πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 887 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
84b45b34-c74c-4b56-bcb0-c905a9a44969 MEDIUM 6.1 The UnGallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2… wordfence
84a206fd-c743-4214-a71a-9996a22ab19c MEDIUM 6.1 The Script Compressor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
849d0d4a-bc4c-4a45-a2db-0ad12ddcf5e4 MEDIUM 6.1 The StudioZen Theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to inclusion of a vulnerable versi… wordfence
848bfa37-7560-4c6b-8bbf-ee133c799291 MEDIUM 6.1 The Cookie Consent & Autoblock for GDPR/CCPA plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… wordfence
847f1c00-0e8f-4d38-84af-fe959e2efe5c
< 1.2.4
MEDIUM 6.1 The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in … wordfence
8451fe09-4280-49ef-b088-698cbf40b86b MEDIUM 6.1 The WP Promoter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
844b7471-3adf-45fd-9906-f0c817d6565c
< 2.0.1
MEDIUM 6.1 The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Re… wordfence
843cc5e7-7820-409c-8de0-bd70245811cd MEDIUM 6.1 The Label Plugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
8416b394-28ae-41de-8784-2ae39f4d201f MEDIUM 6.1 The Avishi WP PayPal Payment Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
83fd4f00-e8a8-4a33-af6b-20ff539fbfeb MEDIUM 6.1 The MoneyTheme theme for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization and outp… wordfence
83d7bf88-5def-4663-a446-dc205f2cd671
< 1.50
MEDIUM 6.1 The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post com… wordfence
83d71349-ddef-492d-8fc6-eb73d379cac2 MEDIUM 6.1 The Likert Survey Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
83d46dce-b218-49ed-85ee-0e8d2a391eb9
< 1.2.1
MEDIUM 6.1 The Contact Form Entries – Contact Form 7, WPforms and more plugin for WordPress is vulnerable to Reflected Cross-Site… wordfence
83d162f9-32a9-4d03-845e-6fc9b8574fb5
< 1.1.6
MEDIUM 6.1 The Darcie theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1.5 d… wordfence
83b2226e-0b30-4a1e-9757-8afc76435211
< 2.6.0
MEDIUM 6.1 The Doppler Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
83b1740c-6392-4b52-82e0-377201aa61ac
< 0.2.11
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the log feature in the John Godley Search Unleashed 0.2.10 plugin for WordPr… wordfence
83abcebf-2d39-4ccd-9606-1a1b04f79675
< 1.6.4
MEDIUM 6.1 The GoStore theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to 1.6.4 (exclusive) … wordfence
83a3f61c-2385-456f-bca3-6d3f3ffd9694
< 1.15.4
MEDIUM 6.1 The MultiParcels Shipping For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an un… wordfence
83a35d16-526d-4e45-b2cf-a6858b2b2f21
< 1.0.17
MEDIUM 6.1 The Header Footer Code Manager Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the message … wordfence
83804c2a-2c4a-4f69-b833-dcd53ddab94d
< 10.5.1
MEDIUM 6.1 The WP Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters from… wordfence
836e3ca0-9f41-4ab2-a9bf-64a593f37c8a MEDIUM 6.1 The WP Keyword link plugin for WordPress is vulnerable to Cross-Site Scripting via the 'limit' parameter in versions up … wordfence
8369d83a-bfbf-4e29-8b0b-ceb371a271b6
< 3.0
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in admin_panel.php in the Simon Elvery WP-Footnotes 2.2 plugin for W… wordfence
835f553b-9c43-47f2-aecf-61c9397e6b5b
< 1.5.75
MEDIUM 6.1 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded… wordfence
835db0c0-f3c9-4acd-aee8-bf7b52447ac9 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the WP-FaceThumb plugin possibly 1.0 and earlier for WordPress allows remote… wordfence
835cbcfa-bb8d-4b46-9316-500e1b47cfb5
< 1.12
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the HK Exif Tags plugin before 1.12 for WordPress allows remote authenticate… wordfence
← Prev 884 885 886 887 888 889 890 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top