🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 883 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8938c153-0640-418b-87ab-ae65d6c80b97
< 1.21
MEDIUM 6.1 The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable t… wordfence
892c44bf-09b2-41cd-b2c5-894363495347 MEDIUM 6.1 The CRUDLab Scroll to Top plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
892a1983-018b-480d-adab-29c32fd88be5
< 1.8.1
MEDIUM 6.1 The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘curr_url’ p… wordfence
89253d8c-6e19-4980-bf87-21e0c5cfe35d MEDIUM 6.1 The Singsys -Awesome Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… wordfence
89209bcb-c74d-4bf9-b1a8-5b529f4d73be
< 4.4.8
MEDIUM 6.1 The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before … wordfence
8919207c-fea7-4e07-9794-1089b996780d MEDIUM 6.1 The Woocommerce – Loi Hamon plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
890c324a-34e0-455f-9782-6fc13ab10f6f MEDIUM 6.1 The BaiduXZH Submit(百度熊掌号) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up… wordfence
890bfe44-32e6-4edd-b46c-379ef4ce54d2 MEDIUM 6.1 The AffiliateImporterEb plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ebdn_min_price' pa… wordfence
88fdd087-4bce-4ead-bc78-c6bdbaa70d9c
< 2.0.1
MEDIUM 6.1 The WooCommerce Amazon Pay plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL when accessi… wordfence
88f78dd8-f720-4c10-98e8-bd7d522c3ceb
< 1.5.11
MEDIUM 6.1 The dynamic-widgets plugin before 1.5.11 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=dynw… wordfence
88f665b7-22ac-492e-8e98-dee1b2dd0a3f MEDIUM 6.1 The Mobigate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, … wordfence
88edf229-2be2-49d0-b500-e8ff7708f806
< 2.2.12
MEDIUM 6.1 The SEUR Oficial plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'change_service' parameter… wordfence
88e508ad-e7dd-4c8f-a44d-ef633e826007 MEDIUM 6.1 The osTicket WP Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
88d93119-5eaa-4c9b-a8dc-f40a5d91c8da MEDIUM 6.1 The Easy Bet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, … wordfence
88b40b01-2e4c-4368-960a-ffc8f0978e59
< 4.9.1
MEDIUM 6.1 The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all… wordfence
889cb1d5-7f5c-4904-9b5f-cc8a505eb65c
< 2023
MEDIUM 6.1 The Stop Spammers Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters i… wordfence
8881c74f-9941-4919-8a15-99407fca0946
< 3.4.8.7
MEDIUM 6.1 The weblibrarian plugin before 3.4.8.7 for WordPress has XSS via front-end short codes. wordfence
887ccf72-9ae1-4b7e-9f62-253dea459652
< 1.2.1
MEDIUM 6.1 The Updater plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 1.2.1 due to insuffic… wordfence
887ca432-5412-401c-8d4e-52dcb511e5ba
< 3.1.1
MEDIUM 6.1 The Advanced Database Cleaner WordPress plugin before 3.1.1 does not escape numerous generated URLs before outputting th… wordfence
8869a4fc-279f-4828-a271-8680d037fa85
< 5.0.9
MEDIUM 6.1 The Essential Addons for Elementor Lite WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escap… wordfence
88622945-9a55-4e44-86e3-f111b9490aa8 MEDIUM 6.1 The Add Sidebar WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the add parameter in the ~/wp_sideb… wordfence
88591c56-ff79-47bf-b5e0-e3471884d3b4 MEDIUM 6.1 The MD Custom content after or before of post plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve… wordfence
884973e2-3836-448f-8c0d-1235fb2c09b6
< 3.1.9
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject… wordfence
88426c25-d6a6-4720-84e9-90e28a552cea MEDIUM 6.1 The Magic Responsive Slider and Carousel WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
883fae5a-ac23-488a-9b26-fb914727f06a MEDIUM 6.1 The Penci Soledad Data Migrator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
← Prev 880 881 882 883 884 885 886 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top