πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 875 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
915f6423-18de-415b-ab89-baaa805203ae MEDIUM 6.1 The Disqus Popular Posts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
915d73ed-33ae-4580-9a51-aa4e9a015ff6
< 3.5.6
MEDIUM 6.1 The Slimstat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a URL in versions up to, an… wordfence
91534af0-74e6-438f-9f28-27ac559b2655
< 2.7.7.25
MEDIUM 6.1 The Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery plugin for WordPress is vulnerable to Reflected Cross-Si… wordfence
9145ce0d-311c-4be1-be15-7e1791c17860
< 1.3.2.4
MEDIUM 6.1 The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ip' parameter on the 'cha… wordfence
913e4f70-7f4e-4d63-a7ba-6850190bdc1f
< 2.4.4.1
MEDIUM 6.1 The JetBlog plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.4.4… wordfence
91358e40-e64f-4e8e-b5a3-7d2133db5fe9
< 2.97
MEDIUM 6.1 The Advanced Woo Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search parameter in… wordfence
9121ab04-d16b-468b-880f-8f00bcec6489
< 5.8.1
MEDIUM 6.1 The DeBounce Email Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
910e7446-2fdd-487e-a096-29c771e33213
< 10.6.6
MEDIUM 6.1 The Wp EMember plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'editrecord' parameter in al… wordfence
910cf7bd-1c2b-4e08-9088-e95ea6867ac3
< 11.5
MEDIUM 6.1 The Planaday API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all ver… wordfence
910902ab-8bd4-42b8-bd60-dce973e80ee5 MEDIUM 6.1 The WooCommerce Maintenance Mode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… wordfence
9104e7df-1a7b-491f-9b51-25467004d8ca
< 3.0.0
MEDIUM 6.1 The SEO Flow by LupsOnline plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
9102ecd8-4860-4521-be34-bfcc91408c0c
< 2.8.1
MEDIUM 6.1 The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all… wordfence
91021b7f-06d1-4403-81bd-ba082685e58e
< 0.5
MEDIUM 6.1 Open redirect vulnerability in age-verification.php in the Age Verification plugin 0.4 and earlier for WordPress allows … wordfence
90fdf5ca-f310-4e03-9662-dcaa68f90ea1 MEDIUM 6.1 The flexo-posts-manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
90f74376-07b2-4d4c-8d7b-35b92de1adf6 MEDIUM 6.1 The WP Extra Fields plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
90e7951b-3834-48a3-8a40-2b6055d1b62c
< 3.4.3
MEDIUM 6.1 The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg(). wordfence
90ce0f70-d3a2-48cb-b6f8-7dda7ac25866 MEDIUM 6.1 The Web Minimalist 200901 theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the PATH_INFO to index… wordfence
90c88379-e87f-4c32-af2b-83704cb14e29 MEDIUM 6.1 The CarZine theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4.6 … wordfence
90b97e57-a021-462c-b3d2-49cf959950dd
< 5.6.0
MEDIUM 6.1 The WPJobBoard plugin 5.5.3 for WordPress allows Persistent XSS via the Add Job form, as demonstrated by title and Descr… wordfence
90b11be6-ae6c-4155-87a2-0d106eec264a MEDIUM 6.1 The WPCRM - CRM for Contact form CF7 & WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
9083d875-ff86-4f18-ad63-368bcb269ad9
< 0.1.1
MEDIUM 6.1 Wordpress plugin Furikake version 0.1.0 is vulnerable to an Open Redirect The furikake-redirect parameter on a page allo… wordfence
9080542f-9c42-439b-b4da-b25f67f2aa97
< 1.5.4
MEDIUM 6.1 The WP Shopify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'product' parameter in all v… wordfence
905ced90-3a24-4dd6-b415-890804bb6f5b
< 115
MEDIUM 6.1 The Simple URLs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions … wordfence
9053cf91-0af1-44f8-9fdf-7ecbd457545b
< 6.4.6
MEDIUM 6.1 The Events Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all … wordfence
9040aa36-2d3b-4470-93ae-19ad16fcd929
< 7.63
MEDIUM 6.1 The All-in-One WP Migration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
← Prev 872 873 874 875 876 877 878 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top