ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 862 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9f3ccf43-dad2-445b-8e65-7d972249dc0b MEDIUM 6.1 The WP Front-end login and register plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions… wordfence
9f397671-0b59-4049-95af-3087e07685f0 MEDIUM 6.1 The Pet Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
9f395100-cf1f-4a3e-a353-1aec6b4e7448
< 1.5.47
MEDIUM 6.1 The PropertyHive plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'merge_ids' parameter in v… wordfence
9f2e0427-c000-4536-8639-b5f0c8f2b19f
< 2.1.14
MEDIUM 6.1 The MemberSpace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2… wordfence
9f200526-890c-4a2a-9d8e-334443ef7e0b MEDIUM 6.1 The WP-Strava plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to… wordfence
9f0fa6a7-43d8-4fc9-a2a3-7586d2bd986b MEDIUM 6.1 The Auto scroll for reading plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
9f0c2d65-a9b1-4ac4-8518-b5ba7dea25c8
< 4.19.1
MEDIUM 6.1 The eForm - WordPress Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions … wordfence
9f00b763-1b8a-4a20-96c6-7a93adf806e4
< 1.2.6
MEDIUM 6.1 The Contact Form 7 Summary and Print plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
9ef8f39e-6e5d-4ef6-a81d-0b2be3506ec1
< 6.4.5
MEDIUM 6.1 The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
9ee9b2e9-e3fe-43b2-9caf-7246a4201fe9
< 1.2.0
MEDIUM 6.1 The MailUp Auto Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
9ee4e021-946f-42e2-bae1-d73fdd34749d
< 7.7.2
MEDIUM 6.1 The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
9ee11e19-21a6-45df-a118-f6dec3b55bc1
< 1.0.8
MEDIUM 6.1 The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' param… wordfence
9ec52096-27c8-4c42-bc89-4aef8239ec6e
< 4.1
MEDIUM 6.1 The SyncFields plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and excluding, 4.… wordfence
9ec1d3e0-eb30-4f46-b533-f57fd9a8510f MEDIUM 6.1 The 17TRACK for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
9ebc263e-ff60-4e6f-8d93-02d99583447d MEDIUM 6.1 The Add custom content after post plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions u… wordfence
9eb14563-7aa6-4703-96ef-95708f08beff
< 1.1.1
MEDIUM 6.1 The Analytics Tracker plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1.0… wordfence
9ea32791-edd3-4495-893e-668f42dcf5e9 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for WooCommerce plugin 2.7.1 and earli… wordfence
9e9ef3dd-9055-4f9f-b3af-6bf34c06292a
< 4.20.96
MEDIUM 6.1 The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUER… wordfence
9e9a8383-7044-484d-8e4a-e9e4171da385
< 1.27
MEDIUM 6.1 The Prolisting - Directory Listing theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… wordfence
9e860c60-b330-4a6c-8d15-947451af62fc
< 1.7.1002
MEDIUM 6.1 The Royal Elementor Addons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
9e3899d8-170e-481f-8c80-90addc66eb41 MEDIUM 6.1 The Woocommerce Custom Checkout Fields Editor With Drag & Drop plugin for WordPress is vulnerable to Reflected Cross-Sit… wordfence
9e283a5a-98b7-464e-9426-cb414f3e3abf
< 3.96
MEDIUM 6.1 The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
9e2543be-e84f-424f-92cc-3a5d7e0a33b9 MEDIUM 6.1 The Naver Blog plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
9e169776-0475-45b8-8e8f-ac98cee558a3
< 4.1.0
MEDIUM 6.1 The LearnPress Export Import plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
9e104e84-5b2c-4111-8950-54030950a790 MEDIUM 6.1 The The Visitor Counter Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
← Prev 859 860 861 862 863 864 865 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top