πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 591 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9a423266-89e1-422d-b1e3-6368051eb2fe
< 1.3.2
MEDIUM 6.4 The Currency Converter Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sho… wordfence
9a30c6c2-fd90-421b-b4d7-ebe2605a96a0
< 1.1.0
MEDIUM 6.4 The Team Section Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
9a2782de-3ce2-4626-84c4-58c1ff454753
< 5.5.32
MEDIUM 6.4 The GetResponse for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortco… wordfence
9a190909-4b0f-4a44-8371-d79f64d323c2
< 3.1.1
MEDIUM 6.4 The a3 Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1… wordfence
9a0f1006-8015-4e67-9b03-16d3ad3c0e77 MEDIUM 6.4 The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
99ec0876-881c-4dfe-a870-b7f58635fd3d
< 1.2.7
MEDIUM 6.4 The Chatbox Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
99e4b38c-f81d-4578-a623-ea62495e934d MEDIUM 6.4 The Sudoku Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background' parameter in… wordfence
99e24496-0e3b-4bff-ba14-dc535be10633
< 2.6.6
MEDIUM 6.4 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sto… wordfence
99d3d5aa-dd82-415a-bc40-9d2c677d9248 MEDIUM 6.4 The Custom fields shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cf shortc… wordfence
99b47856-502e-4e9d-b0ea-62c57509b46a
< 1.8.1
MEDIUM 6.4 The WPBITS Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widget pa… wordfence
99b268a7-fd96-4fed-82e7-cfc651126f1f
< 1.1.0
MEDIUM 6.4 The Image Hover Effects for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
99a8b48b-2967-4179-a0eb-626bbe273f03 MEDIUM 6.4 The WordPress PayPal Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'donate' shortco… wordfence
999d1df5-9c8e-46bd-bf95-9240cd6594ed
< 1.3.3.5
MEDIUM 6.4 The WordPress Meta Data and Taxonomies Filter (MDTF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting i… wordfence
999c2207-6d45-4b46-8fe1-03682a949c5c MEDIUM 6.4 The Advanced Social Media Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `social` short… wordfence
99960ff7-62e1-4c44-ae8e-ebda3e075781
< 2.8.1.2
MEDIUM 6.4 The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
999475c5-5f17-47fa-a0d0-47cb5a8a0eb4
< 4.23.2
MEDIUM 6.4 The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'et_pb_text' shortcode in all… wordfence
9993bdab-3fd9-42f3-b16a-d92512c6573d
< 3.6.5
MEDIUM 6.4 The NiceJob plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.6.5 due to insufficien… wordfence
998d3485-97c2-4aa6-ba0c-693f5fd6af07
< 2.1.2
MEDIUM 6.4 The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'more' parameter in all ver… wordfence
9987b5b4-33d8-4446-acbe-58c6cb5604df
< 2.4.5
MEDIUM 6.4 The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
997b028c-8131-4579-8157-caecf099d7ec
< 2.1.2
MEDIUM 6.4 The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via div classes that can be added t… wordfence
9979bce7-4c9f-473d-b751-621b68300c28
< 4.3.9
MEDIUM 6.4 The CM Tooltip Glossary plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
9979381e-711d-42c8-bfdf-4ee99e2e556f MEDIUM 6.4 The Material Design Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mdi-icon sh… wordfence
996e5952-6462-4afd-81ab-afdc626fcc05 MEDIUM 6.4 The Hercules Core plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including… wordfence
996b5e29-beea-4678-8596-04e96a343584
< 1.2.2.3
MEDIUM 6.4 The Easy Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes ('url',… wordfence
99625a3e-b8a4-42f8-8996-f7c5c0ff2d5f
< 1.5.136
MEDIUM 6.4 The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widg… wordfence
← Prev 588 589 590 591 592 593 594 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top