🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 885 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
87045c4e-d52f-4c35-81be-e8c8fc04479b
< 7.3.0
MEDIUM 6.1 The FloristPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
87019de5-abd3-4080-a5fa-f476a1645456 MEDIUM 6.1 The Just Variables plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
86fe0238-aafb-435f-a686-59393ed68444 MEDIUM 6.1 The WordPress Spam Blocker | Stop Spam for Contact Form 7, WP Forms and Formidable Forms plugin for WordPress is vulnera… wordfence
86f95721-ff77-4137-adba-61d74373ee06
< 1.1
MEDIUM 6.1 The Jetapo | Jobboard WordPress Theme and Jetapo | Jobboard WordPress Theme with WooCommerce for WordPress is vulnerable… wordfence
86e6a246-557a-42f7-8f1b-b1b914f9f928
< 3.2.1
MEDIUM 6.1 The Afterpay Gateway for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ord… wordfence
86e0ae2b-128c-4406-aef9-357904be86fa
< 1.4.18
MEDIUM 6.1 The Index WP MySQL For Speed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… wordfence
86e01e59-7863-4121-a231-53299aa6f0c4
< 2.6.4
MEDIUM 6.1 The Grand Conference Theme Custom Post Type plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in vers… wordfence
86d54e0c-39a8-435c-81a7-cbc35d9da11c MEDIUM 6.1 The Web Testimonials plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
86cb08ae-aa21-4ee6-baed-03429e4d38e2
< 4.1.7
MEDIUM 6.1 The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the use of a… wordfence
86c3ef76-d4d0-4106-850f-88e9ea176979
< 3.1.3
MEDIUM 6.1 The Easy Social Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in ver… wordfence
86ba4092-5d92-476c-b4e4-24429a077c60 MEDIUM 6.1 The LawPress – Law Firm Website Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all… wordfence
86b85505-8cae-4607-a645-5b127f6f37e7
< 4.8
MEDIUM 6.1 The Team Rosters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in all… wordfence
86b1710d-9503-4be3-a443-8c0ad6161d88 MEDIUM 6.1 The G Web Pro Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … wordfence
8693a8b1-15e1-4c9c-90fb-51fcaf5ff451
< 2.0.3
MEDIUM 6.1 The Keep Backup Daily plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘t’ parameter in … wordfence
868905af-ee6e-41a8-8040-84eee696b747
< 2.6.16
MEDIUM 6.1 The Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce plugin for WordPress is vulnerable to Refl… wordfence
8683bc00-1136-42c4-a256-84b2cac1d575 MEDIUM 6.1 The pixelstats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_id' and 'sortby' param… wordfence
86616f56-74cb-4ceb-95ce-fbd4a3842edd MEDIUM 6.1 wordfence
8650383a-712b-4830-894f-cd7ec7b0d5bc MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in ss_handler.php in the WordPress Spreadsheet (wpSS) plugin 0.62 for WordPress… wordfence
86389489-9f9d-479b-b351-19f25166fc91
< 2.5.8
MEDIUM 6.1 The Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin for WordPress is vulnerable to Reflected Cross-… wordfence
86358a01-bf69-4a7f-8b78-a0d42d362d96 MEDIUM 6.1 The MG AdvancedOptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF'… wordfence
862f8743-5c8c-45ee-a2eb-9ae12c2800ca MEDIUM 6.1 The Digihood HTML Sitemap plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘channel' param… wordfence
862d6ae8-5684-4a33-b85c-1d46e48f10f5 MEDIUM 6.1 The Wsify Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.… wordfence
862ab8c7-c4af-437e-a72d-31a401cd1765
< 1.5.7
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in tests/notAuto_test_ContactService_pauseCampaign.php in the Infusi… wordfence
8629d6a3-d35f-4aba-a33c-2800bb677616
< 1.1.0
MEDIUM 6.1 The License For Envato plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
8620d181-22f9-4054-9d5c-1b26a315d10c
< 2.6.3
MEDIUM 6.1 The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Script… wordfence
← Prev 882 883 884 885 886 887 888 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top