πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 863 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9e013542-8a8c-440d-9130-61057d97990d
< 0.7.0
MEDIUM 6.1 Cross-site scripting vulnerability in Custom Body Class 0.6.0 and earlier allows remote attackers to inject arbitrary we… wordfence
9ddc2f44-e53f-45c2-b293-ad4abc8cff8f MEDIUM 6.1 The Geo Magazine Theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜s’ parameter in versio… wordfence
9dd48d0f-00c2-4f76-923b-eb5c7a2b4468 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in settings/pwsettings.php in the Your Text Manager plugin 0.3.0 and earlier fo… wordfence
9dd38406-0e67-4bd6-b9a3-0bc69f99148f MEDIUM 6.1 The Integration of Zoho CRM and Contact Form 7 plugin for WordPress is vulnerable to Open Redirect in all versions up to… wordfence
9dc9907d-9820-478e-80dc-3155b1621c88 MEDIUM 6.1 The WordPress Email Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… wordfence
9dc90b13-2f36-45bc-991c-f1927ae9253d
< 2.20.29
MEDIUM 6.1 The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'rt' parameter … wordfence
9dc49d44-d4ba-49d8-96eb-547832fe4b5e
< 4.24.8
MEDIUM 6.1 The WordPress File Upload plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dir' parameter i… wordfence
9dad1be5-ea6c-40fa-bb21-862e7fd8804a MEDIUM 6.1 The 2D Tag Cloud plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wi… wordfence
9dac1d91-b9a9-47e0-86cb-2000659196c5
< 0.8.8.6
MEDIUM 6.1 The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_timeout_pag… wordfence
9d9d6433-94c1-4e31-b16a-88b6ae6330c5 MEDIUM 6.1 The Twitter Shortcode plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
9d9997f2-df58-4f6d-99ed-0f3060eb9976
< 1.5.5
MEDIUM 6.1 The WordPress Events Calendar Plugin – connectDaily plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
9d990802-a964-493a-8f34-4b5784f52e60
< 11.2.3
MEDIUM 6.1 The Product Feed PRO for WooCommerce WordPress plugin before 11.2.3 does not escape the rowCount parameter before output… wordfence
9d8f2aaf-43db-412b-947c-ca1eb946c3aa MEDIUM 6.1 The Country Blocker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ip' parameter in all v… wordfence
9d86642a-3c11-43a2-8423-ca1cae058458 MEDIUM 6.1 The xPromoter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3… wordfence
9d7f48a9-07f9-4add-bfa2-7ddbcf2f866f MEDIUM 6.1 The wp-whois-domain plugin 1.0.0 for WordPress has XSS via the pages/func-whois.php domain parameter. wordfence
9d7a0f2f-a0f6-4a78-abc9-13364cac8490 MEDIUM 6.1 The Easy Amazon Product Information plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
9d72ad35-a16e-40a1-8d91-2a9a798e83df MEDIUM 6.1 The Translation.Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
9d72604e-23ef-4a69-8839-cf8ff4aef3bc
< 3.2.44
MEDIUM 6.1 The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via redirect parameter in vers… wordfence
9d6a7230-07c7-43f3-a844-77d2bb19545d
< 2.4.6
MEDIUM 6.1 The W4 Post List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via unescaped URLs in versions up … wordfence
9d67965c-f8f3-4868-a261-81cfc80dbcb3
< 1.0.8
MEDIUM 6.1 The Contact Form 7 Redirect & Thank You Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th… wordfence
9d5fc7a7-8461-4bd3-9d4e-1f5c98827d83
< 5.6
MEDIUM 6.1 The XStore Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 5.6 due to insuff… wordfence
9d5f9d2e-6719-4ce7-bbdd-afaf437bd080
< 7.6
MEDIUM 6.1 The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'link_price' and 'link_tag… wordfence
9d4df759-1d5a-478a-aab1-f728fe909b5e
< 1.22.7
MEDIUM 6.1 The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error paramete… wordfence
9d4cede0-133f-487f-9b4d-7a9ffd2133ea MEDIUM 6.1 The CountDown With Image or Video Background plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in ver… wordfence
9d429b0d-ad85-4822-abf5-7e35012b0c3e MEDIUM 6.1 The cTabs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. Th… wordfence
← Prev 860 861 862 863 864 865 866 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top