🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1030 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bce8b43a-a69e-44d1-adab-98253e86cb33
< 4.4.7
MEDIUM 5.5 The WP Meta SEO WordPress plugin before 4.4.7 does not sanitise or escape the breadcrumb separator before outputting it … wordfence
bcd12bf2-0fbe-4c9e-b6f7-43c10798eadc MEDIUM 5.5 The job-portal WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sa… wordfence
bcbb6614-09fc-4f41-81f7-d70aa92101bf
< 5.8
MEDIUM 5.5 The BulletProof Security WordPress plugin before 5.8 does not sanitise and escape some of its settings, which could allo… wordfence
bc79e104-47c0-4f4a-9a7b-dc0d6337ea05
< 1.4.4
MEDIUM 5.5 The Chameleon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpch_news_title’ parameter … wordfence
bc67ff08-b660-477a-9457-b681cf0381f5
< 2.1.3
MEDIUM 5.5 The Donation Thermometer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings para… wordfence
bb8d81c3-4a5b-491f-9868-3bb7b431f8e4 MEDIUM 5.5 The Alpine PhotoTile for Pinterest plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown para… wordfence
bb4d6d2c-a69d-492e-a2d5-fabfaef82f68 MEDIUM 5.5 The OAuth Client by DigitialPixies plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
b9ef419c-3546-489b-b841-b12b8918abdd
< 2.4.8
MEDIUM 5.5 The WP Contact Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Text to display’ pa… wordfence
b99248e9-b34f-4f99-9db1-a4dc2dd45b9c
< 2.0.1
MEDIUM 5.5 The FluentSMTP WordPress plugin before 2.0.1 does not sanitize parameters before storing the settings in the database, n… wordfence
b9738054-058f-47be-9973-f119fbfd4396
< 1.9.7
MEDIUM 5.5 The WP Prayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, an… wordfence
b96d71cb-3af4-4d67-a4af-41bab79a7f61 MEDIUM 5.5 The WP Better Emails plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
b9394801-4a74-4327-9afd-35f4166c2abb
< 3.1
MEDIUM 5.5 The WP Home Page Menu WordPress plugin before 3.1 does not sanitise and escape its settings, allowing high privilege use… wordfence
b92c3d68-2e3e-4500-8da9-f89373126445 MEDIUM 5.5 The Scroll Triggered Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
b890d168-9ea7-49c0-b628-71c76c0c2c9c
< 2.10.4
MEDIUM 5.5 The Simple Banner WordPress plugin before 2.10.4 does not sanitise and escape one of its settings, allowing high privile… wordfence
b8721c4d-d89b-4e97-af01-20327013cfb6 MEDIUM 5.5 The Launchpad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its settings parameters i… wordfence
b82e6dce-b130-4025-b6e3-bde2350a6362 MEDIUM 5.5 The Responsive and Swipe slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rsSli… wordfence
b778048c-22e8-42ea-9d60-6e58b31a3035 MEDIUM 5.5 The Carousel CK WordPress plugin through 1.1.0 does not sanitize and escape Slide's descriptions, which could allow high… wordfence
b6ead872-76a7-49c3-af07-d87a4c68183f MEDIUM 5.5 The RegLevel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,… wordfence
b6c9814e-e854-4420-9ec1-d843187bd9e7
< 1.20.8
MEDIUM 5.5 The Splash Header WordPress plugin before 1.20.8 doesn't sanitise and escape some of its settings while outputting them … wordfence
b644e61a-5842-43a6-9525-97e1339dcc94
< 3.37.2
MEDIUM 5.5 The Wordlift plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in versions u… wordfence
b6119481-f399-4bba-a824-1d7346e7e155
< 3.3.2
MEDIUM 5.5 The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privi… wordfence
b5c715f9-8655-448e-a8d2-71f24c9d48ba
< 5.0.6
MEDIUM 5.5 The WP Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters… wordfence
b53e6c9e-f78f-44e8-ad0f-8cfaaac8b53f
< 1.3.16
MEDIUM 5.5 The Appointment Hour Booking WordPress plugin before 1.3.16 does not escape some of the Calendar Form settings, allowing… wordfence
b4ecf437-b9f5-47d3-85b2-c8159c937473
< 5.5
MEDIUM 5.5 The Image Hover Effects plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters on the … wordfence
b4c61072-5480-43f3-ad9f-ed3f0d577ebc
< 3.9.3
MEDIUM 5.5 The Companion Auto Update plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘update_delay_days… wordfence
← Prev 1027 1028 1029 1030 1031 1032 1033 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top