πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1306 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8a8fc6a5-a28a-4d6b-8d63-c5e2f4d26422
< 6.7.14
MEDIUM 4.4 The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
8a19b102-e097-46b3-9804-71edb91b3daa MEDIUM 4.4 The SEO ALert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, an… wordfence
8a143d0f-0f51-4105-b7b4-d8337432c890
< 4.7.6
MEDIUM 4.4 The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7.5 d… wordfence
89fc8407-3d1f-4b1b-9b4c-13c0da928231 MEDIUM 4.4 The PB SEO Friendly Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings i… wordfence
89f6fa65-ef71-491e-8959-591b58d1444c
< 3.8.8.1
MEDIUM 4.4 The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term… wordfence
89de2cb3-c089-49eb-8bb2-cfa11d66fa18 MEDIUM 4.4 The Floating Social Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
89899ead-eebc-4fcd-a9b2-12d3ac2beedd
< 1.0.4
MEDIUM 4.4 The Dialogity Free Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
89321887-0116-47fb-b65b-008c9fb01b62
< 1.2
MEDIUM 4.4 The WSB Brands plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $logo variable in versions up t… wordfence
892fe839-57ca-45bc-aa9b-f1bf87994a77
< 1.1.9
MEDIUM 4.4 The Sticky Chat Widget: WhatsApp, Messenger, Click to chat, SMS, Email, Messages, Call Button, Contact form and more Cha… wordfence
892cb187-95b6-4df7-a0dc-4db6d8cee902 MEDIUM 4.4 The Better WP Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
8921ea7f-5e27-4f05-b338-1c16366a8c8e
< 1.15.24
MEDIUM 4.4 The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers… wordfence
8915116c-5355-4497-a688-ca7327108945 MEDIUM 4.4 The Global Translator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
890c743e-da5e-46ed-a011-cecd24778163
< 1.18.2
MEDIUM 4.4 The Custom Post Type UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'label' parameter duri… wordfence
89058e5a-0f67-4162-ba3b-0a4353d1e0a9
< 1.3.9
MEDIUM 4.4 The Podlove Subscribe button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ver… wordfence
88f9f4db-b15b-43d4-918a-a4c83e5735d1
< 1.7.7
MEDIUM 4.4 The Video Gallery – YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
88f90762-2d2b-4a31-ac8d-324eab702727
< 1.3.0.5
MEDIUM 4.4 The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions … wordfence
88e2db46-3781-4872-9b8f-73661b7003ed MEDIUM 4.4 The Greenhouse Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
88dec08d-cb27-4ea8-853e-0c12dd0a6ab6 MEDIUM 4.4 The Makesweat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'makesweat_clubid' setting in al… wordfence
88cf21c3-52d7-472f-8f55-8e1a5819f133
< 0.6.3
MEDIUM 4.4 The Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content plugin for WordPress … wordfence
88cea535-1042-4011-aee9-684d7661e193
< 2.1.0
MEDIUM 4.4 The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin … wordfence
889986f8-224e-4af4-a1d2-ef4b04a7e83f
< 2.2.13
MEDIUM 4.4 The Product Enquiry for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings… wordfence
88855d83-d182-4b10-b44f-cd0edec07db1
< 2.0
MEDIUM 4.4 The WP Change Email Sender plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.0 due t… wordfence
887a1697-608e-4bf8-8c15-188737cb22c6
< 3.1.1
MEDIUM 4.4 The TS Webfonts for SAKURA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versi… wordfence
8876ecc4-1a50-43ac-9c8d-354f6de4abdd MEDIUM 4.4 The Motor Racing League plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions… wordfence
886c4ce5-275c-49aa-86eb-b11c3c22ad79 MEDIUM 4.4 The Block Spam By Math Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
← Prev 1303 1304 1305 1306 1307 1308 1309 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top