🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 861 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a01cdc31-3cab-43b0-a5ef-75fb11eeb621 MEDIUM 6.1 The xpinner-lite plugin through 2.2 for WordPress has xpinner-lite.php XSS via several parameters. wordfence
a003129b-4a31-40f8-a9b2-9d3a3286cabe
< 1.1.3
MEDIUM 6.1 The XT Ajax Add To Cart for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the … wordfence
a00147db-2ca5-4290-ae13-27be6119b751
< 7.2.1
MEDIUM 6.1 The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
a0010ee3-1016-479f-ae60-5d5900862489 MEDIUM 6.1 The itsukaita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'day_from' and 'day_to' param… wordfence
9ff5a900-9e4d-4bd0-bd19-cad96e62f973
< 1.8.31
MEDIUM 6.1 The My Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Email field of booked tickets i… wordfence
9fe625bd-6050-4c74-b310-8dce05c1f4a5 MEDIUM 6.1 The Members page only for logged in users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
9fc3355f-a3e3-4f30-885a-90d4982f699e
< 2.18.4
MEDIUM 6.1 The bbPress Notify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
9faf3293-191c-48fb-a932-d61325d6c2e0
< 1.6.7
MEDIUM 6.1 The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
9faa9bd1-c7a8-4d8b-9f92-3a0aa9adbc03
< 1.1.2
MEDIUM 6.1 The Forget About Shortcode Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ajax_… wordfence
9fa1a551-36d4-488c-898a-3c13b509b8c9
< 5.0
MEDIUM 6.1 Multiple client-side cross site scripting vulnerabilities have been discovered in the WpJobBoard v4.5.1 web-application … wordfence
9f9ea566-7492-4616-bd67-e6b7449370f1 MEDIUM 6.1 The Explara Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
9f999f89-29eb-4871-a304-0ba6954e7e5b
< 4.1.2
MEDIUM 6.1 The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in vers… wordfence
9f97bad7-6044-4727-a229-2890e02e36b0 MEDIUM 6.1 Multiple cross-site request forgery (CSRF) vulnerabilities in the Mobile Domain plugin 1.5.2 for WordPress allow remote … wordfence
9f959e61-16cf-4260-b21b-8edb95a3cd65
< 1.7
MEDIUM 6.1 The Simple Membership After Login Redirection plugin for WordPress is vulnerable to Open Redirect in all versions up to,… wordfence
9f8de5a9-2279-4b84-b1f6-fdb293aa6017
< 3.2.2
MEDIUM 6.1 The CardGate Payments for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page… wordfence
9f857556-76fc-407a-8dd3-a248a566232a MEDIUM 6.1 The Zarinpal Paid Download plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
9f850644-4923-46c1-90f6-d29088c9cb1a MEDIUM 6.1 The Star CloudPRNT for WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and inc… wordfence
9f82ec7c-72a0-4c3b-8041-c6ad080a48f1
< 8.6.3
MEDIUM 6.1 The AcyMailing SMTP Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
9f77755a-9b28-4e31-8a01-42e96b5698bf MEDIUM 6.1 The Master Slider Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in v… wordfence
9f7469ec-cbd5-4f13-8455-b907f2542836
< 2.0.10
MEDIUM 6.1 wp-login.php in WordPress allows remote attackers to redirect authenticated users to other websites and potentially obta… wordfence
9f64a450-c280-4197-8ef6-e5828c52c1f1
< 1.7.6
MEDIUM 6.1 The MDJM Event Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
9f6329a7-0baf-4e07-8541-b342e5007014 MEDIUM 6.1 The Authors Autocomplete Meta Box plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions u… wordfence
9f617682-85f2-497f-a83a-f5a06b384d91 MEDIUM 6.1 The WP Visual Adverts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
9f4a3d17-d9fd-4ff4-a4b2-43030cdc7739
< 1.2.41
MEDIUM 6.1 The Booking Calendar Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dex_bccf… wordfence
9f4052ab-ff9e-48a6-8406-72e9b6237668
< 0.8.9
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the cms_tpv_admin_head function in functions.php in the CMS Tree Page View p… wordfence
← Prev 858 859 860 861 862 863 864 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top