πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,901
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 20, 2026
Last Updated

39,901 vulnerabilities found (page 601 of 1597)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9157fa5e-3af8-48ee-bb73-3df6109aae76
< 5.0.4
MEDIUM 6.4 The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/sr… wordfence
915708c5-c958-4c4d-8d94-b93b1bea6013 MEDIUM 6.4 The "Gallery Bank – WordPress Photo Gallery Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
9150a7d9-d792-4bb6-9d33-5892f9cdfd1e MEDIUM 6.4 The menu shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in ve… wordfence
914de8f3-e052-4256-af14-4a08eaa464b8
< 2.4.7
MEDIUM 6.4 The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
914bcc8f-fecd-450e-b2a7-0989b7a0dd4c MEDIUM 6.4 The Skype Legacy Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skype-statu… wordfence
914554fd-1525-4925-bce4-2df4a8df5dbf
< 4.0.6
MEDIUM 6.4 The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross… wordfence
913538e6-db9c-4073-ba4b-639b1996a416 MEDIUM 6.4 The Video Gallery by Huzzaz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
91253487-b82e-4431-aa16-76d94c063c83
< 1.1.5
MEDIUM 6.4 The Advanced Product Information for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… wordfence
9117c46b-33cc-41f5-98e9-4dac8d6352d4
< 1.0.119.1
MEDIUM 6.4 The Rank Math SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in ver… wordfence
910c0a32-b169-4728-888c-0dfea2066c9c
< 5.7.7
MEDIUM 6.4 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W… wordfence
910a877d-384f-46a3-b90d-bc56543caa03
< 1.0.22
MEDIUM 6.4 The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FancyBox in all… wordfence
91019c36-bf33-4cd6-ac54-86c118d086fe
< 3.0.0
MEDIUM 6.4 The JSM Screenshot Machine Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's … wordfence
90f96795-8df7-4388-b58e-fc3611bc215c
< 3.1.4
MEDIUM 6.4 In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accept… wordfence
90f40820-b854-4aaf-a17e-699fd06b2de9 MEDIUM 6.4 The Ads Pro Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5… wordfence
90edb2f1-0203-4f31-be13-cac21d156920 MEDIUM 6.4 The GDPR Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.2… wordfence
90ec6c64-f2c6-483e-9d8b-25e65ccb4a90 MEDIUM 6.4 The WP-Iconics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_icon… wordfence
90e24dba-e251-476e-87b8-c8df1e4317d4 MEDIUM 6.4 The Embed Google Datastudio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'egds' sh… wordfence
90d4d8c8-ccc1-46f8-bbf5-6aabaacc9d79
< 3.15
MEDIUM 6.4 The CopySafe Web Protection plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
90d23f3a-a67d-4f92-9ca8-926569b72a71
< 1.5.9
MEDIUM 6.4 The Primary Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
90d1baf1-2c65-4bdf-958d-001dcfe04d7f
< 1.3.20
MEDIUM 6.4 The All Bootstrap Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
90c34a01-a0d1-4305-b74b-b5a568a42b13
< 1.3.2
MEDIUM 6.4 The Jotform Online Forms – Drag & Drop Form Builder, Securely Embed Contact Forms plugin for WordPress is vulnerable t… wordfence
90b2a644-19a0-43a1-8ff6-7486d7ef29b3
< 1.3.21
MEDIUM 6.4 The Premmerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premmerce_wizard_actions' AJAX … wordfence
90b06fe3-a57b-4ba0-a976-c630e69e3d04 MEDIUM 6.4 The CF7 Spreadsheets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
90a8230f-7008-48af-a1a9-fbaf38dcb21c
< 3.19.15
MEDIUM 6.4 The Ultimate Addons for WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an u… wordfence
909beed4-06a9-4ec4-bf00-4072a38af82b
< 1.8.18.0
MEDIUM 6.4 The WP Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mst_subscribe' short… wordfence
← Prev 598 599 600 601 602 603 604 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top