🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 880 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8bec327f-433f-4bc6-ae50-ed4d12fef81c
< 1.2.6
MEDIUM 6.1 The EZPZ SAML SP Single Sign On (SSO) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… wordfence
8bde77fe-b3e1-44c1-a0da-964a0cc983a5 MEDIUM 6.1 The Contact Form 7 Editor Button plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,… wordfence
8bd77afe-585d-445e-adfd-48c5e0c4dca9
< 7.7
MEDIUM 6.1 The Super Store Finder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
8bcd44c3-75e6-453f-a9e7-3a547eba55e1
< 1.113.0
MEDIUM 6.1 The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is v… wordfence
8bbcbefa-f38d-4752-acca-3545976cc59f
< 3.8.2.3
MEDIUM 6.1 The Pie Register plugin for WordPress is vulnerable to Open Redirect via the 'redirect_to' parameter in versions up to, … wordfence
8bbc6aa7-0625-4689-8afe-d7399009ee53 MEDIUM 6.1 The Recent Posts Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in versions up to… wordfence
8ba90d0f-5ef9-4931-85a9-edf08275510f
< 2.69.0
MEDIUM 6.1 The WP-EMail WordPress plugin before 2.69.0 does not protect its log deletion functionality with nonce checks, allowing … wordfence
8b968849-32ef-4cc9-8ac6-5477b2906952
< 4.3.1
MEDIUM 6.1 The SULly plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.3… wordfence
8b93655b-9a26-4515-8ae2-105271aba9c4
< 6.4.0.1
MEDIUM 6.1 The The Events Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view_data' paramet… wordfence
8b8d21cb-fe87-4947-a44b-7d670cf2123e
< 1.2.6
MEDIUM 6.1 The CM FAQ – Simplify support with an intuitive FAQ management tool plugin for WordPress is vulnerable to Reflected C… wordfence
8b85b1e3-4eb0-4ba1-8d61-ec82fac123ce
< 1.9.7
MEDIUM 6.1 The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[selector_wp_list_pages][show_selector] parameter… wordfence
8b7d7373-e38a-428c-be8c-a5b05e8dc1e9 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in includes/refreshDate.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel… wordfence
8b7ab27f-566f-46f4-9c8e-aedfa3410dec MEDIUM 6.1 The SocialGrid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘default_services’ param… wordfence
8b79fa47-f045-44e9-84b8-60aa3a302dac
< 2.0
MEDIUM 6.1 The filedownload plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.4 due to… wordfence
8b77eff6-52a0-4f51-9b14-a58dec454466
< 6.2
MEDIUM 6.1 The FlatNews theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.8 d… wordfence
8b707d85-ba12-4f54-bd86-6f11d47515e0 MEDIUM 6.1 The WP Panoramio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
8b602f33-ae2f-4349-a8be-901a9eec91c3
< 2.9.94
MEDIUM 6.1 The WordPress Download Manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonst… wordfence
8b56dcd7-f261-42db-833d-5673c8805bb4
< 5.1.5
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.5 for WordPress allows remote attac… wordfence
8b56ca04-c6eb-401f-aa8a-b933c0527e51
< 2.3.2
MEDIUM 6.1 The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' and 'c… wordfence
8b510ffb-27fe-41f2-8176-676cf9540ee8
< 2.0.1
MEDIUM 6.1 The Bank Mellat Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘orderId’ parameter in … wordfence
8b4cf195-d476-4acf-bfb0-df6d971e6c7b MEDIUM 6.1 The Prayer Times Anywhere plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
8b4568dc-afcd-4172-b39a-0d06dfa2f87a
< 3.5.19
MEDIUM 6.1 Cross Site Scripting (XSS) exists in the wp-noexternallinks plugin before 3.5.19 for WordPress via the date1 or date2 pa… wordfence
8b1f0741-1ccc-497a-b239-3cefb1204f04
< 2.9.1
MEDIUM 6.1 The peters-login-redirect plugin before 2.9.1 for WordPress has XSS during the editing of redirect URLs. wordfence
8b12777d-36ab-4ced-9050-b2ce11b23625 MEDIUM 6.1 The Arrow Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
8b0df7f4-d916-414a-8d03-941aab06a001 MEDIUM 6.1 The postman-smtp plugin through 1.7.2 for WordPress has XSS via the wp-admin/tools.php?page=postman_email_log 'page' par… wordfence
← Prev 877 878 879 880 881 882 883 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top