πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 597 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
94c3e857-6e5b-4f1f-8ebb-fee439541beb
< 4.2
MEDIUM 6.4 The MailChimp Subscribe Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
94bae97d-2959-4ace-992d-1f4b1ccc8c3b
< 2.1.14
MEDIUM 6.4 The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcod… wordfence
94b89921-96a3-449a-998f-74cde4570468
< 3.7.3
MEDIUM 6.4 The Easy Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
94afe3e2-a1f1-470b-afaf-c7926beaec9a
< 7.5.5
MEDIUM 6.4 The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… wordfence
94ae2c4e-7281-4993-967b-6321e6279c47
< 1.6.2
MEDIUM 6.4 The Fusion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.1 due… wordfence
94a9ef6b-57f9-4e3b-a048-27538bbecf2f
< 2.1.5
MEDIUM 6.4 The MyBookTable Bookstore by Stormhill Media plugin for WordPress is vulnerable to Cross-Site Scripting in versions up t… wordfence
94a4123b-c21b-4f3e-b1cc-96c8f07c3fc6
< 1.2.2
MEDIUM 6.4 The FormFacade – WordPress plugin for Google Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
949eb9d6-0c8f-43f1-8580-998ea78c9549
< 2.6
MEDIUM 6.4 The Thai Lottery Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `thailottery` shortcod… wordfence
94974552-1c52-417b-9b4e-c30fd13a8ad4
< 13.2.2
MEDIUM 6.4 The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `trust… wordfence
94868d48-2d36-49f1-9da1-7965ecaeae3c
< 4.7.0
MEDIUM 6.4 The Gallery by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via gallery information in … wordfence
946f9596-3212-4208-a7e2-9e33a21dd97c MEDIUM 6.4 The Progress Tracker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
9455c6c6-39cd-4dfd-be4e-c3e4569d6867 MEDIUM 6.4 The Activity Plus Reloaded for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
943f9389-5306-44c6-be81-76f7f07d6d57 MEDIUM 6.4 The Ancient World Linked Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
943e20a1-b9f8-49b1-960a-7cab0f1b7683
< 2.2.2
MEDIUM 6.4 The Publitio plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2… wordfence
942df4bc-2a17-4add-9664-60d77319b93a
< 3.5.4.2
MEDIUM 6.4 The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpm… wordfence
94217d06-21c2-443d-ae2c-a2dbd65b7908
< 1.14.4
MEDIUM 6.4 The Addon Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to… wordfence
941cf3f8-20a0-4d41-8fce-1554653d98da MEDIUM 6.4 The REST API TO MiniProgram plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a mi… wordfence
93f80716-a95b-49fc-805f-446d4723ca77
< 1.3.31
MEDIUM 6.4 The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table C… wordfence
93efae1f-1e4a-48ee-8a69-558c38925250
< 3.9.1
MEDIUM 6.4 The Flower Delivery by Florist One plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'f… wordfence
93ec134f-246a-4b1c-8850-8d26126fd9a8 MEDIUM 6.4 The Liquido theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.1.2 d… wordfence
93de1604-2494-4c51-a93d-b01bf7ed4c07
< 1.4.5
MEDIUM 6.4 The WordPress Backup & Migration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parame… wordfence
93dcbab7-fdf5-4631-8605-77f8f190512d
< 3.1.3
MEDIUM 6.4 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordi… wordfence
93d8277f-3c5a-4024-a7c0-27ccb1a23cfc MEDIUM 6.4 The Aesop Story Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
93cf6dce-892e-4106-bb37-b7952e5ea5a1
< 2.4.0
MEDIUM 6.4 The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured o… wordfence
93c1033e-aaa6-4ddc-a3f0-a41e09069e3e
< 3.7.0.4
MEDIUM 6.4 The Uncanny Toolkit for LearnDash plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
← Prev 594 595 596 597 598 599 600 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top