πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1074 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
90e420be-fe6e-4a35-9c06-f0d360c9f9bf
< 1.4.64
MEDIUM 5.4 The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
9060bb2a-b9d9-466d-bb8d-14173a51d145
< 2023.03.17
MEDIUM 5.4 The Daily Prayer Time plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
8fd93c96-36e9-4e9b-a7ef-b4dc6b7221a8
< 4.24.8
MEDIUM 5.4 The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
8f8bd107-5459-4093-8593-deedec6ffcd6 MEDIUM 5.4 The Universal Slider plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.… wordfence
8f7626b3-86b5-4aa2-871b-07f84a43c47f
< 4.5.1
MEDIUM 5.4 The GEO my WordPress plugin for WordPress is vulnerable to unauthorized access to data due to a missing capability check… wordfence
8f6c20cb-b3a9-41d3-bccf-5b834424a59a MEDIUM 5.4 The Amazon JS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in version… wordfence
8f03b4ef-e877-430e-a440-3af0feca818c
< 4.3.1
MEDIUM 5.4 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized view and modi… wordfence
8eba82b9-20cd-4bf1-85bc-2daea4423ee8
< 1.2.3
MEDIUM 5.4 The WP Map Block WordPress plugin before 1.2.3 does not escape some attributes of the WP Map Block, which could allow us… wordfence
8ea4617a-6211-4f8d-ab51-10ca509aaacf
< 3.4.0
MEDIUM 5.4 The Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation o… wordfence
8e4ad8fa-b04c-4821-aadb-3120f824557f
< 7.6.1
MEDIUM 5.4 The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … wordfence
8e2a994f-7a42-4ccb-8fa0-77107ba1150c MEDIUM 5.4 The The Shortcode Ajax plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and in… wordfence
8e11fcc5-c9af-43e7-8c1d-803124e04e63
< 2.9
MEDIUM 5.4 The Very Simple Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode… wordfence
8de3d3c7-bde2-4455-8d60-20307f0a53ee
< 1.0.13
MEDIUM 5.4 The JetWidgets for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
8dc16ba4-3c2e-43e2-82a0-b742276b9640
< 3.9.0
MEDIUM 5.4 The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object … wordfence
8da42003-f2d8-4837-84b2-e0e7171fa3fe MEDIUM 5.4 The LeadSquared Suite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
8d6637f7-7035-4355-9c9d-193ea87c6e62 MEDIUM 5.4 The Simple Notification plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
8d4a546a-1c15-4fc5-a2ae-8640457a0c22
< 1.5.11
MEDIUM 5.4 The dynamic-widgets plugin before 1.5.11 for WordPress has XSS via the wp-admin/admin-ajax.php?action=term_tree prefix o… wordfence
8d392d0b-f286-44da-aa32-a08d0279baed
< 2.18.17
MEDIUM 5.4 The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… wordfence
8cb37019-33f6-4f72-adfc-befbfbf69e47
< 1.4.1.7
MEDIUM 5.4 The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
8bde357d-e34a-4931-a1a4-bd3ed3b72cec
< 24.0
MEDIUM 5.4 The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_p… wordfence
8bb3ee9d-084a-42f6-bf9c-e398ddde56ed MEDIUM 5.4 The Blog Designer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
8bab0acc-5a5d-4dd4-9201-199b7f5aaa69
< 2.0.6.5
MEDIUM 5.4 The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is … wordfence
8b0a47e0-5be1-418c-afdf-8bb2d784bcc9
< 5.3.6
MEDIUM 5.4 The Customer Reviews for WooCommerce plugin contains several AJAX actions that are not protected by capability or nonce … wordfence
8a7a6da3-d67c-42b3-8826-7e7fc9b938b4
< 1.2.2
MEDIUM 5.4 The WP Directory Kit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
8a345197-d8ba-47ef-a88c-c9e45ddc0319
< 2.11.20
MEDIUM 5.4 The Melhor Envio plugin for WordPress is vulnerable to authenticated settings changes and Cross-Site Request Forgery in … wordfence
← Prev 1071 1072 1073 1074 1075 1076 1077 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top