🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 748 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
08b5f399-018c-4e0b-aefc-55463d4ac48d MEDIUM 6.4 The Sermon'e plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up… wordfence
08b378c9-32c0-4f90-9fbb-c07a24e4121d
< 1.4.3
MEDIUM 6.4 The Consulting Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
089a93a1-0868-4c1d-930a-7e6fcf0aee94
< 1.2.59
MEDIUM 6.4 The Booking Calendar Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
089406e7-4f6a-416b-9077-e17c44069300
< 2.4.6
MEDIUM 6.4 The WP Multi Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and … wordfence
088aead8-37bb-4277-81e0-b7e2c13e9072 MEDIUM 6.4 The WP FEvents Book plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions… wordfence
08891bd4-2f2a-4d9a-b6b4-d6f2043489d0 MEDIUM 6.4 The Headline Analyzer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
0881efbe-9b47-4b56-be2d-12258460b429
< 7.8
MEDIUM 6.4 The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Additional Parameters in… wordfence
08814d06-0039-49cc-bcbb-96cb01129e3c
< 9.7.4
MEDIUM 6.4 The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in … wordfence
0866f9b9-f3e5-48eb-92e0-06bdb2fd2720 MEDIUM 6.4 The Auto Upload Images plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and incl… wordfence
08640d56-fc76-4062-ab08-19415ad77e5e
< 2.3.0
MEDIUM 6.4 The Easy Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget parameter… wordfence
0841127c-fe81-47b1-964f-15e006f618af MEDIUM 6.4 The WP Awesome Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versi… wordfence
083fa428-a13f-4a3a-97e8-316a3856b281
< 1.5.6
MEDIUM 6.4 The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
0838f085-8ff7-4c6a-bd5b-af99f666377b
< 8.5.0
MEDIUM 6.4 The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG Imag… wordfence
082f810c-d55e-4190-908c-c7dd9c2e59a5
< 14.3.3
MEDIUM 6.4 The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all v… wordfence
082ebebc-22c2-49c1-b9a4-0a973de3cad7 MEDIUM 6.4 The DuoGeek Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 0.1.1 due to insu… wordfence
08220b23-d6fa-4005-bbbb-019412d328a5
< 1.4
MEDIUM 6.4 The Tab Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all ve… wordfence
08208cb1-2d57-49f9-8ac7-b59caa0cf5fa
< 3.10.4
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘archive_titl… wordfence
081c6629-6c4d-4336-b93e-3c4817ca8d77
< 4.10.4
MEDIUM 6.4 The Videopack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.10.3… wordfence
08186560-16f5-4b53-985f-d708895c79c1 MEDIUM 6.4 The Easy EU Cookie law plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
08159865-1411-4a07-b5db-f4ba5bf2d633
< 1.0.277
MEDIUM 6.4 The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s)… wordfence
07f97b57-4258-4bd0-88f0-851e87dfd061
< 4.0.2
MEDIUM 6.4 A vulnerability classified as problematic has been found in BestWebSoft Contact Form Plugin 4.0.0. This affects an unkno… wordfence
07f8d3c3-0f1b-4d55-b85b-e41fdea1fb7b
< 3.4.1
MEDIUM 6.4 The Academy LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.… wordfence
07e7f03e-0d5d-4405-a0e7-9547fc762f0e
< 1.4.3
MEDIUM 6.4 The 130+ Widgets | Best Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
07e415f9-42f1-4c80-a023-38f460f634d3 MEDIUM 6.4 The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [zemstl] shortcode in all versions… wordfence
07c26175-51fa-4050-b048-fb4bf8fb5ae1
< 2.1.3
MEDIUM 6.4 The PropertyHive plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1… wordfence
← Prev 745 746 747 748 749 750 751 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top