🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 879 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8d2a1774-1deb-42ac-bae5-7d33d39023c0
< 4.4.1
MEDIUM 6.1 The LearnPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.… wordfence
8d22b146-46c8-4b64-964e-526fe3211a7a MEDIUM 6.1 The Guten Free Options plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
8d12f90c-016e-4c5c-8da7-ba1d963a4ed9 MEDIUM 6.1 The Kentha theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.7.2 d… wordfence
8cfbad9f-61ba-4216-9078-c1e7e809899a
< 1.0.11
MEDIUM 6.1 The Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ paramet… wordfence
8cea7f17-743a-4dce-bd86-5713ff6d8520
< 3.2.3
MEDIUM 6.1 The Peter’s Custom Anti-Spam plugin for WordPress is vulnerable to Reflected Cross-Site Scripting parameter in version… wordfence
8cea16a6-fb4c-48d5-a187-b7fe1679fd35
< 2.6.9
MEDIUM 6.1 The Wallet System for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… wordfence
8ce635f1-3798-4ca2-b4cf-ea183a1e1d79 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the MDC Private Message plugin 1.0.1 for WordPress allows remote authenticat… wordfence
8ccbbdf8-58cf-41ad-b4b5-8ada3b4e822f
< 3.1.13
MEDIUM 6.1 The Crowdfunding for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… wordfence
8cbce71b-0c3c-4dbd-a83e-3f2d64f8aade MEDIUM 6.1 The WordPress Health and Server Condition – Integrated with Google Page Speed plugin for WordPress is vulnerable to Re… wordfence
8cae2842-577d-4836-9de1-c55b0167aabd MEDIUM 6.1 The WP MMenu Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
8caa3644-101c-4e08-832d-63d6f5079c69 MEDIUM 6.1 The Codescar Radio Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
8ca87868-357b-4d71-9bf9-cd3b15b2555d MEDIUM 6.1 The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cros… wordfence
8c84ffd3-e000-4d67-9789-e439e7c128e8
< 6.4.2.5
MEDIUM 6.1 The Auto Affiliate Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
8c82dc37-0b9a-48c2-a8a6-fbee6182003f
< 5.2.2
MEDIUM 6.1 The WP on AWS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST data in all versions up to… wordfence
8c68cf18-0210-452f-933e-6f1e50323b15
< 2.3.4
MEDIUM 6.1 The Popup box plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up… wordfence
8c687b5d-360f-4f25-8685-aa4a8ab9b123
< 25.05.13
MEDIUM 6.1 The Team Showcase plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 25.05.13 due to… wordfence
8c4ef5e0-668d-4814-87fe-5a4a1ae1bb7f MEDIUM 6.1 The Banner Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
8c3f1202-886a-471c-9b93-0efbf4282618
< 3.2.6
MEDIUM 6.1 The The Plus Blocks for Block Editor | Gutenberg plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… wordfence
8c3de1af-b6d4-4b14-bdca-bb67ced0778e MEDIUM 6.1 The Ultimate WP Mail plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.3.9. Th… wordfence
8c28689f-8f0a-4645-93fc-f130dfffb7b6 MEDIUM 6.1 The Bootstrap collapse plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
8c1d8c1a-3adb-4b0b-8e2a-96ee2ff94218
< 1.5.69
MEDIUM 6.1 The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'theme_id' param… wordfence
8c163c9e-5f63-4501-8c51-89ef47488b03
< 5.0.0
MEDIUM 6.1 The Product Table for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… wordfence
8c107e4c-1ba5-4c22-ad56-bd03342a3418
< 0.7.23
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Job Manager plugin 0.7.22 and earlier for WordPress allows remote attack… wordfence
8c0efb37-2510-4362-86db-e5298bea2efe
< 2.1.0
MEDIUM 6.1 The Staggs Product Configurator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in … wordfence
8bfc4713-e0f0-45ec-9ac9-e5f48ba0de97 MEDIUM 6.1 The Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
← Prev 876 877 878 879 880 881 882 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top