ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 596 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
959ce050-bafc-4d17-93bd-a9b09b4b4baa
< 2.1.4
MEDIUM 6.4 The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
9595fa45-6b00-4ee0-89aa-a236dbf82423
< 5.6.0.3
MEDIUM 6.4 The WordPress Infinite Scroll - Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
9592bb6d-8e1d-4c89-addd-11c07272a628
< 20260105
MEDIUM 6.4 The Head Meta Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'head-meta-data' post meta … wordfence
959197c0-ce59-4f61-8fe9-11ac38bb0e41
< 3.5
MEDIUM 6.4 The Advanced Sermons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
9571a2f3-d148-4e9b-8837-b8d212418613
< 2.8.8
MEDIUM 6.4 The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in a… wordfence
956b49c3-42ee-447d-8a0c-56af64793464
< 2.3.4
MEDIUM 6.4 The LightPress Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data download URLs in all … wordfence
95691873-a16a-4e41-9456-41fa07efd6ce
< 2023.05.05
MEDIUM 6.4 The Daily Prayer Time plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
95631d97-14c9-45f2-b709-3eca7c38f09d
< 1.7.1
MEDIUM 6.4 The Justified Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
9548f647-9fcb-481c-874e-0184609283fe
< 2.5
MEDIUM 6.4 The Content Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all … wordfence
9547c6e9-3dfc-442c-900d-111b1528aa5b
< 5.1.7
MEDIUM 6.4 The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1.6 … wordfence
953d64f2-a514-48e9-9ab3-f9a793ad953a
< 1.9.2
MEDIUM 6.4 The Curator.io: Show all your social media posts in a beautiful feed. plugin for WordPress is vulnerable to Stored Cross… wordfence
9517db1f-1704-4f25-9b02-795da3c4c067
< 2.9
MEDIUM 6.4 The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rescue_tab' sh… wordfence
95136083-58d7-4ee4-b894-6910c3992d20
< 1.3.4
MEDIUM 6.4 The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stor… wordfence
9511d8f1-ab96-4695-aa8c-16a3482a6de4
< 2.7
MEDIUM 6.4 The Affiliate Links Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in… wordfence
950f7493-4ccb-4a8a-9cc2-23b9ba3a9cd0
< 3.4.7
MEDIUM 6.4 The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-S… wordfence
950e9042-1364-4200-8f57-171346075764
< 2.6.5
MEDIUM 6.4 The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attribute of a li… wordfence
950e5d04-1436-4886-8d36-fca38bd9414a MEDIUM 6.4 The Canadian Nutrition Facts Label plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'percentage… wordfence
950d71ae-29a1-4b71-b74a-b1a5c9f3326e
< 4.18.29
MEDIUM 6.4 The Real Media Library: Media Library Folder & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
950908c8-9afc-4fc4-aa02-0c9790cdcb4c MEDIUM 6.4 The Admin Columns for ACF Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
94faab0a-dee9-4c31-a5be-4de35cc01d62
< 2.0.3
MEDIUM 6.4 The WP Map Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Marker field in all versions … wordfence
94f366c8-65d7-4086-8a33-d4d81124d03f MEDIUM 6.4 The AuraMart theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.7 du… wordfence
94f19f56-0667-443e-8545-a17fbe9c3ddb
< 1.9.12
MEDIUM 6.4 The Accordion Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ attribute of a… wordfence
94e373fb-b3f5-4c1b-9eaa-89747af4dc30
< 3.11.15
MEDIUM 6.4 The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's… wordfence
94dfb7fc-1d57-4ff9-ae9e-5f7172e9b859
< 1.0.6.9
MEDIUM 6.4 The Active Products Tables for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… wordfence
94ca4814-d55c-4756-b4cf-2619a6fd0999
< 2.4.3
MEDIUM 6.4 The Sanzo theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 2.4.3 due to insufficient i… wordfence
← Prev 593 594 595 596 597 598 599 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top