πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 453 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8f394209-df80-491f-b700-cc06e54ea676 MEDIUM 6.5 The Hero Maps Premium plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in all versions up to… wordfence
8ef64d17-fc52-4d47-aca3-e136245bc114
< 1.1.4
MEDIUM 6.5 The YourMembership Single Sign On plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
8ebfc52b-278c-49d5-9226-d28a59335d46
< 2.3.13
MEDIUM 6.5 The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the w… wordfence
8e98d92a-fe64-4591-972b-ed11542506b7 MEDIUM 6.5 The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to Sensitive In… wordfence
8e4c42e6-92f3-4c2f-8748-877c6df39e62 MEDIUM 6.5 The Woo superb slideshow transition gallery with random effect plugin for WordPress is vulnerable to SQL Injection via t… wordfence
8e175383-be6c-441b-a29a-02277c599ebb
< 1.5.5
MEDIUM 6.5 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to SQL Injection in version… wordfence
8ddbfa41-94c3-4aca-a3ec-f46b4b248f66
< 3.12.14.1
MEDIUM 6.5 The The Easy Appointments plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and… wordfence
8dcf5685-94b8-432c-8073-e1fb1a2ca29b MEDIUM 6.5 The Wr Age Verification plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.0 … wordfence
8d6b0d86-3cb4-4723-b677-141c604f00cc
< 11.59
MEDIUM 6.5 The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to… wordfence
8ceb4750-0780-4437-a3b0-c4c4606f2715 MEDIUM 6.5 The Pre* Party Resource Hints plugin for WordPress is vulnerable to SQL Injection via the 'hint_ids' parameter of the pp… wordfence
8ce4be1b-3807-4ded-80a5-30f2f80db89d
< 5.0.8
MEDIUM 6.5 The All In One WP Security & Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions 5.0.0 - 5.0.… wordfence
8cd8ffcb-0a24-4e0a-a9f9-23501742715f
< 2.4.2
MEDIUM 6.5 The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the '… wordfence
8cd603aa-c4d4-488c-b134-6983240c3a18
< 4.0.1
MEDIUM 6.5 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via S… wordfence
8c965f4c-5fb6-4992-b004-f85eed3a70a6
< 5.4.12
MEDIUM 6.5 The SlimStat Analytics plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.4.11 due … wordfence
8c6c2695-6244-43fa-8920-7dba14668659
< 0.9.76
MEDIUM 6.5 The WPvivid backup plugin for WordPress is vulnerable to arbitrary file read due to missing parameter sanitization and … wordfence
8bb172cc-b7a6-401d-a246-1918702d654d
< 4.1.12
MEDIUM 6.5 The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to SQL Injection via… wordfence
8b9e69f0-7b21-4cc5-924c-1556764cbb0d
< 5.2.5
MEDIUM 6.5 The Ninja Tables plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.2.4 due to insu… wordfence
8b8e3cb9-00b3-4500-adf0-c8a9fbf9d546
< 4.0.2
MEDIUM 6.5 The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, a… wordfence
8b8c85f2-11c7-491f-9b91-0ddf4814e40d
< 3.4.2
MEDIUM 6.5 The The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnera… wordfence
8b4ddcc5-a046-494e-a79f-c4c41969481e
< 1.1.6
MEDIUM 6.5 The Frontis Blocks β€” Block Library for the Block Editor plugin for WordPress is vulnerable to Server-Side Request Forg… wordfence
8b019499-8edf-4921-9612-12d39c2e8e85
< 1.6.11
MEDIUM 6.5 The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user maki… wordfence
8ad642df-1a3f-4eb2-a64c-431b32ef5aef MEDIUM 6.5 The Contact Us page - Contact people LITE plugin for WordPress is vulnerable to SQL Injection in versions up to, and inc… wordfence
8aa19b3a-229e-460d-b592-c0a2c7fd5c06
< 1.0.8
MEDIUM 6.5 The Transposh WordPress Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tk0' para… wordfence
8a8eeae9-572c-420a-be7d-a240c54e96ae
< 1.3.0
MEDIUM 6.5 The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File Read in all versions up … wordfence
8a756804-4f39-46ce-8a0e-c5632f78686d
< 4.6
MEDIUM 6.5 The SERPed.net plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.4 due to insuffic… wordfence
← Prev 450 451 452 453 454 455 456 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top