🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 891 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
809d0632-39a7-44a7-b368-9dc58270c666
< 6.1.7
MEDIUM 6.1 The Wordfence plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘adminURL’ parameter in v… wordfence
80871684-037a-472e-bc38-10dfe33d5c41 MEDIUM 6.1 The Comments Capcha Box plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … wordfence
807f895e-8a1d-4bf3-87df-2c9a5af54267 MEDIUM 6.1 The WP-tagMaker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
8073cc59-e5cc-4940-bce0-e501f0d959cc
< 3.3.0
MEDIUM 6.1 MapSVG MapSVG Lite version 3.2.3 contains a Cross Site Request Forgery (CSRF) vulnerability in REST endpoint /wp-admin/a… wordfence
807345dc-5e93-4dcf-a1a2-f13d6370d4a5
< 2.9.0
MEDIUM 6.1 The Photo Contest | Competition | Video Contest plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… wordfence
8070a920-9e8d-4bae-9ae5-f5732c8fb6d5 MEDIUM 6.1 The Terms of Use plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
806bbfb8-ebf3-4823-a241-91e01dc95228
< 1.8.3
MEDIUM 6.1 The Photo Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8… wordfence
8069e16d-a68a-4c72-934f-f79e50777565
< 2.7.5
MEDIUM 6.1 The White Label CMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
8063a545-4792-4ab7-b188-0e51a0fcfed4
< 4.4.4
MEDIUM 6.1 The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the H… wordfence
805a7bef-d56b-4678-8db9-798ad401352f MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in organizer/page/users.php in the Organizer plugin 1.2.1 for WordPr… wordfence
8059ea88-55b9-423e-9827-075d0aa90938
< 1.1.0
MEDIUM 6.1 Easy Canadian Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_… wordfence
805311c4-45ad-4d60-aa1c-35c710bfad90
< 2.1.17
MEDIUM 6.1 The Arconix Shortcodes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
8051fb03-7c38-4902-bbff-049c270d2be2
< 5.6
MEDIUM 6.1 The BP Profile Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ BPS_FORM’ param… wordfence
8049bff1-3262-464b-a9fa-d216eb3ab299
< 8.1.1
MEDIUM 6.1 The Seers | GDPR & CCPA Cookie Consent & Compliance plugin for WordPress is vulnerable to Cross-Site Request Forgery in … wordfence
8036bd83-9af5-4b71-8974-9b0690ea6769
< 6.3
MEDIUM 6.1 The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
80328a83-d70a-4801-8935-c7e1dddc5b23 MEDIUM 6.1 The Woo Store Mode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
8027fa07-6bc2-4e63-89d0-98079729921d
< 1.111
MEDIUM 6.1 There is an open redirect in the PhastPress WordPress plugin before 1.111 that allows an attacker to malform a request t… wordfence
80203516-8546-441a-b51d-2d09968492b5 MEDIUM 6.1 The Staff Directory Plugin: Company Directory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t… wordfence
800a06f3-8a5b-4ba1-ad16-3d3a214f372f
< 1.9.6.4
MEDIUM 6.1 The UpdraftPlus WordPress plugin for WordPress is vulnerable to Cross-Site Scripting via the 'add_query_arg()' and 'remo… wordfence
80098d80-79f5-4016-860a-15f7f608da29 MEDIUM 6.1 The Simple Matted Thumbnails WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVE… wordfence
7ffc705f-2fc8-4ab9-9853-fb4611188320 MEDIUM 6.1 The Thecs theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4.7 du… wordfence
7ff58a34-93ab-4e51-b857-fed1107631ea
< 2.7.8
MEDIUM 6.1 The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.7.… wordfence
7fe97e7a-5a4e-43e7-b4f3-81786e9ee3dc
< 1.5.6
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the new_fb_sign_button function in nextend-facebook-connect.php in Nextend F… wordfence
7fe4e182-5d0b-41da-8402-8b7de0b2c2e7 MEDIUM 6.1 The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all ver… wordfence
7fe412b3-038b-4cc7-88e9-d30f719273ab
< 2.7.6
MEDIUM 6.1 The Jobs for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
← Prev 888 889 890 891 892 893 894 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top