πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 886 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8617dc53-8994-4fab-a3df-27863ad3dd10
< 1.6
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme before 1.6 for WordPress allows remote attackers … wordfence
860ce27b-749d-497f-9038-7e035cb3fe1d MEDIUM 6.1 The Live Chat from ClickDesk – Live Chat – Help Desk Plugin for Websites plugin for WordPress is vulnerable to Cross… wordfence
8607de39-39cd-4edb-82da-179f4518b462 MEDIUM 6.1 The a Gateway for Pasargad Bank on WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in a… wordfence
8604f1d2-7300-4163-828b-ca17ba53f613
< 2.3.2
MEDIUM 6.1 The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mp' parameter in all ver… wordfence
85ca96a6-7992-424b-8b88-9a0751925223
< 1.0.93
MEDIUM 6.1 The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the… wordfence
85ba90ae-8144-42f0-90db-e7f2638fec47
< 1.11.12
MEDIUM 6.1 The CartFlows Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versi… wordfence
85b08a8f-8dfe-4ed4-8694-76382c6308c3 MEDIUM 6.1 The phZoom Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
85b0841c-eae1-4cce-9bfb-0ef5ba6abccc
< 3.7.8
MEDIUM 6.1 The Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.7. This… wordfence
85a8a7df-b472-4a81-b808-a413c158c1cf
< 0.21.11
MEDIUM 6.1 The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg withou… wordfence
859e9233-1e5d-4430-87c1-bcd8225b6258
< 2.9.1
MEDIUM 6.1 The WooCommerce Ultimate Gift Card - Create, Sell and Manage Gift Cards with Customized Email Templates plugin for WordP… wordfence
856f8b5f-809e-4ce2-8ef1-3ed169bc2b19
< 3.2.8
MEDIUM 6.1 The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789. wordfence
85581a5d-a898-4dac-af48-139b36728760 MEDIUM 6.1 The Simple Behance Portfolio WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `dark` parameter i… wordfence
85551a4b-d75d-4bbb-bfcb-465cdb4ad4eb MEDIUM 6.1 The JobBank plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2.2… wordfence
8550c89d-05af-4506-8fa7-cd1762a6c330
< 7.2.5
MEDIUM 6.1 The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,… wordfence
85501fc0-5d51-492b-b208-4b84f371ee77 MEDIUM 6.1 The Hello In All Languages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
852c44ba-e5c5-4206-b727-f4c4c1b889a1 MEDIUM 6.1 The WP etracker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
85277e85-b28e-47e1-a24a-5ba971d9f868 MEDIUM 6.1 The CAS Maestro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
85277960-2bba-4cd7-9f4c-e04f6743b96c
< 3.3.4
MEDIUM 6.1 The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter cal… wordfence
85198759-0b9c-4c8a-b650-ad268d0cb784
< 2.10.0
MEDIUM 6.1 The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.0 was affected by a reflected Cross… wordfence
8517eaa7-278c-4671-855e-bf8c87068c4c MEDIUM 6.1 The BetPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.… wordfence
84f10360-3c8b-487e-9213-dbdf1e41cbe7
< 1.0.5
MEDIUM 6.1 wordfence
84ef0f21-74af-4cb7-bab6-47c25df0522e
< 3.6
MEDIUM 6.1 The Morning Coffee theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the PATH_INFO to index.php in… wordfence
84e230d1-9b62-450b-8d8f-bdf25e17a97a MEDIUM 6.1 The alike plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.0… wordfence
84d0a029-c18c-47f9-80e0-294d050007a1 MEDIUM 6.1 The Pixobe Cartography plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
84be56bd-b9b5-4211-82f3-c86d4eee3a16 MEDIUM 6.1 The Smart Maintenance & Countdown plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
← Prev 883 884 885 886 887 888 889 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top