πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 605 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8cfc0403-48cb-443e-b55f-b8692aaad180 MEDIUM 6.4 The imaGenius plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7 du… wordfence
8cfc0162-f80d-4979-9b87-df24c30e99ba
< 0.5.1
MEDIUM 6.4 The Responsive video embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's embed shor… wordfence
8cf1ac25-2e55-4e27-af01-9b5b1997f339
< 3.7.35
MEDIUM 6.4 WordPress before 5.5.2 allows stored XSS via post slugs. wordfence
8ce7aa01-7e79-4048-a84d-fcb9541d5f8b
< 3.6.1
MEDIUM 6.4 PDF.js is vulnerable to Arbitrary JavaScript Execution in versions prior to 4.2.67. This is due to a missing type check … wordfence
8cdea5f0-b3a9-492a-be00-cb63fc570464
< 2.1
MEDIUM 6.4 The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
8cc7a0f3-6a58-4e42-9341-aecf55d2ccb1 MEDIUM 6.4 The Text Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ts` shortcode in a… wordfence
8cc56ea6-96d5-4041-a21c-1e9e19636a19 MEDIUM 6.4 The Image Style Hover plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
8cb6639d-06ba-4bad-af73-d387a7e3f6b5
< 1.12.11
MEDIUM 6.4 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-wts-url' va… wordfence
8c99f70b-77a6-4bd7-99b1-ad4ec76d50c6
< 4.7.0
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
8c8e37f8-708e-41d5-a6b8-3ba587437532
< 2.1.11
MEDIUM 6.4 The Anchor Episodes Index (Spotify for Podcasters) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
8c7385c7-47de-4511-b474-7415c3977aa8
< 2.2.9
MEDIUM 6.4 The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ggpkg' shor… wordfence
8c483cf9-fb63-4c43-ad42-1404448540c2
< 3.7.32
MEDIUM 6.4 In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular… wordfence
8c27fc2c-b515-4314-908d-435a4167ee99
< 1.6.36
MEDIUM 6.4 The Elementor – Header, Footer & Blocks Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
8c176594-989c-4f3a-94c9-57e1a6ff3a69 MEDIUM 6.4 The QR Code Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
8c10e7f5-91e7-48c8-8c84-b61138ac1665
< 2.9.4
MEDIUM 6.4 The Simple Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… wordfence
8c0b64a0-c462-4c39-bf67-e2af54ac4154
< 2.1.59
MEDIUM 6.4 The Job Board Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
8bfd363d-5cf1-45f3-aa74-070d49a22718 MEDIUM 6.4 The Simple Select All Text Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
8bf73313-3612-400f-929e-958a06314a28
< 1.9
MEDIUM 6.4 The Sitekit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8 due … wordfence
8bf0e224-d8c7-4bf9-b9a3-97545da9d90c MEDIUM 6.4 The BMI Calculator Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
8bf04325-e313-4a68-89a0-b560bdef5a14
< 3.0.1
MEDIUM 6.4 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
8bebc229-9d15-439f-a8df-f68455bc5193 MEDIUM 6.4 The WS Facebook Like Box Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'ws-facebook-likeb… wordfence
8bdbd196-cb77-4042-86bb-7c67325c8c07
< 3.0.6
MEDIUM 6.4 The Collapsing Archives plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
8bd18b7a-6555-4838-821d-fcbe0be34ac4
< 1.6
MEDIUM 6.4 The WP Get The Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜url’ parameter in al… wordfence
8bcd2c5e-4969-4530-b3ab-930c5051d8f1
< 2.15.8
MEDIUM 6.4 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
8bcae8d6-6dbd-4174-85ff-0b52d8e45c84
< 2.9.0
MEDIUM 6.4 The TNC PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in al… wordfence
← Prev 602 603 604 605 606 607 608 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top