🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1010 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
08940eaf-48fb-4e40-9667-cde710738542
< 2.0.1
MEDIUM 6.1 The Multisite Content Copier/Updater plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up… wordfence
08916934-c9b8-4bc0-8b8c-991ed0b78be2 MEDIUM 6.1 The Ooorl plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter found in the 'red… wordfence
088e0d77-06bf-4420-88fb-2c6f8051ece5 MEDIUM 6.1 The Shortcode IMDB plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.… wordfence
087df130-d75f-4792-b3f9-c78ddb0f7a48
< 1.1.0
MEDIUM 6.1 The Empty Tags Remover plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
0879bfe6-0b73-4bdc-9770-f8b2a3da2686
< 3.2.11
MEDIUM 6.1 The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to Open Redire… wordfence
08746755-9abe-4120-8ffb-90f2f9f1b7cf
< 2.4.3
MEDIUM 6.1 The WP-Lister Lite for Amazon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
086ff82e-d954-4ded-af72-b3ea3523d443 MEDIUM 6.1 The CGM Event Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
085b39e4-2e38-4e9d-af1a-f8981d5c6ed5
< 1.1.1
MEDIUM 6.1 The Social Buttons Pack by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … wordfence
0856f3bf-da17-44bb-aa30-26f9fb6e22b1 MEDIUM 6.1 The Top Bar Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
0854a9d9-3da2-443b-ad2b-ef3136407be3
< 1.2.1
MEDIUM 6.1 The Billplz Addon for Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all version… wordfence
085213ea-297d-451d-8fad-69937f0dcbad MEDIUM 6.1 The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to Open Redirect in all versions up to,… wordfence
083cc89e-0352-44ff-abcb-87f3c5375a31
< 3.5.0
MEDIUM 6.1 Cross-site scripting vulnerability in Email Subscribers & Newsletters versions prior to 3.5.0 allows remote attackers to… wordfence
08396330-4fb8-4df0-b7eb-3d3b847cb9b0 MEDIUM 6.1 Cross-site request forgery (CSRF) vulnerability in the PictoBrowser (pictobrowser-gallery) plugin 0.3.1 and earlier for … wordfence
0828a4a4-2dd5-4dff-8563-c81d6b24b949
< 1.7.4
MEDIUM 6.1 The YITH Custom Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_a… wordfence
0814c64e-f786-4cc3-85ee-c8cfbebf7e2c
< 2.6.9
MEDIUM 6.1 The WP-Lister Lite for Amazon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
08137a9e-6e4d-4ca6-954e-e98a44b0c9be
< 3.4.14
MEDIUM 6.1 The Post Grid Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘argsArray['read_mor… wordfence
08033270-5547-437b-95e6-e004b78df5e4
< 3.12
MEDIUM 6.1 The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
07fa22aa-52fc-4453-8935-132bdd8800a5 MEDIUM 6.1 The root Cookie plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
07f25481-51c1-4d02-85c6-561bee587587 MEDIUM 6.1 The SimpleForm Contact Form Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the … wordfence
07ede585-c0d2-4643-9c36-7b5da5f721bd MEDIUM 6.1 The Membership Database plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
07e9ae6a-7734-40ee-9287-ae0a99b1fc31
< 4.21.83
MEDIUM 6.1 The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
07d1c715-3620-4b82-a883-57b24c8cd031
< 1.5.8
MEDIUM 6.1 The crafty-social-buttons plugin before 1.5.8 for WordPress has XSS via several parameters. wordfence
07b48c64-aa54-4b9b-b1ee-c0f065e2aaa4
< 1.3.1
MEDIUM 6.1 The JobBoardWP – Job Board Listings and Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripti… wordfence
07b1efbd-0caf-412d-ac1b-ab1b27c32b8c
< 3.1.2
MEDIUM 6.1 The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field. wordfence
07aeed92-f3e9-4a25-a7e0-b364cb98f5dd
< 2.0.5
MEDIUM 6.1 The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitize and escape th… wordfence
← Prev 1007 1008 1009 1010 1011 1012 1013 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top