🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 374 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8b430f0a-d50c-4923-8916-2c26bf5d619a
< 5.2.0
HIGH 7.2 WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto versions below 5.2 are vulnerable to C… wordfence
8b2d42ab-46c1-4c3e-b99a-1cdcade1b5bb HIGH 7.2 The Video List Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7 due to … wordfence
8b213c3b-3907-47d9-9826-379936f15078
< 2.1.7
HIGH 7.2 The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's … wordfence
8ae734d1-0cd4-4ff5-8448-828b0fb64f70 HIGH 7.2 The SMTP Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, … wordfence
8ad7c3d5-fce8-4214-a7f8-5aa2b9fe0934
< 5.8.22
HIGH 7.2 The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL st… wordfence
8acb86fa-50b4-45b3-9bf8-ef65679b85ac
< 5.2.1
HIGH 7.2 Authenticated (admin or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Herd Effects plugin … wordfence
8a303875-ad8c-40ed-a3ab-4a63080c9845
< 4.1.8
HIGH 7.2 The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a … wordfence
8a1179bc-6f8d-4223-a80b-9834adc08d3b HIGH 7.2 The ark-commenteditor plugin for WordPress is vulnerable to iFrame Injection in versions up to, and including 2.15.6 due… wordfence
8a106ebb-f3ec-4995-9717-358b91d468b4
< 4.16.4
HIGH 7.2 The GiveWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.16.3 du… wordfence
89fe030b-253f-4fbc-b593-fb92fb7eb323
< 5.0.1
HIGH 7.2 The Autopay / Blue Media for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
89e2962a-b884-4577-a29b-92087e10ce58 HIGH 7.2 The Synergy Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
89655e84-acb5-40f2-a22f-a483a1bb29df
< 7.9.7
HIGH 7.2 The NEX-Forms plugin for WordPress is vulnerable to SQL Injection via the ‘form_id’ parameter in versions up to, and… wordfence
88fe46bf-8e85-4550-92ad-bdd426e5a745
< 2.9
HIGH 7.2 The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' paramet… wordfence
88b0e98b-3416-40d1-9901-6ab0dfb7dea1
< 3.26.7
HIGH 7.2 The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
884b97b7-d023-4752-81b1-086ab022f85e
< 4.8.0
HIGH 7.2 The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parame… wordfence
8848a247-52a6-48de-9ad5-deef89c2c599 HIGH 7.2 The Wow Forms WordPress plugin through 3.1.3 does not sanitise or escape a 'did' GET parameter before using it in a SQL … wordfence
87f7b9c3-f3aa-4ace-ab67-c32fa92fcffe
< 5.0.0
HIGH 7.2 The Dynamic Pricing With Discount Rules for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
87e408c4-55da-4765-8ca6-e709b9045c8b HIGH 7.2 The fs-shopping-cart plugin 2.07.02 for WordPress has SQL injection via the pid parameter. wordfence
879df622-ca6a-45ea-b8f9-e3882d4bfff7
< 1.6.12.11
HIGH 7.2 The Simply Schedule Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
87950d16-dba6-4759-b15f-57c495cdda67
< 1.18.4
HIGH 7.2 The GlobalPayments Gateway Provider for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in… wordfence
874130f0-7dc9-49fe-a7b0-e0be432799bd
< 3.2.9
HIGH 7.2 The Google XML Sitemaps Generator plugin for WordPress is vulnerable to PHP Code Injection in versions before 3.2.9 via … wordfence
8727f4fa-b6a9-4da7-b2a5-5d74ddcc082f
< 2.12.3
HIGH 7.2 The WP Debugging plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1… wordfence
87178c7c-343b-487a-9adb-7ff13aae81df
< 3.1.51
HIGH 7.2 The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerabl… wordfence
870bf5fe-00c6-48fe-b9e6-e8233c689b71 HIGH 7.2 The Gerador de Certificados – DevApps plugin for WordPress is vulnerable to arbitrary file uploads due to missing file… wordfence
870ae326-a7c9-4201-bf0d-0fbda663a694
< 1.3.73
HIGH 7.2 The Appointment Hour Booking plugin for WordPress is vulnerable to iFrame Injection via the ‘email’ or general field… wordfence
← Prev 371 372 373 374 375 376 377 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top