🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 870 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9704b633-5779-42a7-90d7-e532448f2e51
< 3.4.6
MEDIUM 6.1 The wp-all-import plugin before 3.4.6 for WordPress has XSS. wordfence
96f1ede7-ec36-4edf-baee-5e41907290af
< 2.1.1
MEDIUM 6.1 The Gwolle Guestbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘/gwolle-gb/admin/page-… wordfence
96f08ba8-102e-425e-b3e6-21e689682a24 MEDIUM 6.1 The GoogleMapper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
96ef8459-1600-4ca0-93c6-0ee42f8adabd MEDIUM 6.1 The VatanSMS WP SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` parameter in all… wordfence
96e47918-7848-407a-8f77-dbbfeb17029d
< 3.6.0
MEDIUM 6.1 The Skt NURCaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
96d5bfeb-b082-44cc-8d84-1ef1c3f5b562
< 2.73.4
MEDIUM 6.1 The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting … wordfence
96cec16e-7bb3-4279-8c17-eca88d413ad8
< 1.1.0
MEDIUM 6.1 The MemorialDay plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
96cb9096-f3bd-4fe2-affb-ca8c69af14f1 MEDIUM 6.1 The Show notice or message on admin area plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
96c5836f-6d33-4a56-b30b-5e5d95b81b6b
< 2.4.2
MEDIUM 6.1 The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress … wordfence
96a9f567-6cf8-4988-bf8e-77eade71c5f6 MEDIUM 6.1 The ocim-mp3 plugin through 2016-03-07 for WordPress has wp-content/plugins/ocim-mp3/source/pages.php?id= XSS. wordfence
96a5db79-a88d-4c1f-9da4-6dd3120ff85e MEDIUM 6.1 The WP Revisions Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
969b54d4-50db-4a2f-afa1-e22b29af661e
< 1.1.5
MEDIUM 6.1 The Colorbox Lightbox Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_locale’ parameter… wordfence
9680fed3-e8fe-4845-9807-f139f9e22e79
< 1.0.6
MEDIUM 6.1 The Check & Log Email WordPress plugin before 1.0.6 does not sanitise and escape a parameter before outputting it back i… wordfence
967ff273-33f3-4580-928a-7764583429aa
< 7.5.9
MEDIUM 6.1 The YellowPencil Visual CSS Style Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the liveL… wordfence
9678e683-5d51-47dd-8c0f-4eb47d9be636 MEDIUM 6.1 The Mobilize plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.… wordfence
966b43ea-dbd3-4f1e-b803-08027fff6f8f
< 1.2
MEDIUM 6.1 The wordpress vertical image slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘imag… wordfence
96649aa6-f3ba-4e9e-9fa5-a5fbd52c3836
< 2.2.0
MEDIUM 6.1 The CodeBard's Patron Button and Widgets for Patreon plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
9651f4cf-5349-460c-a453-326600280990 MEDIUM 6.1 The AdWork Media EZ Content Locker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up t… wordfence
9638fb3b-e1dd-4917-8770-62b1598b85be
< 0.4.7.5
MEDIUM 6.1 The Media Downloader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
96320410-48e2-42a6-9a1e-1641c1229256
< 2022.0123
MEDIUM 6.1 The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" … wordfence
962c0440-04d7-4201-829c-dad9b8f796d5 MEDIUM 6.1 The Integration of Moneybird for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the er… wordfence
96265dd0-ed3d-4557-80e9-41f8b943b2a7
< 5.4.9
MEDIUM 6.1 The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_notice parameter before o… wordfence
9623e815-a107-4f9f-90b2-ec8b1cc87ddc
< 2.6.17
MEDIUM 6.1 The WP-Lister Lite for Amazon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
961cf553-8871-436d-af95-61af963f5e9d
< 4.9.21
MEDIUM 6.1 The SAML Single Sign On – SAML SSO Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to t… wordfence
96154542-b600-471a-a539-319352a3fe18 MEDIUM 6.1 The Code Generate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
← Prev 867 868 869 870 871 872 873 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top