πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 872 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
94b289bf-0ef1-47d1-98bd-8f7bb753c2bc
< 1.6.8.2
MEDIUM 6.1 The Advanced AJAX Product Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' p… wordfence
949effee-d99c-4965-9d89-3309d4df66cd MEDIUM 6.1 Persistent XSS Vulnerability in Wordpress plugin AnyVar v0.1.1 via var_name parameter. wordfence
94953618-2beb-43f6-ab73-94e676546fa7
< 2.0.6
MEDIUM 6.1 The WP Table Builder – WordPress Table Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in … wordfence
94750424-bb52-4236-962e-aa8cbdeb1459
< 8.3.5
MEDIUM 6.1 The File Manager Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tb' parameter in all … wordfence
947286b0-347f-47ab-885a-7805b50f0be8
< 2.7.2.1
MEDIUM 6.1 The Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin for WordPre… wordfence
94712f92-5045-420b-9d6d-59a4c031e998
< 3.0.1
MEDIUM 6.1 The Google Fonts For WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
946f3b30-2f6f-41df-8944-a5da488b4278
< 2.8.1
MEDIUM 6.1 The HandL UTM Grabber / Tracker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
946d4ec2-b75f-41e2-8132-47ccfc41d91a
< 2.1.3
MEDIUM 6.1 The weMail – Email Marketing, Newsletter Builder & Email Automations for WooCommerce plugin for WordPress is vulnerabl… wordfence
946bff00-32ff-4d9b-93e1-77e6ee4cd987 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in bicm-carousel-preview.php in the BIC Media Widget plugin 1.0 and earlier for… wordfence
9469946f-f471-4c7f-b69c-a38cbc08b0ac MEDIUM 6.1 The Canalplan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
9462b048-0e01-43b0-894d-43a53f744eb9
< 4.2.1
MEDIUM 6.1 The WordPress Security Firewall, Malware Scanner, Secure Login and Backup plugin before 4.2.1 does not sanitise and esca… wordfence
94564fad-cfda-497f-a542-94f19960eb6d MEDIUM 6.1 The Woocommerce Envato Affiliates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… wordfence
9450ad3b-065b-48f1-860a-7efc86dbcd23
< 2.1.4
MEDIUM 6.1 The WP Docs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2… wordfence
9445a54c-06b9-400a-a8ae-a58f1b968196
< 2.8.25
MEDIUM 6.1 The Premium Addons PRO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
94426ff8-55e2-4c8e-86dc-aca306075f89 MEDIUM 6.1 The ShopApper: Mobile App for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versi… wordfence
94337b59-6a88-467e-b487-b7b7e4f6f7a0
< 1.6.7
MEDIUM 6.1 Open redirect vulnerability in nokia-mapsplaces.php in the Nokia Maps & Places plugin 1.6.6 for WordPress allows remote … wordfence
942aad86-787e-4c25-a98b-9b7fe64aec23
< 3.7.5
MEDIUM 6.1 The WP Latest Posts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
93f9e932-a084-4a88-a180-027054ede77d MEDIUM 6.1 The WordPress SQL Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
93df6480-9bb1-4f5d-bb39-ff1a01d739cf MEDIUM 6.1 The OPEN-BRAIN plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.… wordfence
93d78063-238d-40c0-92c9-6870d85d29f7 MEDIUM 6.1 The Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versio… wordfence
93cb6d59-6654-4ce1-b65f-0e162ae58bac
< 1.6.5
MEDIUM 6.1 The Download Monitor plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.6.4 … wordfence
93c940a5-1145-47ac-b55f-bf346719e584 MEDIUM 6.1 The Donate Extra WordPress plugin through 2.02 does not sanitise and escape a parameter before outputting it back in the… wordfence
93c1b6d2-a818-4ce5-96b7-524fac4081b2
< 1.6.7
MEDIUM 6.1 The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu… wordfence
93badb2f-bb47-4ae6-a447-d8237cc9237f
< 3.4
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the x-forms-express plugin 2.1.0 for WordPress allow remote attac… wordfence
9396c350-d72e-472b-8cbc-44edce557256
< 5.2.6.0
MEDIUM 6.1 The RegistrationMagic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
← Prev 869 870 871 872 873 874 875 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top