πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 888 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
83556ba7-6eb3-404e-a077-05d78171badd
< 5.4.6
MEDIUM 6.1 The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
834ff44a-4259-49a5-bad3-26fce393fb98
< 21.08.02
MEDIUM 6.1 The Docket Cache – Object Cache Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t… wordfence
834e86c6-f516-4991-a693-d23db2bf14ce
< 1.7.5
MEDIUM 6.1 The Student Result or Employee Database plugin for WordPress is vulnerable to Cross-Site Request Forgery on its ajax act… wordfence
8321c669-af27-4454-ab7a-374de4f149cf
< 1.9.3
MEDIUM 6.1 The Filled In plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9… wordfence
83157b37-75f6-4ab9-8759-3d9a9cb9303d
< 1.35
MEDIUM 6.1 The Updater by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
83145c07-29e5-4609-8f14-d62fe6b64c73 MEDIUM 6.1 The RWS Enquiry And Lead Follow-up plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up t… wordfence
83106660-0678-44c0-894d-7287230f616e
< 5.6.10
MEDIUM 6.1 The Enfold theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.6.9 d… wordfence
830baa14-e6bb-4d89-8678-dcf48c8b8377 MEDIUM 6.1 The 5centsCDN plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 25.… wordfence
8306090a-cb23-4cff-b859-07b0a0bf9186
< 7.0.6
MEDIUM 6.1 The Persian Woocommerce SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
8305be9c-cad5-4bbc-beab-0730a9abe1d9
< 1.7.1
MEDIUM 6.1 The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg. wordfence
8303c84f-8065-4394-a692-29cb72bada0a MEDIUM 6.1 The Hunk External Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜hr’ parameter … wordfence
82fe99af-f254-4f4f-ac27-3e1997c370f6
< 5.28.1
MEDIUM 6.1 The CiviCRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via improper CSRF checks in the CKEditor C… wordfence
82f525c9-c032-4770-8424-4ab7e05784f4 MEDIUM 6.1 The TinyMCE Extended Config plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … wordfence
82f214e3-a869-4295-9b92-725724cf059c MEDIUM 6.1 The Ads24 Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
82e9bd78-726f-421f-8bf0-560fa9eeab2c
< 1.14.6
MEDIUM 6.1 The weMail plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.14.5… wordfence
82e235ac-55b9-4cb7-94cd-086142accf3a MEDIUM 6.1 The The World plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.4… wordfence
82df5b2e-4c4a-402f-99c9-694fa710009b
< 2.1.11
MEDIUM 6.1 The LuckyWP Table of Contents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
82da75f4-f036-40e0-ae4c-5011d6a39df4
< 0.34
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in libs/xing.php in the 2 Click Social Media Buttons plugin before 0.34 for Wor… wordfence
82d6fc5d-8678-4459-8d2a-423803629d10 MEDIUM 6.1 The WordPress File Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
82caf69a-2423-4f0f-9cf2-7d4fe428e915 MEDIUM 6.1 The Tm – WordPress Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
82c6ed2f-20e8-46d1-a460-16d32b7536cd
< 1.2.0
MEDIUM 6.1 The WP Directory Kit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
82b48e39-4f8f-48b8-ba46-49e06bee2cc7
< 4.4.4
MEDIUM 6.1 The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'qc_res' parameter in v… wordfence
82b45bd5-4e47-458c-bff8-ee15cd9a3c0e MEDIUM 6.1 The Theme Demo Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
82b4291c-5e31-4909-b743-778e68a0fe20
< 8.5.5
MEDIUM 6.1 The WP eStore plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI in all versions up to… wordfence
82b182db-3f7b-4e8f-95ef-19800bb01a24 MEDIUM 6.1 The my white theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0.8… wordfence
← Prev 885 886 887 888 889 890 891 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top