🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 881 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8b0c54f2-3942-48bd-b821-b66a57fd1506
< 21.3.6
MEDIUM 6.1 The Contest Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
8b089114-b403-4e42-a578-c1f3b100978f
< 1.2.1
MEDIUM 6.1 The Cookieless Backend Server Tracking for Google Analytics – WordPress Plugin for WordPress is vulnerable to Cross-Si… wordfence
8b06d68e-153d-4cee-94d5-cbeac7468665
< 0.3.0.1
MEDIUM 6.1 The WooCommerce Easy Duplicate Product plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the wedp… wordfence
8aecdd7e-3d51-413e-b181-9b367ccf7931 MEDIUM 6.1 The WordPress 淘宝客插件 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to… wordfence
8aec2a8b-c0d7-440f-a389-1d98cef77c2e MEDIUM 6.1 The Akal theme through 2016-08-22 for WordPress has XSS via the framework/brad-shortcodes/tinymce/preview.php sc paramet… wordfence
8ae4ffe1-ecb6-4bde-8ac4-baeea82a0299 MEDIUM 6.1 The Coming Soon Chop Chop plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
8ada3f45-e9f3-46f0-810a-26545a1a54d9 MEDIUM 6.1 The WordPress Data Guard Website Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
8ad2890c-2385-414b-8630-f2c2f2199db9 MEDIUM 6.1 The Animated AL List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… wordfence
8ad239d3-c761-4c78-903d-119133fcb79b
< 6.0.0
MEDIUM 6.1 The Special Text Boxes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in ve… wordfence
8abe5885-0f04-4545-a2fe-7aa2a1dcbbe6
< 14.1.00
MEDIUM 6.1 The WooCommerce Amazon Affiliates - Wordpress Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin… wordfence
8ab2882e-60c6-4eb9-91e7-3be4fa625711
< 13.2
MEDIUM 6.1 The cforms II(2) plugin before 13.2 for WordPress has XSS in lib_ajax.php. wordfence
8a9f17e3-f1cf-44c5-a4eb-38b43b00f912
< 3.2.3
MEDIUM 6.1 The Easy Digital Downloads (EDD) Software Licensing extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x … wordfence
8a95af34-559c-4644-9941-7bd1551aba33
< 5.2.2
MEDIUM 6.1 Several plugins by Wow-Company are vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in various … wordfence
8a8edf0c-1e40-4aab-b704-b67e41214ce0
< 2.3.8
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the Mobiloud (mobiloud-mobile-app-plugin) plugin before 2.3.8 for… wordfence
8a7ff364-dd50-44d4-a8ff-f0cebe392bcf MEDIUM 6.1 The FriendStore for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
8a7bf74b-1dc7-4159-a874-29694fe5895e MEDIUM 6.1 The Copy Or Move Comments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
8a79fda3-44eb-41fd-b049-971b959daecf
< 1.1.7
MEDIUM 6.1 In the VikRentCar Car Rental Management System WordPress plugin before 1.1.7, there is a custom field option by which we… wordfence
8a631446-90b6-4326-9700-12ebbe1c7877 MEDIUM 6.1 The Advanced PDF Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
8a5d32fc-41cd-4477-af2d-4a9709b05e72
< 4.0.0
MEDIUM 6.1 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Reflected Cross-Site Scr… wordfence
8a56c38c-93ba-4e22-92b4-72d79ba8cca4 MEDIUM 6.1 The WP Database Error Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘email’ p… wordfence
8a539a4e-f4df-46c7-83c2-9f189f081405
< 3.37.30
MEDIUM 6.1 The WP Fusion Lite WordPress plugin is vulnerable to Cross-Site Request Forgery via the `show_logs_section` function fou… wordfence
8a4ee97c-63cd-4a5e-a112-6d4c4c627a57
< 1.5.6
MEDIUM 6.1 The GN Publisher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in ver… wordfence
8a48f82a-761b-4b7a-a51e-0f9c780e0306 MEDIUM 6.1 The IFrame Admin Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter … wordfence
8a43db90-2a9e-4223-bf55-fef1a6bb2280
< 2.36.2
MEDIUM 6.1 The Simple Giveaways for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'method' and 'share' paramete… wordfence
8a41f96d-216f-4e5a-a28d-665b052666fb
< 1.0.76
MEDIUM 6.1 The Amelia plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'code' parameter in versions up … wordfence
← Prev 878 879 880 881 882 883 884 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top