🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 868 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
98beda7c-7896-4b53-b22a-83aac79563fa MEDIUM 6.1 The Read More Copy Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
98be1eb8-ee7d-4a39-b70f-5037b651ba96
< 2.6.4
MEDIUM 6.1 The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versi… wordfence
98b172d3-9751-4a55-8327-57ca7abf8a20 MEDIUM 6.1 The WP Social Broadcast plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … wordfence
98994612-c9b4-45a1-afc1-5d7a0712376d MEDIUM 6.1 The Gallerio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, … wordfence
988c1968-ef92-4d3d-bbd5-88e73512ebb4
< 1.27
MEDIUM 6.1 The Require & Limit Categories, Tags, Featured Image and taxonomies plugin for WordPress is vulnerable to Reflected Cros… wordfence
9889aa40-c4a4-4218-918a-57c5dc17e076 MEDIUM 6.1 The Simple Proxy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
986957ab-7394-457e-9a6f-f6b96b56cd15
< 1.45
MEDIUM 6.1 The Breadcrumbs Shortcode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
985fd6a4-282a-48e9-9149-69e6ee794667
< 5.5.9
MEDIUM 6.1 The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_q… wordfence
985daa72-80be-477d-9c80-b7849c94a405 MEDIUM 6.1 The eDS Responsive Menu plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
984bfc69-e203-4a06-9d4b-2185ecf771bd
< 1.5.2
MEDIUM 6.1 The time-sheets plugin before 1.5.2 for WordPress has multiple XSS issues. wordfence
9846cb0e-fc68-4a1b-a5a5-63116289c369
< 3.5.6
MEDIUM 6.1 The Easiest Funnel Builder For WordPress & WooCommerce by WPFunnels plugin for WordPress is vulnerable to Reflected Cros… wordfence
983c603b-b9bb-4942-b554-345535886aea
< 0.2.6
MEDIUM 6.1 The World of Warcraft – Armory Table plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘p… wordfence
983b4fac-cf27-4156-85a0-e4db90aee327 MEDIUM 6.1 The Felici Premium Magazine Theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘buttonText’… wordfence
983b0fb8-a6e6-422e-ad90-325ad7aa628b
< 3.15.10
MEDIUM 6.1 The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
98345631-45df-419b-aada-b7053a31b68c
< 4.2.0
MEDIUM 6.1 The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vu… wordfence
9832c598-aa12-4a98-8e0f-643ecbe75839
< 2.40.1
MEDIUM 6.1 Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious … wordfence
982bc924-1dcd-47b5-b15a-4ff0ad123ad1
< 3.5.15
MEDIUM 6.1 The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulner… wordfence
982680a5-c534-4038-ae80-e59aa9761174
< 2.9.9.5.8
MEDIUM 6.1 The Pinpoint Booking System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
98125cd1-b037-4ace-9769-3522db53d081 MEDIUM 6.1 The WP_Identicon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
980ed456-b6a9-4ca0-99ce-513b20af6d8f
< 0.6.1
MEDIUM 6.1 The WP Print Friendly plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.6 d… wordfence
980d1726-375f-41b2-a67c-1b934e20312c
< 2.0.2
MEDIUM 6.1 The Easy Digital Downloads (EDD) Attach Accounts to Orders extension for WordPress, as used with EDD 1.8.x before 1.8.7,… wordfence
98008119-1be7-404c-b191-7585d51549d3 MEDIUM 6.1 The Import Export For WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
97fd7952-a7f0-4797-82cd-840c0a3e5fbe
< 1.3.29
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Ultimate Member WordPress plugin before 1.3.29 for WordPress allows remo… wordfence
97f2b71f-ef3e-4826-8e78-62820672ec0c MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in library/includes/payment/paypalexpress/DoDirectPayment.php in the Spotlight … wordfence
97f16bad-f0ad-44cc-bb07-04ce33d0cdf9
< 1.6.0
MEDIUM 6.1 The SEO Backlink Monitor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
← Prev 865 866 867 868 869 870 871 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top