🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 869 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
97e97825-8144-423c-ac4c-3c5ae0dbbb10 MEDIUM 6.1 The RentPress WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the selections parameter found in the… wordfence
97e1d671-7be9-4515-8df1-b2e617f0c94d MEDIUM 6.1 The Universal Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
97cdcc23-4f63-4976-bc47-805d5dbbee09 MEDIUM 6.1 The Fixedly Media Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘template_id’… wordfence
97cbf2d7-2fdc-4c10-872d-add54687dd9b
< 1.15.4
MEDIUM 6.1 The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Reflected Cros… wordfence
97c921e4-a05d-43db-9fe7-3dac8ea4d249
< 4.1.10
MEDIUM 6.1 The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a spe… wordfence
97c24208-46b2-48a0-a87b-78e642c044cd
< 3.1.1
MEDIUM 6.1 The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search… wordfence
97c21d5a-9140-4e97-b166-531d243b084d
< 7.9.4
MEDIUM 6.1 The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to 7.9.4 (exclu… wordfence
97bff7aa-d304-4ccd-bfca-d3f18568df6c MEDIUM 6.1 The dhtmlxSpreadsheet plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.0 v… wordfence
97ad1b6e-2f2b-49f6-9970-fd413bfc544a
< 1.10.5
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the My Calendar plugin before 1.10.5 for WordPress allows remote attackers t… wordfence
979f52b8-0860-43d0-9675-6e9880f48e21
< 3.6.1
MEDIUM 6.1 The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vul… wordfence
979bb48d-6dbf-4bb2-90f3-573797ff23f7
< 1.4.3
MEDIUM 6.1 Themb.miniAudioPlayer – an HTML5 audio player for your mp3 files plugin for WordPress is vulnerable to Cross-Site Scri… wordfence
9798cee8-9aaa-40c1-91a4-55251baafbb0
< 7.0.9
MEDIUM 6.1 The Grand Restaurant theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 7.0.9 due to … wordfence
977a673c-075a-4662-b3e1-91a604e546f8
< 3.0.5
MEDIUM 6.1 The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPr… wordfence
9773329c-8d08-4467-a546-03c5a2531303 MEDIUM 6.1 The Whitelist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5… wordfence
9772aa85-15e6-4254-9e76-e5794d71084b
< 1.7.7
MEDIUM 6.1 The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Reflec… wordfence
976f9d0e-8ad8-4ce8-8917-b5c7f5a24cbb
< 2.1
MEDIUM 6.1 In the Parallax Scroll (aka adamrob-parallax-scroll) plugin before 2.1 for WordPress, includes/adamrob-parralax-shortcod… wordfence
97690bde-f2c6-429b-8d5a-51bee4a981ca
< 2.9.51
MEDIUM 6.1 Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect us… wordfence
974f14e8-1a59-4ba5-8806-b4d8b135315e MEDIUM 6.1 The Sloth Logo Customizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
974b3894-f4e2-49c7-ba92-eaa5be0b4298 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in phpwhois 4.2.5, as used in the adsense-click-fraud-monitoring plugin 1.8.6 f… wordfence
97411fd3-72c0-4715-be1c-c01e8744d278 MEDIUM 6.1 The Strx Magic Floating Sidebar Maker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… wordfence
97291fdf-ca78-4588-ba38-b021654a168f MEDIUM 6.1 The Advanced lazy load plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
971d06e2-29dc-424d-b20e-8ec34990014d MEDIUM 6.1 The Ambience Theme for WordPress is vulnerable to Cross-Site Scripting via the 'src' parameter in the 'thumb.php' file. … wordfence
9719d083-cc7c-4655-a4c4-f5370cfe76e0
< 3.20.1
MEDIUM 6.1 The Order Delivery Date for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'or… wordfence
9717e4aa-4294-4194-b2ab-3b0ec845a1ca
< 2.5.4
MEDIUM 6.1 The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg. wordfence
9707faea-ed46-4b7e-b4f5-a2aacdc70c80 MEDIUM 6.1 The Awesome Twitter Feeds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
← Prev 866 867 868 869 870 871 872 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top