🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 874 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
929674a1-348e-44b6-b849-72ed5e5d39d9 MEDIUM 6.1 The Services updates for customers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up t… wordfence
928584e5-7391-4442-820e-d5d5fc288572 MEDIUM 6.1 The Blix <= 0.9.1, Blixed <= 1.0, BlixKrieg <= 2.2 themes for WordPress are vulnerable to Reflected Cross-Site Scripting… wordfence
9279ffc8-ab81-4dae-9174-49103b990d0d MEDIUM 6.1 The WP Bookmarks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
92734acf-2021-4217-8cdd-a9d269198db3
< 1.5.2
MEDIUM 6.1 The Seriously Simple Stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
9271c465-cc60-4e0f-a2e4-f0a428ca3ded MEDIUM 6.1 The TM Islamic Helper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
926341b5-345a-4906-b578-b32bfe2ee4ac
< 2.1.1
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the 2kb Amazon Affiliates Store plugin before 2.1.1 for WordPress… wordfence
926246a7-2f0d-4472-ae0a-fa3d95e5810f
< 2.9.42
MEDIUM 6.1 The Contact List – Easy Business Directory, Staff Directory and Address Book Plugin for WordPress is vulnerable to Ref… wordfence
92474cf6-2ae5-402f-8eb4-853277eac78d MEDIUM 6.1 The WP Calais Auto Tagger plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
92474491-b9fa-49f8-9256-8400af9eef95
< 2.5.1.9
MEDIUM 6.1 There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re… wordfence
9225d2ad-9045-4c96-9274-682adab3cd21
< 3.3.7
MEDIUM 6.1 The Ali2Woo Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
920ba51a-3434-4d7e-8b62-f9fb9e57b9d6
< 2.4.6
MEDIUM 6.1 The CarSpot theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 2.4.6 due to insuffici… wordfence
91fcb76f-89b5-492e-b595-b0f91bca14a4
< 1.23
MEDIUM 6.1 The WP-Cumulus plugin for WordPress is vulnerable to Cross-Site Scripting via the 'xmlpath' parameter in versions up to,… wordfence
91f7b0d3-a2d4-4689-9029-14f3463bc4fa MEDIUM 6.1 The Another Events Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
91e5c89e-85d3-4dda-8b79-e0b4d64e29f0
< 1.05
MEDIUM 6.1 The All custom fields & groups plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
91de3a32-236e-441d-b648-56cd69257c5f
< 5.11.1
MEDIUM 6.1 The WPJobBoard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.… wordfence
91da9275-0934-496e-9cf9-5f5e6eedfdff MEDIUM 6.1 The REDIRECTION PLUS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
91d21894-2728-467c-9eb1-2ba2b32fcb28 MEDIUM 6.1 The Simple Booking – Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
91abd172-e024-4272-96ee-1725af4d5488
< 2.8.1
MEDIUM 6.1 Fahad Mahmood RSS Feed Widget Plugin v2.8.0 and lower does not sanitize the value of the "t" GET parameter before echoin… wordfence
919f02ab-a336-46c9-9ce7-f94acac29145
< 3.6.5
MEDIUM 6.1 The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
919a2a4a-061e-4206-84b2-7b43b1276fa0
< 1.0.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in admin/test_mail.php in the Newsletter Manager plugin before 1.0.2 for WordPr… wordfence
9178723e-c51d-4f78-82b1-59b0c8eb0f8f
< 9.1
MEDIUM 6.1 The MagOne theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 9.0 due… wordfence
917820b1-c6a6-4afd-9009-60fc1c0a39d8 MEDIUM 6.1 The LDD Directory Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_que… wordfence
916d4f2f-769b-4902-9464-f55d8f64c9d2
< 0.7.0
MEDIUM 6.1 The Product Specifications for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … wordfence
9169af40-32da-4b38-95ee-d0c7d4e67779
< 3.0.6
MEDIUM 6.1 The IMPress for IDX Broker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘leadID’ par… wordfence
91652abf-2127-40be-bcd8-4a0679707953
< 4.0.4
MEDIUM 6.1 The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module. wordfence
← Prev 871 872 873 874 875 876 877 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top