🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 889 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
82b020ea-fe42-4a97-b851-a335e73c9cd6 MEDIUM 6.1 The Ultra WordPress Admin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
8278debf-074f-40ba-ae35-db278a73880e MEDIUM 6.1 The Admin Cleanup plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
827220d0-edb7-4a41-9b00-a289073c6aad MEDIUM 6.1 The iMoney plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.36 d… wordfence
825d9154-7385-4652-b258-cf813be9bcdb
< 2.15.3
MEDIUM 6.1 Cross-site scripting vulnerability in Site Reviews versions prior to 2.15.3 allows remote attackers to inject arbitrary … wordfence
825af974-dccd-4409-8f22-fa70240b0c66 MEDIUM 6.1 The Easy Set Favicon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
8259508b-186d-4f2f-ac37-72e3b259ea5e MEDIUM 6.1 The Display Future Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
82583e18-2e0b-4618-bc0c-d8b058acc1c8
< 1.6.4
MEDIUM 6.1 The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
8247c654-0082-4677-a0a6-b90a0256de81
< 1.6
MEDIUM 6.1 The Smash Balloon Social Photo Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘acce… wordfence
823677be-c12b-4c75-ae42-7238f7a32a82 MEDIUM 6.1 The WP Ultimate Reviews FREE plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… wordfence
8232ff9e-e8de-4bd1-9a73-2383a4a25b80
< 2.0.8.4
MEDIUM 6.1 The The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library) plugin for WordPress is vulnerabl… wordfence
822f5b92-8c58-4132-80a7-d15e1215c934
< 1.61
MEDIUM 6.1 Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote… wordfence
822c0a33-e57e-48c7-b8df-fddf3bb2e552
< 3.0.10
MEDIUM 6.1 The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
82259b54-0313-41a2-ace4-41e583b93e8a
< 2.9.16
MEDIUM 6.1 The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging. wordfence
81fd3ac1-91af-4cfa-ac4e-712beb4236c0
< 4.2.5.4
MEDIUM 6.1 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the add… wordfence
81f4f8e8-cac3-4865-a686-212f6c7f7b65 MEDIUM 6.1 The CAPTCHA in Thai plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘noise’ and ‘dist… wordfence
81ebbfb5-8189-4ba0-80cd-380c897ab234
< 7.2.6
MEDIUM 6.1 The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
81d73996-d192-485b-bc47-1db7e6ca70e6
< 4.2.4
MEDIUM 6.1 The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Reflected Cross-Site Script… wordfence
81d28e90-252f-4b5f-a55b-8cb96292538e
< 3.2.6
MEDIUM 6.1 The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
81cc09ee-da3d-407d-82c0-542b56df5aed
< 3.2.20
MEDIUM 6.1 The Booking Calendar and Booking Calendar Pro plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via… wordfence
81ca577d-5337-4d46-94bb-93c230cf0348
< 2.1.1
MEDIUM 6.1 The The7 — Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Cross-Site Scripting in ve… wordfence
81bedea8-fbf7-411b-a31b-51af23522498
< 2.2.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the SoundCloud Is Gold plugin 2.1 for WordPress allows remote attackers to i… wordfence
81b76824-8099-433d-88e3-c05df9434fd6
< 2.0.8
MEDIUM 6.1 The Subscribe to Comments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI in all ve… wordfence
81b4a218-7752-4276-a523-1edbe1e36442
< 5.4.9
MEDIUM 6.1 The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_create_products_xml_resul… wordfence
81ac0ec4-8476-4ed5-9b00-a0456afef191
< 7.5.46.7212
MEDIUM 6.1 The FV Flowplayer Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… wordfence
81ab65c1-9440-49fb-9369-feda1b662fe0 MEDIUM 6.1 The Pit Login Welcome plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
← Prev 886 887 888 889 890 891 892 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top