🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 866 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9af6d311-a72e-4c86-8ecb-70fa83e5a240
< 1.3.0
MEDIUM 6.1 The OTA Sync Booking Engine Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
9ae771d1-9c4e-4123-9221-146e7ba2c2ac MEDIUM 6.1 The WordPress Firewall 2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
9ae135c3-2b2b-4cd2-a17b-3b1e9de9dbac
< 2.70.00
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in feedlist/handler_image.php in the FeedList plugin 2.61.01 for WordPress allo… wordfence
9ab22aa8-399f-449b-83cf-25583c057cff
< 4.62
MEDIUM 6.1 The SP Project & Document Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown pa… wordfence
9aa2d91f-0524-4bf1-8274-bbd35370ba67 MEDIUM 6.1 The Agrion theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.0 d… wordfence
9a999044-5d4a-4415-a3b9-28c564e63a25
< 1.5.9
MEDIUM 6.1 The Responsive Vertical Icon Menu plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ … wordfence
9a93ecaf-582d-4689-ba1f-52731c4b1ab7 MEDIUM 6.1 The Edit Comments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘jal_edit_comments’ p… wordfence
9a932e25-f7ff-4765-b827-c9e7dd9e30bd MEDIUM 6.1 The FS Product Inquiry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
9a8e6313-97df-45bf-840b-97002f368235 MEDIUM 6.1 The WP FixTag plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
9a83f381-a8ce-472d-a202-f7d7f22fd650
< 1.7.92
MEDIUM 6.1 The Simple SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in version… wordfence
9a7cbd2e-79c9-4be7-b458-e4e5f0376a22
< 1.4.9.6
MEDIUM 6.1 The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb… wordfence
9a7737b3-d85b-471f-8252-3ee6b598786d
< 1.23
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for Wor… wordfence
9a7709fd-bb53-47a6-9fae-d5a6be513b39
< 1.11.9
MEDIUM 6.1 The Broken Link Checker plugin through 1.11.8 for WordPress is susceptible to Reflected XSS due to improper encoding and… wordfence
9a5eb090-2dfb-4b30-bfc6-38061b94b87a
< 1.6
MEDIUM 6.1 The Password for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
9a4bcfc8-7f6f-4039-9712-016f34a5ed76 MEDIUM 6.1 The WP Featured Screenshot plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
9a279832-64d8-4e0b-8eba-b7b89c80069d
< 2.9.3
MEDIUM 6.1 The Survey And Quiz Tool plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.… wordfence
9a13cbc7-fd51-43e6-bf22-4d0510c5a1c7
< 1.2.5
MEDIUM 6.1 The Easy Digital Downloads (EDD) Quota theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.… wordfence
9a0fc036-5fd1-4cc2-b7e0-2830feb66355 MEDIUM 6.1 The banner-manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
9a0bc461-d4fa-46d5-8725-9ab4c540b80e
< 2.9
MEDIUM 6.1 The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions u… wordfence
9a077f41-ff1d-4c86-8f39-5e2f795abc3e MEDIUM 6.1 The FlashCounter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
99fe886b-efc3-4133-98e7-8ceccf89a99b
< 2.0.93
MEDIUM 6.1 The RentSyst – CRM solution for fleet management plugin for WordPress is vulnerable to Cross-Site Request Forgery in a… wordfence
99e922ec-d40a-47e7-a10f-d966a351d182
< 3.3.76
MEDIUM 6.1 The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi… wordfence
99e001f2-9fed-4674-b150-01612d8a74d8
< 1.7.2
MEDIUM 6.1 The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Sc… wordfence
99df8839-caad-4568-9b05-cb2aea38a051
< 1.3.0
MEDIUM 6.1 The TownHub theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2.9 … wordfence
99dcb6c4-b9c6-4d3d-942f-b3877cc3efa7
< 1.66.3
MEDIUM 6.1 The SEO Landing Page Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad… wordfence
← Prev 863 864 865 866 867 868 869 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top