🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 873 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
93928123-c90d-4bbb-b51d-33e809867b79
< 11.4.8
MEDIUM 6.1 The Smart Custom 404 Error Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER['REQUE… wordfence
937e56cc-58dc-483c-8f17-ced3b1f7a481 MEDIUM 6.1 The Wordpress Simple Shop WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the update_row parameter … wordfence
937a1474-2fe8-40dd-86c3-2d839a7b9c07
< 1.4.8
MEDIUM 6.1 The DigiTimber cPanel Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
9370c320-b3bc-4965-9cc7-b2bf3a24e251
< 1.4.0
MEDIUM 6.1 The Copyscape Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
936de04d-9b80-430b-a8b7-9755b68e2a02
< 1.92.1
MEDIUM 6.1 The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to t… wordfence
935a8d4e-5d5e-46c2-b3b2-eb550f27d535 MEDIUM 6.1 The Table of Contents Creator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
93504959-2154-4b8c-a7d1-c982bdc8d034
< 2.9.3.1
MEDIUM 6.1 The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t… wordfence
933ea8a2-3d1d-43a3-bb14-52f37576c9e5 MEDIUM 6.1 The AA Cash Calculator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘invoice’ parame… wordfence
933d8f1a-ae6e-4c49-92bc-a0b6bd3a0598
< 4.1.7
MEDIUM 6.1 An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject ma… wordfence
9331aa66-2eee-4745-b286-fa6db3bd9f37
< 1.2.6
MEDIUM 6.1 The Razorpay Payment Button Elementor Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to… wordfence
930d8c9e-4af0-49f0-adcc-246800e71284
< 1.0.2
MEDIUM 6.1 The WooFramework Branding plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in versions up … wordfence
92f667bc-c8fa-4c0d-a14d-db5227168aac
< 4.2.6
MEDIUM 6.1 The Podlove Podcast Publisher plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, … wordfence
92ea7488-f99b-4bae-8972-1e84a0a74071
< 1.4
MEDIUM 6.1 The Ultimate Classified Listings plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i… wordfence
92d6421a-b408-48b2-bf97-98087c3e329b
< 3.2.6
MEDIUM 6.1 The PORTONE 우커머스 결제 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up … wordfence
92cdb716-8e45-41ea-8805-527d20a4bcb5
< 1.1.6
MEDIUM 6.1 The WP LMS – Best WordPress LMS Plugin WordPress plugin through 1.1.5 does not properly sanitise or validate its User … wordfence
92c8ce3d-a9a1-41ba-a8f8-e4d821108a6d MEDIUM 6.1 The FAQs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.2 du… wordfence
92c5c282-9193-41b3-9c1e-cd700765f346
< 0.13.4
MEDIUM 6.1 The Global Flash Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
92c52129-7cf5-4a1b-80a1-b01140e6a72b
< 1.2.8
MEDIUM 6.1 The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Open Redirection in all versions up to, … wordfence
92c22d7e-64d5-465e-b7c2-62b6d9db4cc5 MEDIUM 6.1 The Author: Munzir plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
92bb3464-c15b-4d95-8732-9d3bd801999a MEDIUM 6.1 The More Link Modifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
92b1a47e-31e2-4cfd-a24c-460ff2f00d09
< 4.41.2
MEDIUM 6.1 The Webcam 2Way Videochat plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4… wordfence
92ae6f51-a6cb-46ce-b45b-ca4f12f5a67f
< 1.18
MEDIUM 6.1 The RokNewsPager plugin for WordPress is vulnerable to Cross-Site Scripting via the 'src' parameter in the 'thumb.php' f… wordfence
92abab9e-904a-4a62-a911-a57baa9aa4af
< 2.1.3
MEDIUM 6.1 The Constant Contact Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the … wordfence
92a9ca70-2867-433a-932e-191ed7f01945
< 1.1
MEDIUM 6.1 The CSV Import plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘alertmsg’ parameter in … wordfence
92a234cb-9807-4ee5-b727-bc3bdacd77aa
< 1.4.4
MEDIUM 6.1 The FunnelCockpit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
← Prev 870 871 872 873 874 875 876 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top