< 2.4.0
MEDIUM 6.4 The GeneratePress Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom meta… wordfence
9dcd480e-71c5-4933-8627-914881776e13
< 1.3.8
MEDIUM 6.4 The Gum Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
9dc5452d-41e4-4b28-bb89-fe5ef9c10cb7
< 1.6.5
MEDIUM 6.4 The Medical Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typew… wordfence
9dc23817-f5fe-420a-8204-8440935f0bd7
< 2.1.0
MEDIUM 6.4 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
9dbd26f5-b75e-41a3-aefb-d6c8cc2cec7b
< 2.0.0
MEDIUM 6.4 The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the breakdance_css_file_paths_cache… wordfence
9dbc1f95-0f21-4a37-b1f7-eba03f29f021
< 1.3.16
MEDIUM 6.4 The Stratum plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.15 d… wordfence
9d8a03f7-a028-401c-9088-77e75dd365f6
< 1.0.21
MEDIUM 6.4 The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Co… wordfence
9d87fd94-8a64-4b9b-9e51-025a689fa87b
< 2.3.6
MEDIUM 6.4 The Restaurant Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in ver… wordfence
9d83c085-b33a-4003-9e0a-8457669d6634
< 3.0.5
MEDIUM 6.4 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sto… wordfence
9d7cd3eb-3ab7-44b3-8568-ce145977dfab MEDIUM 6.4 The WordPress Appointment Schedule Booking System plugin for is vulnerable to Stored Cross-Site Scripting via the 'cssfi… wordfence
9d50c9e5-d7c3-46d6-b01b-0a8f0e6f019e
< 2.3.1
MEDIUM 6.4 The Perfect Font Awesome Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
9d4f6085-39c8-4f2e-83e1-adb27de46af3 MEDIUM 6.4 The LC Wizard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.0 … wordfence
9d3b6448-14cc-4146-9a93-98150031fcb6
< 1.2.1
MEDIUM 6.4 The Wibar | Wine and Vineyard WooCommerce WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
9d37b7d7-ca79-4bf9-8e3a-00d4b0c5565f
< 1.7
MEDIUM 6.4 The Featured Image from Content – AI Featured Image Generator plugin for WordPress is vulnerable to Server-Side Reques… wordfence
9d28bd7d-ad3f-4720-9e09-466169fc672b
< 2.18.8
MEDIUM 6.4 The Lazy Load for Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lazy‑loading handle… wordfence
9d1cb486-f461-4a06-ae9a-39669109b2c0 MEDIUM 6.4 The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnera… wordfence
9d17a3a0-3c09-4d67-96d6-d97bde92f100
< 2.10.44
MEDIUM 6.4 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Ta… wordfence
9d0f1227-cb60-4973-95a6-6272f5173bf4
< 2.8.0
MEDIUM 6.4 The Yoga Schedule Momoyoga plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and … wordfence
9d04d8c1-75c0-447c-a26a-c2724c0a6618
< 1.9.8
MEDIUM 6.4 The Create by Mediavine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Schema Meta s… wordfence
9cfe91e6-238b-4652-892c-0016c1330088
< 1.1.13
MEDIUM 6.4 The B Slider - Slider for your block editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… wordfence
9cdf1b24-95fd-45e2-b303-36e033ed6ed4 MEDIUM 6.4 The mcjh button shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
9cd819c2-45ab-4e0d-b29a-d92722db7164 MEDIUM 6.4 The Mitfahrgelegenheit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘date’ parameter in… wordfence
9ccf2b56-0355-43e6-a616-d06196e90972
< 3.13.7
MEDIUM 6.4 The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is… wordfence
9ccb47c2-5f4b-45ea-9c48-0a9042a2fce6
< 3.7.1
MEDIUM 6.4 The Listdom – Business Directory and Classified Ads Listings WordPress Plugin plugin for WordPress is vulnerable to St… wordfence
9cad27cd-b4cc-4f34-8588-130e1ba997f9
< 2.1.3
MEDIUM 6.4 The Big Post Shipping for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… wordfence
← Prev 585 586 587 588 589 590 591 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top