πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 867 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
99d73781-d0e8-4730-9ec1-ff2151982006
< 10.6.6
MEDIUM 6.1 The Wp EMember plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'login_pwd' parameter in all… wordfence
99d62147-f1bf-4146-a22d-d7d8486ed9e7 MEDIUM 6.1 The Book a Place plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
99c89e29-a21d-4c32-9459-18c7b08b9ff0
< 1.5.69
MEDIUM 6.1 The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜ bwg_search_X… wordfence
99c13de3-e040-4c11-b9c0-bd6a337c4769
< 1.3.5
MEDIUM 6.1 PageLayer before 1.3.5 allows reflected XSS via color settings. wordfence
99be8703-b462-4589-9918-76c0ebbb3bcf
< 2.1
MEDIUM 6.1 The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in ve… wordfence
99afde73-3f2b-4ba4-a82b-a6df42462384 MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow… wordfence
99a51d1f-35eb-4fe9-967e-c723b47393ea MEDIUM 6.1 The Author Showcase plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
999d8168-b4be-492e-8f25-9df104711341
< 2.0.15
MEDIUM 6.1 The J&T Express Malaysia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
999692ee-8bd4-4e7c-89a8-fba9d6f88bc2 MEDIUM 6.1 The Firework Shoppable Live Video plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… wordfence
9980ec20-60ae-42eb-a2cd-146e57435398
< 1.1.15
MEDIUM 6.1 The Premmerce WooCommerce Customers Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the… wordfence
99711f41-d21b-4725-acc8-9542283daf12
< 1.1.10
MEDIUM 6.1 The Thumbnail carousel slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
99555021-68f4-4395-978d-ff1bbae9ebd4
< 1.3.2.1
MEDIUM 6.1 The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ipf' parameter on the 'ch… wordfence
9954c283-4dd5-4b78-8c86-97b93a1880b4 MEDIUM 6.1 WordPress Xorbin Digital Flash Clock 1.0 has XSS via 'widgetUrl' parameter. wordfence
993670b7-a3ea-497d-ad46-881bd47b9346
< 2.8.18
MEDIUM 6.1 The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Filename parameter in … wordfence
9933ca13-32fd-4481-a18f-21e9a11c423c
< 4.9.3
MEDIUM 6.1 The Slimstat Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜$_SERVER['REQUEST… wordfence
992f9f08-82c1-4bbd-bbd2-543ad8affe53
< 2.3.22
MEDIUM 6.1 The WP Dynamic Keywords Injector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up… wordfence
992d3ed0-2df9-44f4-a36b-434bd89aa4ea MEDIUM 6.1 The Woocommerce Notify Updated Product plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … wordfence
99258980-2be8-4590-bf47-576bd1ae4535 MEDIUM 6.1 The Social Analytics plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
991a9271-f6cb-4d33-b853-21b927ac4ad1 MEDIUM 6.1 The ShareBang, Ultimate Social Share Buttons for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Sc… wordfence
9918ffe1-5911-48d7-84ba-8e6568d6f50c
< 5.0
MEDIUM 6.1 The Newsmag WordPress theme before 5.0 does not sanitise the td_block_id parameter in its td_ajax_block AJAX action, lea… wordfence
99140d47-88bb-48a1-863a-93a558541800
< 3.5.15
MEDIUM 6.1 The Modal Dialog plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the modal config id in version… wordfence
9911e99e-0b3b-4be1-b8cd-28593b6d12ad
< 1.09
MEDIUM 6.1 The LH Copy Media File plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_… wordfence
98f71c32-9453-4598-acb5-242818508c74
< 7.6
MEDIUM 6.1 The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to,… wordfence
98e47920-fb99-478d-9d6c-1612e8b4aca1
< 1.5.7
MEDIUM 6.1 The Contact Form to DB plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.5.… wordfence
98c9c9cb-ca35-461e-9ca6-733012332fd6
< 2.6.5
MEDIUM 6.1 The MakeStories (for Web Stories) plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and incl… wordfence
← Prev 864 865 866 867 868 869 870 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top