🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1036 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8e04769b-2977-48fc-8ec8-bb0b2905f89c
< 2.4.2
MEDIUM 5.5 The Broken Link Checker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inc… wordfence
8dda7b14-c341-434b-85f1-029f384c65d6
< 3.3.4
MEDIUM 5.5 The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
8dbaed2a-cc35-455c-ad7e-c7826d5b3e7f
< 2.11.0
MEDIUM 5.5 The Rock Convert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘text’ field on the setti… wordfence
8cec5695-1fe5-4349-b78d-2e4f7d3b9908
< 3.6.1
MEDIUM 5.5 A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via… wordfence
8ce350cb-78ae-4d76-99a7-8a81d342a9c8 MEDIUM 5.5 The LinkedIn Company Updates WordPress plugin through 1.5.3 does not sanitise and escape its settings, allowing high pri… wordfence
8cde404a-a419-4aa9-95d8-7f5dcde29daa MEDIUM 5.5 The Admin Menu Groups plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
8cb4a14a-8bef-4747-ac89-70891f5c44bb
< 1.1.6
MEDIUM 5.5 Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Backup Migration plugin <= 1.1… wordfence
8cac4bde-8518-48ec-8cbd-4cdf6094b831
< 2.4.2
MEDIUM 5.5 The Restaurant Menu by MotoPress WordPress plugin before 2.4.2 does not properly sanitize or escape inputs when creating… wordfence
8c755b87-68b9-4a42-bb4d-ecdb4cff6de2 MEDIUM 5.5 The WP Admin Style WordPress plugin through 0.1.2 does not sanitise and escape some of its settings, which could allow h… wordfence
8c74d5ad-30f3-4fde-b240-97318fc3c7d6
< 1.20.0
MEDIUM 5.5 The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting … wordfence
8c37cc28-fde0-45c6-b49c-d6dfb296c4a5
< 1.7.17
MEDIUM 5.5 The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fo… wordfence
8c1a7103-14be-46ce-bac3-fb88b7f51003 MEDIUM 5.5 The My Link Order plugin for WordPress is vulnerable to Cross-Site Scripting via the 'cats' & 'hdnCatID' parameters in v… wordfence
8be16fec-8961-49ad-ba2f-8bec70c33ec0
< 1.4.8
MEDIUM 5.5 The Video Slider WordPress plugin before 1.4.8 does not sanitize or escape some of its video settings, which could allow… wordfence
8b8b7ee8-4c11-4353-b664-761955d49b8c
< 1.39
MEDIUM 5.5 The Book appointment online WordPress plugin before 1.39 does not sanitise or escape Service Prices before outputting it… wordfence
8b3f0d5c-7daa-47e2-9e73-6e4f31dd7148
< 1.5.9
MEDIUM 5.5 The Borderless plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.8… wordfence
8b2b6a6b-73c2-441e-893d-ec171a659546 MEDIUM 5.5 The Anih - Creative Agency WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via admin se… wordfence
8b271f2f-d765-4d2d-bb0d-f8425ebc64ca
< 1.6.9
MEDIUM 5.5 The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters i… wordfence
8acf7327-2cdc-44ad-a04c-01cb0337d510
< 3.7.12
MEDIUM 5.5 Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow re… wordfence
8aac2717-0d1c-4c77-9dd2-b659fa2863a3
< 1.6.4
MEDIUM 5.5 The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Watermark font siz… wordfence
8a95633f-b5e1-4a92-b566-90fb05a289ce
< 4.5.0
MEDIUM 5.5 The Software License Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the License Key Prefi… wordfence
89ed1f07-a230-4478-b6d4-7f74c9dd7656
< 3.3.3
MEDIUM 5.5 Multiple cross-site scripting (XSS) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPress allo… wordfence
89ea4709-f637-4932-9dbd-8b3fccab45a8
< 4.0.1
MEDIUM 5.5 The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘input’… wordfence
89bd70b2-0b5f-4edb-890b-d291bdb8a851
< 3.2.4.3
MEDIUM 5.5 The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native ga… wordfence
89b528f7-42a7-4b6a-b3f7-3176b91e0dfe
< 2.0.4
MEDIUM 5.5 The Jeeng Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'client_id' param… wordfence
898af9aa-72c4-46a6-afc2-76dd17672fbc
< 3.6.0
MEDIUM 5.5 The Quick/Bulk Order Form for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
← Prev 1033 1034 1035 1036 1037 1038 1039 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top