🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 609 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
88d19782-492f-4306-a8c0-5eaa470e457d
< 1.12
MEDIUM 6.4 The Ticket Tailor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
88c2033d-705e-4950-b6c8-7039e365dcc0
< 1.3
MEDIUM 6.4 The Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2 du… wordfence
88bbdb6d-c824-4f31-9352-ebc0f8fd8247 MEDIUM 6.4 The WeedMaps Menu for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's weedm… wordfence
88b76986-73d4-415b-a62d-8012d0bccd66
< 3.2.2
MEDIUM 6.4 The PowerFolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.1… wordfence
88ade7a7-da31-4752-b100-40dae81735b0
< 3.1.2
MEDIUM 6.4 The Magic Embeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all … wordfence
88a3b4ad-7b8c-40ae-b81f-ccb979b49a47
< 3.7.28
MEDIUM 6.4 In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privil… wordfence
8885fc41-1b3b-4170-9752-aea7628daf4f MEDIUM 6.4 The AddFunc Mobile Detect plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
88829cca-4389-4b1a-a376-7abfbc37508e
< 3.9.5
MEDIUM 6.4 The Visualizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versio… wordfence
88809668-ea6b-41df-b2a7-ffe03a931c86 MEDIUM 6.4 The Theme Blvd Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions u… wordfence
8875d2d5-1de0-4a8c-8acb-69c8095effe5
< 3.6.26
MEDIUM 6.4 The DirectoryPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3… wordfence
8852cd88-fe13-4613-be6c-514b90b896a3 MEDIUM 6.4 The City Store theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.5 … wordfence
88520d8e-8e13-4b58-9df3-3b99afd39144
< 4.8.2
MEDIUM 6.4 The Game Review Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ paramete… wordfence
8844c230-162d-46c4-9b34-fc9d18b93f4f MEDIUM 6.4 Improper Access Control vulnerability leading to multiple Authenticated (contributor or higher user role) Stored Cross-S… wordfence
883ad6f7-e701-4708-b5d4-69b72ff38499
< 2.5.1
MEDIUM 6.4 The Woostify plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.0 T… wordfence
88391d02-66d9-4c00-a519-17f92f64a17a
< 2.3.53
MEDIUM 6.4 The PDF Flipbook, 3D Flipbook—DearFlip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via outline s… wordfence
8837e74c-677b-494d-9d7a-4bb166921bbf
< 2.4.0
MEDIUM 6.4 The Reality theme for WordPress is vulnerable to Stored Cross-Site Scripting via the property and user pages in versions… wordfence
883484dd-d48d-46f9-ae96-223626c50039 MEDIUM 6.4 The Quran Live Multilanguage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cheikh' and 'lan… wordfence
882070df-8a76-490b-a77c-03cdf84c481f MEDIUM 6.4 The WP ViewSTL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'viewstl' shortcode in… wordfence
881ec131-a716-4929-a44e-84bac161d81c
< 3.7.4
MEDIUM 6.4 The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
881b8b18-d048-4de4-a797-a5de60d7fd3e MEDIUM 6.4 The SEO Bulk Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… wordfence
880f1f3f-857c-46da-a65c-082348260f89
< 4.2.6.5
MEDIUM 6.4 The Passster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_protector shortc… wordfence
880036ab-509b-406e-a11e-d4b638d98450
< 2.3.6
MEDIUM 6.4 The Listamester plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.… wordfence
87fdadcd-b776-471a-9756-708e384de4f0
< 2.6.0
MEDIUM 6.4 The Chatroll Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'chatroll' sho… wordfence
87eb6644-fd70-42a1-b05d-b166cb89c45c MEDIUM 6.4 The Video Central plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in ver… wordfence
87e74f4f-8426-4550-8c4d-eb776f023d09
< 3.7.0
MEDIUM 6.4 The WP Travel Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
← Prev 606 607 608 609 610 611 612 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top