🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 882 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8a3e3d91-5ce5-4db1-856e-c1d12471f9ed MEDIUM 6.1 The Linux Promotional Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
8a36b98b-7197-434e-88ac-6fcfa34d6abb MEDIUM 6.1 The Photo Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘pf-gid’ parameter in al… wordfence
8a253b04-bbe9-42d1-b6d9-1a62ad37855c
< 1.9.4.5
MEDIUM 6.1 The WassUp Real Time Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters … wordfence
8a22873f-6f09-4183-92c5-a84e0d378920
< 1.0.3
MEDIUM 6.1 The WP Pocket URLs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] in vers… wordfence
8a096e35-4480-4950-96ea-02a8751b8e98
< 4.7.9
MEDIUM 6.1 The Noo JobMonster theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
8a052ca1-2c2c-4c8a-9213-5f01b0fa70dd
< 2.17.4
MEDIUM 6.1 The limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows wp-admin/options-general.php?page=limit-logi… wordfence
8a047313-fdbc-47fa-912a-a624033bbce1 MEDIUM 6.1 The Clik stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` param… wordfence
8a02f5b1-5f0a-45f7-925c-1837a47dd051 MEDIUM 6.1 The UDesign theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.7.3 … wordfence
8a01ed06-4b48-4958-9990-469bf43d3e00 MEDIUM 6.1 The GuCherry Blog theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
89dec659-5427-46bb-8250-1e4a132611df
< 9.0.30
MEDIUM 6.1 The WP Google Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
89ccfd33-042f-4d9e-a70e-dfbd4235efa6 MEDIUM 6.1 The WP Flipkart Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
89c588e4-2f42-4ec5-8d05-3b45b23066c5
< 1.16
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the ThreeWP Email Reflector plugin before 1.16 for WordPress allows remote a… wordfence
89c3aae0-68f4-471e-8687-e87e71fa7a82 MEDIUM 6.1 The All push notification for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up… wordfence
89c32230-99e4-4d08-8afb-8f6f8bf94eab
< 1.4.11
MEDIUM 6.1 The simple-fields plugin before 1.4.11 for WordPress has XSS. wordfence
89b12c36-e115-4f67-86e6-647dfc9fd25b MEDIUM 6.1 The Audio Comments Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
89a6aab0-e85b-4604-b911-03a01c5cca13
< 1.7.0
MEDIUM 6.1 The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php. wordfence
898c2851-27e9-493a-96c7-b6be1c1f5c7f
< 3.11.3
MEDIUM 6.1 The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php… wordfence
898bd4ae-6dc7-4fb3-8236-d46b891e086f MEDIUM 6.1 The Translator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.… wordfence
89888c4c-74e1-4808-9a1e-6d23df513db5 MEDIUM 6.1 The Custom Admin Menu plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
89746f2b-4893-4e9b-841a-6f346cd8dac4 MEDIUM 6.1 The Captchelfie – Captcha by Selfie plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions u… wordfence
8965a9e4-af93-49fb-8224-2d6e62fa2fd3 MEDIUM 6.1 The Darna Framework plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
89614950-8517-4765-886a-1aa30a2f052e
< 2.4.2
MEDIUM 6.1 The Paid Member Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
8946d3be-857c-4675-999a-5b35633668d2 MEDIUM 6.1 The XTRA Settings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
8945cd7a-4185-4f0f-b56b-8ddd193dfed7
< 2.0.0
MEDIUM 6.1 The wpape APE GALLERY plugin 1.6.14 for WordPress has stored XSS via the classGallery.php getCategories function. wordfence
8945128b-79b7-46c7-b981-78e6619d3f63 MEDIUM 6.1 The WPSID Shortcode plugin for WordPress is vulnerable to Open Redirect due to the plugin accepting a user-supplied red… wordfence
← Prev 879 880 881 882 883 884 885 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top