🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 864 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9d2a238f-7192-49f0-be2e-3a35fca651d9 MEDIUM 6.1 The 微信机器人高级版 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
9d272148-0c05-49c7-ab86-22a3bc622bcf
< 1.9.4
MEDIUM 6.1 The pdf-print plugin before 1.9.4 for WordPress has multiple XSS issues. wordfence
9d164f5e-c313-4e45-a17b-61460b10204e
< 5.4.13
MEDIUM 6.1 The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is … wordfence
9d0eb69a-3c94-40c2-acdf-6310190197a6
< 2.3.1
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the Leaflet plugin before 2.3.1 for WordPress allow remote attack… wordfence
9d0782ef-b74e-4540-a11d-280e432fc127
< 2.1
MEDIUM 6.1 The Mail Subscribe List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sml_name' and 'sml_em… wordfence
9cfa4cb3-0f16-40be-9e78-ea378c3f535f
< 2.74
MEDIUM 6.1 The media-library-assistant plugin before 2.74 for WordPress has XSS via the Media/Assistant or Settings/Media Library a… wordfence
9cf10ed7-7248-4dfd-b7ee-13cea3ee2154 MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in Quick Post Widget plugin 1.9.1 for WordPress allow remote attacke… wordfence
9cebd25f-d2de-40d9-b2ab-a746c817b3ce MEDIUM 6.1 The Amazon Showcase WordPress Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… wordfence
9ce819fa-5c94-4116-9361-1de24619c27b MEDIUM 6.1 The Login Widget With Shortcode plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including… wordfence
9ce6b1fe-637b-4e2d-99e1-d23873d8f53f MEDIUM 6.1 The BizLibrary plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
9ce0cc7a-c5ab-4a65-9f1b-7b2f83e36bdd MEDIUM 6.1 The XmasB Quotes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
9cc1627c-2eb7-4817-a7ce-eaa9097fd5f8
< 5.4.3
MEDIUM 6.1 The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
9cbc3383-f30e-46a1-a606-5b31082b0696 MEDIUM 6.1 The Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable to R… wordfence
9cb3a665-8a3a-4261-b84c-0f4c90ee7664 MEDIUM 6.1 The xSmart theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2.9.4… wordfence
9cac974f-a7d7-47d0-8472-9df7e09e02ca
< 3.0.1
MEDIUM 6.1 The VForm plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.0.0 d… wordfence
9ca26f8b-795c-4d3b-b79c-1109e65a9e7f
< 1.9.2
MEDIUM 6.1 The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is… wordfence
9c9feabc-6a8d-4367-8ea2-cc5284dbc041
< 6.46
MEDIUM 6.1 wordfence
9c8ff308-712b-4cf6-98ea-200d2fed9c43
< 3.2.0
MEDIUM 6.1 The Comments - wpDiscuz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘message’ param… wordfence
9c839d07-c496-46cc-8024-742f44cd3638
< 2.0.6
MEDIUM 6.1 The quotes-collection plugin before 2.0.6 for WordPress has XSS via the wp-admin/admin.php?page=quotes-collection page p… wordfence
9c77f6f3-f3de-44ca-b0e1-9281559c40db MEDIUM 6.1 The XV Random Quotes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'qo' parameter in all … wordfence
9c5a4705-1bad-4ea9-9102-dc2780a61ac7
< 1.7.2
MEDIUM 6.1 The essential-real-estate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in… wordfence
9c538318-4c6f-4610-b4d4-a20005148d23
< 1.0.9
MEDIUM 6.1 The Gallery Categories by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ca… wordfence
9c42095d-c5b5-448a-8c6e-9a6c0e15a660
< 3.7.9
MEDIUM 6.1 The Usernoise modal feedback / contact form plugin for WordPress is vulnerable to Cross-Site Scripting in versions befor… wordfence
9c397428-7f4e-4775-b520-e47328cbe753 MEDIUM 6.1 The Stripe and PayPal Payment Forms for WordPress – PayForm plugin for WordPress is vulnerable to Cross-Site Request F… wordfence
9c2f884b-3b5e-41ab-a291-3562c4b5a732
< 12.7.4
MEDIUM 6.1 The real-estate-manager-pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … wordfence
← Prev 861 862 863 864 865 866 867 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top