🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 865 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9c2c3022-b0a0-4c1c-83da-8efe8ae935e4 MEDIUM 6.1 The 新淘客WordPress插件 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… wordfence
9c2883e6-2a90-46c7-ba42-cc078e4d1670
< 7.1.14
MEDIUM 6.1 Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject… wordfence
9c2465b8-09d2-4895-bc97-6f6f2e349d50 MEDIUM 6.1 The WP-ContactForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the (1) wpcf_email, (2) wpcf_su… wordfence
9c1814b0-b421-4957-b3e5-ac7415ee6108 MEDIUM 6.1 The WP Smart Flexslider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … wordfence
9c07a512-b5ca-4370-b244-7d0b07c30801 MEDIUM 6.1 The Real Estate Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
9bf83028-df6d-448e-a841-1da98a3a43d5 MEDIUM 6.1 The KeyCAPTCHA – Social WordPress CAPTCHA plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers… wordfence
9be8c202-56f0-449f-84fa-375d239b5654
< 2.5.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Markdown on Save Improved plugin before 2.5.1 for WordPress allows remot… wordfence
9bdf7b10-6a3e-47aa-86ae-479b4cd29c49
< 1.2.30
MEDIUM 6.1 installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin before 1.2.30 for WordPress has XS… wordfence
9bc832fa-9845-4157-b7a6-54d8c3794085 MEDIUM 6.1 wordfence
9bc66669-ee38-408a-9dea-e6421cc6f75c
< 3.4.1
MEDIUM 6.1 The WP Subtitle WordPress plugin before 3.4.1 adds a subtitle field and provides a shortcode to display it via [wp_subti… wordfence
9ba4e993-bf75-4570-bd9d-003339f4e214 MEDIUM 6.1 The duoFAQ - Responsive, Flat, Simple FAQ WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the msg pa… wordfence
9b97404f-c34d-483d-b11c-03a706306270 MEDIUM 6.1 The Cream Blog theme for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.1.3 due to … wordfence
9b86d9ea-b842-4492-82e4-dd979fbe70cf
< 1.9.4
MEDIUM 6.1 The WP ULike Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation i… wordfence
9b85c78c-da02-4871-a397-1d00a321a3c0
< 2.2.0
MEDIUM 6.1 Reflected XSS in wordpress plugin hero-maps-pro v2.1.0 via 'v' parameter. wordfence
9b78834c-cb13-4698-aa19-65f8c6874c8f
< 7.5.35.7212
MEDIUM 6.1 The FV Flowplayer Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ par… wordfence
9b6f004c-aaf4-4f44-8f59-0e9168d4d921 MEDIUM 6.1 The Google Maps GPX Viewer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
9b6be9c5-0142-458e-bf7e-2d4ae169e555 MEDIUM 6.1 The Sailthru Triggermail plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
9b57fbe8-0c8d-4ddb-8768-03ed354b2d21 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in fpg_preview.php in the Flash Photo Gallery plugin 0.7 and earlier for WordPr… wordfence
9b508a74-d61a-4837-a18b-c1d12c3acb80
< 5.0.0
MEDIUM 6.1 The Taskbuilder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4… wordfence
9b4bb70a-ee8e-4e1a-9989-7658307bedc1
< 4.20
MEDIUM 6.1 The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_item… wordfence
9b2b1500-04b6-40fb-8d1f-9c210f95788b MEDIUM 6.1 The LatestCheckins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
9b261abb-0af2-4a06-ae79-7661bab1b727 MEDIUM 6.1 The Syntax Highlighter Compress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
9b1329b6-ae1f-4a46-8435-5023c5c130f5 MEDIUM 6.1 The Contentboxes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in vers… wordfence
9b05ffc8-3f28-424b-aa3d-4132994b7376 MEDIUM 6.1 The RSV GMaps plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5… wordfence
9aff1e5b-2f16-43d0-b75a-c07e59a9c15f
< 2.217
MEDIUM 6.1 The Bard theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without app… wordfence
← Prev 862 863 864 865 866 867 868 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top