🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 877 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8f4dc917-028c-451a-9b32-26ef2c488850
< 2.0.4
MEDIUM 6.1 The Nexter Extension plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post’ and 'post_i… wordfence
8f494ca7-3f2f-4535-92ff-1ed5c469bf45
< 2.10.3
MEDIUM 6.1 The Doneren met Mollie plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search’ paramet… wordfence
8f374eea-e6c0-4007-8855-4b1b63335775
< 3.6
MEDIUM 6.1 The LDD Directory Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to echoing $_SERVER['REQ… wordfence
8f34ecd8-ee38-4313-9c4d-fd138a93f4be MEDIUM 6.1 The FOMO Pay Chinese Payment Solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions u… wordfence
8f2d99ce-89b6-441d-b185-2c321b08b73c MEDIUM 6.1 The Image Rotator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
8f24743c-3894-40a8-9128-7d04bc2c8345 MEDIUM 6.1 The WP Post to PDF plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.3.1 du… wordfence
8f10a95c-59ff-49a2-8bbf-1b0a802b62c6 MEDIUM 6.1 Reflected XSS in wordpress plugin page-layout-builder v1.9.3 in 'layout_settings_id' parameter. wordfence
8f0ee03c-8cf6-4372-b740-722fc1283ee3 MEDIUM 6.1 The MM-email2image plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
8ef3a657-28ce-4a27-b4d8-617db8027ffc
< 3.0.9
MEDIUM 6.1 The Easy Social Icons plugin <= 3.0.8 for WordPress echoes out the raw value of `$_SERVER['PHP_SELF']` in its main file.… wordfence
8eca8a98-73df-4062-8800-34c0fdd2a6b1 MEDIUM 6.1 The User Password Reset plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
8eb77a53-4aea-46c3-8eea-a16f728dfa23
< 1.5.5
MEDIUM 6.1 The Shortcodes Finder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unsanitized nonce in v… wordfence
8eb778d0-2aa4-4d0a-9ac1-42af51c335bf
< 7.9.4
MEDIUM 6.1 The Salon booking system plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
8ea59532-e1c2-4dad-b2a8-01f401c54181 MEDIUM 6.1 The NextScripts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4… wordfence
8ea087a7-197b-4dbe-b551-8074a0ea23ba
< 2.5.1.9
MEDIUM 6.1 There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re… wordfence
8e9a872d-575c-455c-8f26-709878817ae0 MEDIUM 6.1 The Jabbernotification plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO … wordfence
8e8fe6f4-7e41-44d3-9980-b5e7f43aa849
< 1.9.0
MEDIUM 6.1 The Parcel Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all ve… wordfence
8e8e5a64-0e11-42e7-bc7b-674abbeee25f
< 2.1
MEDIUM 6.1 The DPortfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… wordfence
8e83475e-03fc-47b8-b23c-a7b16641351b
< 1.0.4
MEDIUM 6.1 The Easy Digital Downloads (EDD) PDF Invoices extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before… wordfence
8e809215-8b20-4a36-acd9-d16cf4a55bc5
< 1.5.0
MEDIUM 6.1 The Zephyr Admin Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
8e6e91c2-cb6b-4b5d-b13e-099969dca847
< 1.4.0
MEDIUM 6.1 The Heartland Management Terminal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions u… wordfence
8e59e02f-d701-476a-9fd8-2098004089ec MEDIUM 6.1 Reflected XSS in wordpress plugin pondol-carousel v1.0 via itemid parameter. wordfence
8e4dbf38-e955-4634-9a07-775ea49b0051
< 1.9
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the WP Construction Mode plugin 1.8 for WordPress allows remote attackers to… wordfence
8e332a52-071c-4725-99db-3cc10ee50230
< 3.4.2
MEDIUM 6.1 The Extensions for Leaflet Map plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple paramet… wordfence
8e227e25-3dd9-47fd-bba8-e076f7f92d56
< 5.18
MEDIUM 6.1 The Sendle Shipping plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
8e15d347-8cdb-4988-a68b-eb2f713ae69f
< 2.4.6
MEDIUM 6.1 The Boutique theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 2.4.6 due to insuffic… wordfence
← Prev 874 875 876 877 878 879 880 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top