πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1454 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8ad5db8f-c3c2-4b76-abc6-3d95e0567ab0
< 2.2
MEDIUM 4.3 The Category Specific RSS feed Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… wordfence
8ad03d04-a93a-4be0-b18a-00bf37b70950
< 6.0.5
MEDIUM 4.3 The Jock On Air Now (JOAN) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
8accf552-f235-46dd-857b-330eef7765a0
< 3.4
MEDIUM 4.3 The SKT Addons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inclu… wordfence
8ab8eb9d-1427-4e99-8986-179147e0862e
< 3.5.4
MEDIUM 4.3 The ElasticPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.… wordfence
8ab0cad4-1a82-4127-bedb-c0ddfce4ec10
< 6.3.11
MEDIUM 4.3 The Business Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
8aa467ad-9744-4594-91b6-02df0970aa60
< 2.7.31
MEDIUM 4.3 The Unyson plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.30… wordfence
8aa2ba7f-c33d-4e80-b1cf-2d7b2a497f04
< 1.2.5
MEDIUM 4.3 The Magical Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… wordfence
8a9b2ec2-edbe-45c5-bd36-45a6101356d1 MEDIUM 4.3 The bbPress Toolkit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
8a94aac9-e31e-45ed-b126-469c83f4d74b
< 0.0.10
MEDIUM 4.3 The Cookie Consent – GDPR & CCPA Cookie Banner & Consent Manager plugin for WordPress is vulnerable to unauthorized ac… wordfence
8a90de6e-6bd5-43b6-980d-84d25d4120ad
< 4.2.7
MEDIUM 4.3 The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vu… wordfence
8a8d1b0c-8699-4d52-b848-2826cb1ce8a3
< 1.1.7
MEDIUM 4.3 The Virusdie – One-click website security plugin for WordPress is vulnerable to unauthorized access due to a missing c… wordfence
8a8ac15a-9f9b-4bb8-81a4-1fdd11670a07
< 6.1.0.0
MEDIUM 4.3 The Community by PeepSo plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
8a643fa1-afdb-4710-ba1c-3b226b4098bd
< 2.6.92
MEDIUM 4.3 The Smart Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
8a63a9b3-c056-45f3-952c-9aee997d1d27
< 3.14.4
MEDIUM 4.3 The SmartCrawl SEO checker, analyzer & optimizer plugin for WordPress is vulnerable to unauthorized modification of data… wordfence
8a43ec32-ed48-4590-8fef-c4f460ffcabc MEDIUM 4.3 The DeMomentSomTres WordPress Export Posts With Images plugin for WordPress is vulnerable to unauthorized access of data… wordfence
8a3138b3-9a20-43f6-9697-4c0e524b4964
< 1.15
MEDIUM 4.3 The Manual Image Crop plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to 1.15.… wordfence
8a276a3e-12c3-4af7-9eb8-a25d20563de7 MEDIUM 4.3 The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and in… wordfence
8a27253d-bfc1-40b5-9da4-d16cc403ad41
< 3.4
MEDIUM 4.3 The Taggbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3. This… wordfence
8a2542e9-d50d-4254-8163-205240a5efdb MEDIUM 4.3 The Zara 4 Image Compression plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
8a07d293-4c50-4be0-955f-b7c4a0eaef4b
< 2.1.11
MEDIUM 4.3 Multiple plugins for WordPress by tychesoftwares are vulnerable to unauthorized modification of data due to a missing ca… wordfence
8a071801-be75-4cd8-8610-576a170a41a4 MEDIUM 4.3 The QS Dark Mode Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
89dd21b1-35f4-45f1-a9b0-f64434220a94
< 3.6.12
MEDIUM 4.3 The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
89dc1740-0050-4793-847b-9aa44cc12822
< 3.0.17
MEDIUM 4.3 The CrawlWP SEO – Instant Search Engine Indexing & SEO Performance Monitor plugin for WordPress is vulnerable to Cross… wordfence
89dbf14f-1cc8-4a66-b3d3-3568cba9a0aa MEDIUM 4.3 The Live Preview for Contact Form 7 plugin for WordPress is vulnerable to unauthorized plugin option update due to a mis… wordfence
89d42a87-6adc-43e6-868f-b9b2c51ed8e0
< 1.1.6
MEDIUM 4.3 The Feather Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
← Prev 1451 1452 1453 1454 1455 1456 1457 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top