ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 604 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8e143386-4ff7-4d2d-9cea-642cee198d55
< 1.13.19
MEDIUM 6.4 The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.13.… wordfence
8e014aa5-4fdf-458b-a975-e3ced7186dc2 MEDIUM 6.4 The Cookielay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cookielay shortcode in … wordfence
8df03b7f-58c0-4a84-9f96-7ae7596e5b77 MEDIUM 6.4 The Blox Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.8 … wordfence
8defdd2e-e191-498e-826a-b73c6b4f2f57
< 1.4
MEDIUM 6.4 The Hero Banner Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting possibly via unspecified shor… wordfence
8dc991ea-0d00-4734-9b9a-5af759e83540 MEDIUM 6.4 The Nearby Now Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_tech' parameter o… wordfence
8dbe4104-b7d1-484f-a843-a3d1fc02999d
< 5.8.16
MEDIUM 6.4 The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael… wordfence
8daa0321-e8cc-416d-ad0e-173e316caf83 MEDIUM 6.4 The Voyage Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the 'post… wordfence
8d9fe6b4-8696-45eb-bdb8-764dea7cce88
< 6.2.1
MEDIUM 6.4 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
8d9f75e0-1be8-4372-92c5-1f146b08a770
< 1.12.57
MEDIUM 6.4 The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.12.20… wordfence
8d9bba8c-0e75-4170-a006-16fa4bd0d0ed
< 1.2.89
MEDIUM 6.4 The PDF Builder for WPForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' variable in … wordfence
8d97a1d3-0f78-4fc2-80ea-8dd600451326
< 7.8.1
MEDIUM 6.4 The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.8… wordfence
8d966924-aeab-4397-9555-78291af70efe
< 2.94.2
MEDIUM 6.4 The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map b… wordfence
8d945c4b-3eb1-4bab-b355-117b7fd06553
< 3.6.1
MEDIUM 6.4 The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
8d7b6ae4-8cf7-4576-ad17-f05f01490e74 MEDIUM 6.4 The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
8d5d554c-f155-4609-afe0-98f331940b65
< 1.3.1
MEDIUM 6.4 The Himalayas theme for WordPress is vulnerable to Stored Cross-Site Scripting via author display names in all versions … wordfence
8d52779e-3c86-4823-af0e-6f8d55d35e90
< 4.0.1
MEDIUM 6.4 The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the pa… wordfence
8d4f018c-483b-4435-a8b1-f18e5f843507
< 3.3.8
MEDIUM 6.4 The GS Logo Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in vers… wordfence
8d4d948e-359e-4514-9c8f-dbd8198ef4fe
< 1.3.4.1
MEDIUM 6.4 The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl… wordfence
8d45640a-859a-488c-b134-3c260d3d3078
< 5.10.5.1
MEDIUM 6.4 The TheGem theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.10.5 due… wordfence
8d44dcef-6330-4ef6-8385-923e88db669f
< 2.7.1
MEDIUM 6.4 The YITH WooCommerce Quick View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yith_… wordfence
8d434250-aa16-4ba1-a1f8-289371176545
< 1.4.15
MEDIUM 6.4 The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '… wordfence
8d182c47-3840-4ab7-a4b8-cfaf02586a5b
< 3.8
MEDIUM 6.4 The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in a… wordfence
8d0e8494-13d9-4d5d-98e7-e3ba5ee358aa MEDIUM 6.4 The Extensions for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
8d07dcb9-ec8c-4f38-b5c2-2f4020a1c610 MEDIUM 6.4 The GoToWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions u… wordfence
8d024ad7-6932-4c84-ae2e-493a1cebbbee
< 1.1.0
MEDIUM 6.4 The HT Mega – Absolute Addons for WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
← Prev 601 602 603 604 605 606 607 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top