πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 607 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8acb7893-85b2-404a-b3fe-b4c1a835b3eb
< 1.1.0
MEDIUM 6.4 The Lana Text to Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lana_text_to_image' an… wordfence
8ac66027-14b8-4e0a-a483-c014905ef04e
< 2.4.7
MEDIUM 6.4 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
8ac5fe69-7885-4fb7-8107-079216d6955e
< 1.6.4
MEDIUM 6.4 The Structured Content (JSON-LD) #wpsc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'… wordfence
8abed8c7-0c3f-4054-a116-82ce47d605de MEDIUM 6.4 The Searchie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sio_embed_media' shortc… wordfence
8abe897e-d9e2-49fc-abab-0c738e585a30 MEDIUM 6.4 The Aptivada for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
8aa0eada-dc6c-4cd5-9ced-f162416ec439
< 4.5.4
MEDIUM 6.4 The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
8a9cfef5-d9fc-4dbf-b3ec-d8d4da2edd2f MEDIUM 6.4 The Penci Pay Writer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
8a99f19a-7874-4f55-bbdd-db23182a0ece
< 1.5.23
MEDIUM 6.4 The Page Builder: Live Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's short… wordfence
8a8c626f-221c-4b81-a8af-7a836ec40475 MEDIUM 6.4 The Persian Nested Show/Hide Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
8a832e2b-a900-4057-96fc-1bd6899e3950
< 1.2
MEDIUM 6.4 The WPB Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the output of 'tags' adde… wordfence
8a68d036-9109-4bc0-9451-47fa2f9fa628
< 2.5.1
MEDIUM 6.4 The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.… wordfence
8a530a55-44d7-4f78-9cbd-513ef290908a
< 5.1.7
MEDIUM 6.4 wordfence
8a474b6a-9fde-4577-af84-d7a6c060ef56
< 2.0.2
MEDIUM 6.4 The Epeken All Kurir plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
8a410d51-f926-4b6a-adab-91e9fa97a4b9 MEDIUM 6.4 The WooCommerce Display Products by Tags plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
8a390a29-c8f4-49d5-98d1-8b63b3f42d5f MEDIUM 6.4 The SV Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.05 … wordfence
8a35f0bb-691f-4acf-a30d-4ddabe3b919c MEDIUM 6.4 The Sell Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sell_media_search_for… wordfence
8a2cd4d3-12d3-43bd-bde1-927b793f04a8
< 1.7
MEDIUM 6.4 The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ver… wordfence
8a297784-96cd-4135-a8f1-e50f3a0d71bd
< 1.1.10
MEDIUM 6.4 The One Click Order Re-Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… wordfence
8a20f582-10e7-4530-8d3c-9bc1e844badd
< 2.24
MEDIUM 6.4 The GiveWP for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, an… wordfence
8a11e702-34d2-49ee-8762-cc3614a7950a
< 3.27.5
MEDIUM 6.4 The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
8a089ebf-9c42-4e88-8e97-9a83ca4cd5f0 MEDIUM 6.4 The Ethiopian Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
89f4d353-bb6a-4520-bb3e-a0121fb4bf9b
< 4.24.0
MEDIUM 6.4 The kallyas theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in a… wordfence
89eb2229-a507-4f7c-be31-58959d3eca62
< 6.6.8
MEDIUM 6.4 The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored C… wordfence
89e3fd97-1d37-4e6f-b340-bb80373c6738
< 3.2.31
MEDIUM 6.4 The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
89e053ac-6ef9-4f5a-8aab-bdca40d68ab4 MEDIUM 6.4 The Next Date plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in… wordfence
← Prev 604 605 606 607 608 609 610 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top