🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1037 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8be16fec-8961-49ad-ba2f-8bec70c33ec0
< 1.4.8
MEDIUM 5.5 The Video Slider WordPress plugin before 1.4.8 does not sanitize or escape some of its video settings, which could allow… wordfence
8b8b7ee8-4c11-4353-b664-761955d49b8c
< 1.39
MEDIUM 5.5 The Book appointment online WordPress plugin before 1.39 does not sanitise or escape Service Prices before outputting it… wordfence
8b3f0d5c-7daa-47e2-9e73-6e4f31dd7148
< 1.5.9
MEDIUM 5.5 The Borderless plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.8… wordfence
8b2b6a6b-73c2-441e-893d-ec171a659546 MEDIUM 5.5 The Anih - Creative Agency WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via admin se… wordfence
8b271f2f-d765-4d2d-bb0d-f8425ebc64ca
< 1.6.9
MEDIUM 5.5 The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters i… wordfence
8acf7327-2cdc-44ad-a04c-01cb0337d510
< 3.7.12
MEDIUM 5.5 Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow re… wordfence
8aac2717-0d1c-4c77-9dd2-b659fa2863a3
< 1.6.4
MEDIUM 5.5 The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Watermark font siz… wordfence
8a95633f-b5e1-4a92-b566-90fb05a289ce
< 4.5.0
MEDIUM 5.5 The Software License Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the License Key Prefi… wordfence
89ed1f07-a230-4478-b6d4-7f74c9dd7656
< 3.3.3
MEDIUM 5.5 Multiple cross-site scripting (XSS) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPress allo… wordfence
89ea4709-f637-4932-9dbd-8b3fccab45a8
< 4.0.1
MEDIUM 5.5 The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘input’… wordfence
89bd70b2-0b5f-4edb-890b-d291bdb8a851
< 3.2.4.3
MEDIUM 5.5 The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native ga… wordfence
89b528f7-42a7-4b6a-b3f7-3176b91e0dfe
< 2.0.4
MEDIUM 5.5 The Jeeng Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'client_id' param… wordfence
898af9aa-72c4-46a6-afc2-76dd17672fbc
< 3.6.0
MEDIUM 5.5 The Quick/Bulk Order Form for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
897824d0-17cc-4322-bcd9-5e41d141bf62
< 3.0.7
MEDIUM 5.5 The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field , which c… wordfence
8962c601-2c2c-4b96-b8a4-fdc2ad8a2c08
< 9.6.5
MEDIUM 5.5 The Quick Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version… wordfence
89384b42-8c66-469d-a7d2-1c50c89cfe7e MEDIUM 5.5 The WP DS Blog Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions … wordfence
890f83dc-d8d2-4fb2-a04a-c7b70d104b49
< 1.2.0
MEDIUM 5.5 The Export Post Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘epi_random_string_file… wordfence
88f447d5-990f-4d86-93a3-fd11b63af408
< 1.7.7
MEDIUM 5.5 The Custom Product Tabs Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_wc_custom_produ… wordfence
88b38a0d-2742-48f7-8af4-f05c91a94820 MEDIUM 5.5 The WP-OGP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.5 due… wordfence
879e7695-3a61-4e65-b102-fcdc63fac688 MEDIUM 5.5 The amr users plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 4.59.4. This allows … wordfence
8741bbdf-ddd9-41f7-8d22-b9350f2cf659
< 9.1
MEDIUM 5.5 The Amministrazione Trasparente plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … wordfence
87246b00-7a61-4ab4-90f1-2ac42f5b9f1d
< 6.19.9
MEDIUM 5.5 The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for W… wordfence
86d3ff76-49be-4517-a62e-7522e26479b7 MEDIUM 5.5 The Slickr Flickr plugin for WordPress is vulnerable to Stored Cross-Site Scripting when saving its settings in versions… wordfence
8680ad0a-7513-408d-a62d-ffb0b0e7addb
< 4.1.0
MEDIUM 5.5 The Stream plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.2… wordfence
86264c7d-d1a5-4f3a-872f-b27a94d796e3
< 1.11
MEDIUM 5.5 The Mitsol Social Post Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
← Prev 1034 1035 1036 1037 1038 1039 1040 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top