ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 589 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9caaa8f9-b04c-4522-97e8-323f38b38bb3
< 2.2.1
MEDIUM 6.4 The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
9ca2c966-cea4-426b-9c70-5cb98fc1d125
< 2.0.1
MEDIUM 6.4 The E-cab Taxi Booking Manager for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers… wordfence
9c7edcbd-83b8-405b-892a-c404947990b3
< 4.4.1
MEDIUM 6.4 The Ø§ÙØ²ÙˆÙ†Ù‡ پیامک ووکامرس Persian WooCommerce SMS plugin for WordPress is vulnerable to SQL Injection a… wordfence
9c6cbe4e-ee14-4361-9db3-d6e820ee7171
< 4.5.14
MEDIUM 6.4 The WP Meta SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.5.… wordfence
9c641d50-51ac-47ca-beaf-3e79f436e091 MEDIUM 6.4 The WP-Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'roboshot' shortcode in all v… wordfence
9c2de78e-8530-416b-adef-e2e8ff322802
< 2.1.25
MEDIUM 6.4 The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _ob_spacera… wordfence
9c29c110-87ed-47e3-919f-f6e98f703805 MEDIUM 6.4 The Simple File Downloader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes… wordfence
9c1ac689-329a-4459-8b67-176e959cc02d
< 4.2.9
MEDIUM 6.4 The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' … wordfence
9c0df52e-f0c9-4ea5-aec7-d1075fd9668a
< 3.3.0
MEDIUM 6.4 The Ultimate Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
9c0d229d-b80c-4c73-a14e-253f382d87a2
< 3.1.2
MEDIUM 6.4 The The Events Calendar Shortcode & Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
9c0c3932-bdb0-4edb-bfec-2ed52cbc5cb6
< 6.0.4.4
MEDIUM 6.4 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … wordfence
9bfaff5c-25b0-470a-b1ef-fce5976ce205 MEDIUM 6.4 The UltraEmbed – Advanced Iframe Plugin For WordPress with Gutenberg Block Included plugin for WordPress is vulnerable… wordfence
9bf6b196-6dd8-41b7-9838-287be16559fd
< 1.2.2.21
MEDIUM 6.4 The WP Stripe Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcodes in the wp_st… wordfence
9bce7b25-fb64-44ac-b48f-00ef871610c6
< 3.1.3
MEDIUM 6.4 The mTouch Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the quiz name in versions up to, a… wordfence
9bc9e382-9902-4b2d-ac50-ecb2b94a2803
< 8.9.4
MEDIUM 6.4 The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
9bbe89d0-4b0a-40d6-b1a0-3faf9550ec5c MEDIUM 6.4 The Fintelligence Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fintell… wordfence
9bb6683a-b8e6-4776-880f-5b48966fc5c6
< 1.26.5
MEDIUM 6.4 The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plguin for WordPress is vulnerable to Stored Cross… wordfence
9baa8bbf-a318-4bc5-8bfd-2bd64536965e
< 4.6.14
MEDIUM 6.4 The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortco… wordfence
9ba07137-f834-4f56-bcd5-0f6fde756681
< 1.3.9
MEDIUM 6.4 The Hash Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' parameter within multi… wordfence
9b9d66db-53a8-4d93-9222-6f9649a7d842
< 2.7.9.9
MEDIUM 6.4 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_in… wordfence
9b9bd42f-cb24-483a-ae91-add4378067d9
< 7.0
MEDIUM 6.4 The ND Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.9 the p… wordfence
9b787a46-b887-4eb8-834a-456b7f495c5e MEDIUM 6.4 The Optimate Ads – Advance Ad Inserter AdSense & Ad Manager plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
9b726e21-ff76-43ea-beb1-f68e94d3b7a4
< 2.3.2
MEDIUM 6.4 The Smart Cookie Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in ver… wordfence
9b63dc2f-0d2b-43c8-9dc1-9d202cc92767
< 1.5.0
MEDIUM 6.4 The WP Table Builder – WordPress Table Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an… wordfence
9b633f24-4818-43cb-89f7-7d6caf84499b
< 2.6.4
MEDIUM 6.4 The Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates plugin for WordPress is vulnerab… wordfence
← Prev 586 587 588 589 590 591 592 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top