🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 876 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
903abd7f-6bee-4d96-96c2-f09abbb2eefe
< 3.17.1
MEDIUM 6.1 The Amazon Affiliate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in… wordfence
90331fdc-6a44-4a35-941f-dd5717a7632b
< 1.5.5
MEDIUM 6.1 The Pretty Url plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… wordfence
9032d416-28d1-4fdc-ac95-ba807df165a2
< 1.0.0
MEDIUM 6.1 The Visitors plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.9 … wordfence
902ec583-c072-4c6d-8250-ad08d7ecf239
< 1.0.7
MEDIUM 6.1 The Ai Image Alt Text Generator for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pag… wordfence
9022b4d9-f076-41b1-8fdf-2752199aeca3 MEDIUM 6.1 The Wptobe-signinup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
90220c8d-8efc-48a2-955c-3155598f5f19
< 1.11.7
MEDIUM 6.1 The Post Status Notifier Lite and Premium plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the … wordfence
900e45fc-3544-4c04-9940-a07e69795816
< 1.4.4
MEDIUM 6.1 The SimpleCharm theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… wordfence
8ff18222-5796-432e-a810-d01fd5fbec4e
< 2.0.14
MEDIUM 6.1 The PlusCaptcha Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in al… wordfence
8fefda27-aa3c-4fdf-beea-aaf0cdaaeb77
< 2.4.3.1
MEDIUM 6.1 The Permalink Manager Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
8febf4ba-ad0f-4f93-8c13-f976d583e689 MEDIUM 6.1 The SMS OVH WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the position parameter found in the ~/s… wordfence
8fea93d2-c1a5-416d-90d4-92304d8dc41f MEDIUM 6.1 The 1 Flash Gallery plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.9.0 d… wordfence
8fd13b18-63e6-4af2-a224-d87ad3a70dba
< 2.2.12
MEDIUM 6.1 The redirection plugin before 2.2.12 for WordPress has XSS, a different issue than CVE-2011-4562. wordfence
8fcfd8c1-89b3-49f1-90dc-5eac1f9dbae5
< 1.4.5
MEDIUM 6.1 The OxyExtras plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.4.4 due to … wordfence
8fbcd728-d2a2-4787-841d-0ce77356f737
< 4.6.2
MEDIUM 6.1 The Albo Pretorio Online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Ente' parameter in v… wordfence
8faecb99-df49-40b5-a5cb-7a8a21cb512c
< 3.1.7
MEDIUM 6.1 The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages. wordfence
8fab1e59-5123-4ccb-bc0c-b8908643af89 MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the WP RESTful plugin 0.1 and earlier for WordPress allow remote … wordfence
8f890790-c5ca-4812-9566-6c945d8f39b5 MEDIUM 6.1 The Review Ratings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
8f854737-e87b-4c50-a9fb-d3b129f9d9fc
< 0.9.93
MEDIUM 6.1 The GDY Modular Content plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query… wordfence
8f7edb22-1441-4cac-9899-cd27dc313870
< 1.0.4
MEDIUM 6.1 The Taxonomy Switcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_a… wordfence
8f715947-e379-4a05-9ab8-5d9e94ffc136 MEDIUM 6.1 The BBS e-Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2… wordfence
8f70c96c-5146-41d8-9d9c-7f2adb336049
< 0.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the News theme before 0.2 for WordPress allows remote attackers to inject ar… wordfence
8f6e7756-d8cc-4380-a93e-47d7916a5f7b MEDIUM 6.1 The Twitscription plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO in al… wordfence
8f68c70b-9fde-43a6-8a7c-00938aa0e109 MEDIUM 6.1 The WooCommerce Product Categories Selection Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
8f5d0539-4cd5-469c-8dd5-fd528aa519b7 MEDIUM 6.1 The GoQSmile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.… wordfence
8f52fd57-abfe-48c4-a950-66d72a5a9627
< 1.11.5
MEDIUM 6.1 The Tracking Code Manager for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tcmp_action’ parame… wordfence
← Prev 873 874 875 876 877 878 879 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top