🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 871 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
96084352-cc53-45fc-a33f-2ebf470f81a7
< 4.51
MEDIUM 6.1 The Webcam Video Conference plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including,… wordfence
960249b2-61e7-4105-a946-e3aea8d0ab16 MEDIUM 6.1 The NS Simple Intro Loader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
95f9066c-e0dd-4909-a57b-c52070b135d1
< 1.1.5
MEDIUM 6.1 The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputt… wordfence
95ebb2ad-91a8-4a0d-ba91-f417943545b4
< 2.5.8
MEDIUM 6.1 The Campaign Monitor Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the … wordfence
95c59e71-b755-4b39-bd5f-b2b2ac99f934
< 4.2.0
MEDIUM 6.1 The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues via the 'tab' paramete… wordfence
95c2038f-c4f9-472a-92ab-59ee395bda3d
< 3.2.9
MEDIUM 6.1 The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter … wordfence
95bae3f2-313b-4b6c-a81c-8af6f169151b
< 2.4.6
MEDIUM 6.1 The Woody code snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query… wordfence
959775d4-1c03-454a-b13b-670c726fec91 MEDIUM 6.1 The WP doodlez plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1… wordfence
956f86c5-05af-41c3-a779-5b25f62122dd
< 4.9.3
MEDIUM 6.1 The Gwolle Guestbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘gwolle_gb_content’ p… wordfence
95579b81-857a-4ebb-9943-3761a2e5b3d9
< 3.2.2.0
MEDIUM 6.1 The Universal Video Player - Addon for WPBakery Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site … wordfence
953be831-d688-4ae1-b8c1-d863eded945b
< 5.9.5
MEDIUM 6.1 The Contact Form 7 plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 5.9.4. This… wordfence
95265186-ff13-464b-adb9-3cf1753487d5
< 1.2.7.6
MEDIUM 6.1 The Alpine PhotoTile for Instagram plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the client_i… wordfence
952293ff-ff17-4e35-8afb-88638265ec8d MEDIUM 6.1 The Triss - Beauty Cosmetics Shop WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting in… wordfence
94f803f4-0a06-4b77-9483-5c63f6dfd2f0
< 3.1.2
MEDIUM 6.1 The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS. wordfence
94f6b24e-2c53-45c7-a19a-c37486838183
< 3.1
MEDIUM 6.1 The Addon Jobsearch Chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
94f03821-eb33-4eb6-b7ff-b32a74facdd2
< 3.4.3
MEDIUM 6.1 The "Schedule Name" input in the Weekly Schedule WordPress plugin before 3.4.3 general options did not properly sanitize… wordfence
94e9a982-a46d-4dda-9145-e7f74cf09820
< 3.4.24
MEDIUM 6.1 The WP-Filebase plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in ver… wordfence
94e859ea-3f90-49d1-9e66-fe3ab749c872
< 1.6.0
MEDIUM 6.1 The Language Switcher for Transposh plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions… wordfence
94dd90ef-d801-4fd6-ade7-e1e7ad2e5fec
< 1.0.4
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Elegant Grunge theme before 1.0.4 for WordPress allows remote attackers … wordfence
94dc8fc6-8212-4f83-a844-f08174531d3b
< 1.0.3
MEDIUM 6.1 The Simple Login Registration plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includin… wordfence
94d522bc-9808-435d-804d-e979a6c8be66
< 1.10.9
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability exists in the Wordpress admin panel when the Broken Link Checker plugin before … wordfence
94c2dab9-40b3-4863-a5f3-fcaba10d2e20
< 5.1.10
MEDIUM 6.1 CDI – Collect and Deliver Interface for Woocommerce plugin for WordPress is vulnerable to Cross-Site Scripting via mul… wordfence
94c1e520-efd7-479f-8cfc-bc75a00a610f MEDIUM 6.1 The Universal Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
94c118a2-b0af-488f-bbb7-e2575c2c9523 MEDIUM 6.1 The AlphaOmega Captcha & Anti-Spam Filter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
94bd2229-0dfa-4f8b-9aa8-e2ee1bb7bc27 MEDIUM 6.1 The No Future Posts WordPress plugin through 1.4 does not escape its settings, which could allow high privilege users su… wordfence
← Prev 868 869 870 871 872 873 874 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top