🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 884 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
88290419-2086-4b43-b2b9-5d8128b208e2 MEDIUM 6.1 The Allure Real Estate Theme for WordPress is vulnerable to Cross-Site Scripting via ZeroCliboard.swf in versions up to,… wordfence
882639e3-615f-48df-9ddc-afbe0788d55f MEDIUM 6.1 The MM-Breaking News plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
882631ab-ef16-4158-adbc-60ad177ae6b8
< 1.11.27
MEDIUM 6.1 The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘message’ and 'error' p… wordfence
87efa10d-d359-4258-9db2-811d5ae75c60 MEDIUM 6.1 The LinkedIn Resume plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
87ee0da1-3a95-4e09-a070-4c8aa336ffe8 MEDIUM 6.1 The WP MediaTagger plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
87eb4569-bfde-4bd8-95ef-561ec04158c8 MEDIUM 6.1 The Userbase Access Control plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … wordfence
87e76cf7-cfaf-499d-8929-db7efd6ec284
< 2.1.5
MEDIUM 6.1 The Product Table by WBW plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
87d064fc-923a-41f1-a14f-09ff91b2aaee
< 2.8.0
MEDIUM 6.1 The CM Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.7… wordfence
87ca4c05-b9fc-4932-be4b-beb57ca3bb7e MEDIUM 6.1 The WordPress Content Slide plugin for WordPress is vulnerable to Cross-Site Scripting via the 'wpcs_options[slide_image… wordfence
87bb2aa8-9554-493b-931f-bef80dc5404a MEDIUM 6.1 The One Backend Language plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
87b8386e-863e-4a33-8beb-aab3e704ecb6
< 1.06
MEDIUM 6.1 The Built-in Widgets Query extend plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… wordfence
879bd819-5513-4253-b6e0-a34dbebae287
< 1.2.9
MEDIUM 6.1 The Better Find and Replace WordPress plugin before 1.2.9 does not escape the 's' GET parameter before outputting back i… wordfence
878ec7b7-356a-4e14-8c48-3e217f5f51a1
< 1.1.2
MEDIUM 6.1 The MemberPress Discord Addon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
87870d48-05ff-4f51-9ad9-091ce2ffaf01
< 3.9.002
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allow… wordfence
878671d2-572c-43f9-8fba-f2e2e955b7a6
< 3.8
MEDIUM 6.1 The Protect WP Admin plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.7 du… wordfence
8782aefa-6fb6-4b42-b697-cee3e1713e9c
< 3.0.5
MEDIUM 6.1 The Verowa Connect plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
875fbe6e-436c-445c-bd0c-0e6beae3fbf2 MEDIUM 6.1 The WordPress Gallery Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
875c6474-5bf3-4556-b529-299cd2f65afe
< 5.0.5
MEDIUM 6.1 The Slimstat Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
8759bb88-2c19-4875-99c1-f83a2abaffa2
< 2.3.2
MEDIUM 6.1 The Paytm Payment Donation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
87418933-53a6-41d4-af7b-f1d2408ff4cd MEDIUM 6.1 The Like in Vk.com plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
873b6ace-0377-42d8-a6c5-3fe0226cebc5
< 6.8.6
MEDIUM 6.1 The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type pa… wordfence
872a6264-f0e2-4936-a942-172a99892672
< 2.6.2
MEDIUM 6.1 The google-document-embedder plugin before 2.6.2 for WordPress has XSS. wordfence
8721b15f-cb17-48d2-bd8f-20125452d621 MEDIUM 6.1 The Redux Converter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
871bef47-a151-4c5b-bffa-bc0abb53e191
< 1.7.6
MEDIUM 6.1 The Integration for WooCommerce and Salesforce plugin for WordPress is vulnerable to Open Redirect in all versions up to… wordfence
87135f68-8010-40ff-8507-3111cf8e86e2 MEDIUM 6.1 The Smooth Dynamic Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
← Prev 881 882 883 884 885 886 887 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top