๐Ÿ›ก๏ธ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 603 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8f4b9647-84ac-4011-a063-56740b42359e
< 1.2.23
MEDIUM 6.4 The VK Google Job Posting Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
8f444df8-a7ed-4ab0-bf68-8b18ba5e90c0
< 2.2.0
MEDIUM 6.4 The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
8f3f3591-5169-4885-95ec-c2aae888b88b MEDIUM 6.4 The Fast Video and Image Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
8f09f239-dd6e-4fc0-b656-f8c73b7e9022 MEDIUM 6.4 The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callo… wordfence
8f034716-5004-49ca-94f7-e05a1a4c30ee
< 9.2.04.003
MEDIUM 6.4 The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 9.2.04.003 d… wordfence
8ef75bb4-febf-4009-a6b4-f0b40a4fc903
< 2.2
MEDIUM 6.4 The Manager for Icomoon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's icomoon shor… wordfence
8ed90a91-e007-42a5-bbef-f186bd3875ea
< 1.6.0
MEDIUM 6.4 The Pretty Google Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(… wordfence
8ed413a9-bf1d-4564-b740-4c92ec2c2249 MEDIUM 6.4 The Chart Expert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pmzez_chart' shortcode in al… wordfence
8ec4eb8a-7b03-4392-9137-4f17622bfe54 MEDIUM 6.4 The Music Sheet Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pn_msv' short… wordfence
8ea002da-bf37-4c6d-a46e-4f0e7f8968ad
< 4.2.6.5
MEDIUM 6.4 The LearnPress โ€“ WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id va… wordfence
8e7b40e4-c80a-4317-acff-77696fd8098f MEDIUM 6.4 The Bamboo Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
8e796458-acd4-4334-af1c-29c82f0791ac
< 1.4.5
MEDIUM 6.4 The Services Section Block โ€“ Showcase Service Details in Grid or Columns plugin for WordPress is vulnerable to Stored … wordfence
8e7831c5-2262-42c9-9655-a43ef2dac54f
< 2.8.8
MEDIUM 6.4 The Ad Inserter โ€“ Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custo… wordfence
8e75d72d-d999-4755-8c90-7fb7d630ab00
< 3.2.20
MEDIUM 6.4 The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
8e721128-2e34-4717-8945-5fd25f2efd7d
< 2.3.6
MEDIUM 6.4 The Easy Liveblogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elb_liveblog' sho… wordfence
8e65e06f-f907-4f42-a454-4da63a11136d
< 3.7.0.3
MEDIUM 6.4 The Uncanny Toolkit for LearnDash plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
8e618025-f631-48af-b360-e11524e61be3 MEDIUM 6.4 The Znajdลบ Pracฤ™ z Praca.pl plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
8e5417d3-c466-4caf-9fb6-26d6e2c06fe1
< 2.4.7
MEDIUM 6.4 The HT Mega โ€“ Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
8e501b31-a7f4-4d0d-bf83-af7b6c023a6b
< 1.2.1
MEDIUM 6.4 The ์ฝ”๋“œ์— ์ƒต ์†Œ์…œํ†ก plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'msntt_add… wordfence
8e4dc6fd-4bd5-4ed1-ade0-cf2f8831fac3 MEDIUM 6.4 The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_title]' p… wordfence
8e47a612-4921-4227-be86-54711bf61c43
< 4.2.3
MEDIUM 6.4 The SureCart โ€“ Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payme… wordfence
8e461095-8dce-4502-8bbf-8c985105cf24 MEDIUM 6.4 The Tribute Testimonials โ€“ WordPress Testimonial Grid/Slider plugin for WordPress is vulnerable to Stored Cross-Site S… wordfence
8e42831f-844d-40dc-965e-80334aab333c
< 2.1.50
MEDIUM 6.4 The wpDataTables plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1… wordfence
8e24306a-b741-4840-b238-e37138425bf8
< 0.5
MEDIUM 6.4 The List categories plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'categories' shor… wordfence
8e1fb02f-b19c-42d3-8a31-6465077a1715 MEDIUM 6.4 The Links in Captions plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
← Prev 600 601 602 603 604 605 606 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top