πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 590 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9b6175e7-0cfc-4049-bcfe-2c57cfb24fdb MEDIUM 6.4 The WP fancybox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.… wordfence
9b5e37b4-4a7e-41a1-b1ef-0c69c8658c58
< 2.5.6
MEDIUM 6.4 The Slideshow SE plugin for WordPress is vulnerable to Stored Cross-Site Scripting in certain plugin configurations in v… wordfence
9b53cdb8-e207-4a7a-bc7c-9d8669df1143
< 2.2.12.1
MEDIUM 6.4 The JetTabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.12 d… wordfence
9b4d2561-34aa-493e-9dc7-50406dd7f9a4
< 1.3.4
MEDIUM 6.4 The Gallery PhotoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
9b487949-c52d-43ec-b660-2d4057bf3c08
< 1.7.6
MEDIUM 6.4 The Page scroll to id plugin for WordPress is vulnerable to Stored Cross-Site Scripting via one of its shortcode attribu… wordfence
9b38d892-6797-43ae-9f17-f8f90222911e
< 2.3.5
MEDIUM 6.4 The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting … wordfence
9b192a54-fe49-4bdf-bd91-0e88eb228cc4
< 2.3.1
MEDIUM 6.4 The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
9b09e0dc-b394-4c74-a89d-8cd4379adb73
< 1.5.6
MEDIUM 6.4 The Xpro Addons For Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ver… wordfence
9aef779b-b1fc-4504-bba5-0d2698b52427
< 2.2.7
MEDIUM 6.4 The Easy Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
9ae076e4-ad15-4069-be10-f0f4aced4132
< 5.3.7
MEDIUM 6.4 wordfence
9ad96faa-cbc2-46c3-a8e6-afa6744ada86
< 0.2.7
MEDIUM 6.4 The WP DataTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜id’ parameter in all ver… wordfence
9acec3df-84d6-4cea-8756-64fbb468e5e0
< 1.2.2
MEDIUM 6.4 The Cinza Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cgrid_skin_content' post meta … wordfence
9acb6e7d-990d-4ed7-93ab-79ba94aa9016 MEDIUM 6.4 The Login Logout Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in… wordfence
9ac33fd5-602b-4810-96e1-850ea6ee739d
< 2.19.1
MEDIUM 6.4 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uag… wordfence
9abb2f0a-413f-4632-9b05-3bb0e7c2bb85
< 1.7.3
MEDIUM 6.4 The ID-SK Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
9abae49f-b396-4684-8dd5-0b5593069861
< 1.8.0
MEDIUM 6.4 The Lana Downloads Manager plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and includi… wordfence
9aa98012-1c0c-402d-9e4f-89b2d45f71e1 MEDIUM 6.4 The WCS QR Code Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
9a9d6c71-98ce-4fa7-817a-43e4f3dc0602
< 2.2.0
MEDIUM 6.4 The Shortcodes Blocks Creator Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'scu' short… wordfence
9a92f44b-6f2b-439c-8245-ace189740425
< 1.3.2
MEDIUM 6.4 The Custom WooCommerce Checkout Fields Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
9a87f0a2-42b0-4536-b4d1-83a9f6ed4262
< 9.1.1
MEDIUM 6.4 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
9a7ca5f6-89c0-49ce-9aef-2208365c6151
< 8.9.4
MEDIUM 6.4 The Simple Link Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `qcopd-dire… wordfence
9a714afd-2840-4301-a2b8-1ca9b6774698 MEDIUM 6.4 The Simple Post Expiration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
9a5c2cb6-827f-442d-b510-8f0ddcaaaca3
< 2.9.10
MEDIUM 6.4 The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
9a4a2c6c-81f5-4812-8226-73a27782d78e MEDIUM 6.4 The Aparat Responsive plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
9a47708e-c8b4-4eab-a960-4abaa831ca42 MEDIUM 6.4 The Fintelligence Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
← Prev 587 588 589 590 591 592 593 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top