🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1066 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bf9d2008-a397-413d-868d-23afb55a8947 MEDIUM 5.4 The create_post_page AJAX action of the Custom Post View Generator WordPress plugin through 0.4.6 (available to authenti… wordfence
bf92c64b-ca76-4af7-a1e4-585a60b03153
< 1.71.0
MEDIUM 5.4 The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to unauthorized arbitrary shortcode execution in all ve… wordfence
bf16617d-cec2-4943-bd20-7ade31878714
< 2.1.9
MEDIUM 5.4 The Tutor LMS plugin for WordPress is vulnerable to unauthorized access, modification, or loss of data due to a missing … wordfence
bed25977-040e-4427-b1e3-e9be9733b31f
< 0.9.19
MEDIUM 5.4 The Contact Form 7 Extension For Mailchimp plugin for WordPress is vulnerable to Server-Side Request Forgery in all vers… wordfence
beceb191-654b-48ea-9b8f-3f4ca974160e
< 4.2.4
MEDIUM 5.4 Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in … wordfence
beb70eb8-9a9c-4116-832c-337fc2a03329
< 3.7.35
MEDIUM 5.4 is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not p… wordfence
bead5edb-402a-44bc-9e2b-89201fa4603c
< 1.5.7
MEDIUM 5.4 The “HT Mega – Absolute Addons for Elementor Page Builder” WordPress Plugin before 1.5.7 has several widgets that … wordfence
be10894d-2a86-4f07-8119-e6eac8c9c950
< 5.9
MEDIUM 5.4 The Menubar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.2. Th… wordfence
bdeba3c8-fd78-40c1-8d76-75ff927c97e4 MEDIUM 5.4 The Custom Shortcode Sidebars plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
bd6cddeb-c812-4496-9377-cc8832842c51
< 20.3.1
MEDIUM 5.4 The WordPress Online Booking and Scheduling Plugin WordPress plugin before 20.3.1 does not escape the Staff Full Name fi… wordfence
bd3a2aaa-f911-43ec-9d49-2c04f74e5e8d
< 2.2.8
MEDIUM 5.4 The Add Link to Facebook Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘al2fb_render_ad… wordfence
bd0d8661-4725-41dd-88ce-8e94e285d5b8
< 4.15
MEDIUM 5.4 The Uncanny Automator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
bc7384d7-c2fd-4d63-9b80-bb5bde9a23d5
< 6.4
MEDIUM 5.4 The Weaver Xtreme theme for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta in all versions … wordfence
bc5c7974-4c10-4880-8823-2accee3c0da4
< 3.3.09
MEDIUM 5.4 The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3… wordfence
bc2ee795-39e5-48c2-ac2a-cfc520bdd857
< 1.6.1
MEDIUM 5.4 The QR Redirector WordPress plugin before 1.6.1 does not sanitise and escape some of the QR Redirect fields, which could… wordfence
bb4abe41-fb18-46f4-9fd8-90bb1996b241
< 4.6.19
MEDIUM 5.4 The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newslette… wordfence
baecb227-08c4-4de7-a725-db6639587f13
< 2.7.2
MEDIUM 5.4 The JS Help Desk plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.… wordfence
bad7e5c9-f413-43ce-9ab8-e700002f2f3a
< 2.0.4
MEDIUM 5.4 The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which co… wordfence
babcd8a8-c64d-4a71-b7ed-92ef497ef63d MEDIUM 5.4 The Free Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includ… wordfence
ba9d12c5-fe3a-4958-8d35-c63bb05b6d5a
< 1.2.9
MEDIUM 5.4 The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin… wordfence
ba798567-4a6e-4bbc-bd79-e1351af2ad4e
< 2.4.9
MEDIUM 5.4 The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, … wordfence
ba70f811-543f-4da4-ba45-715dbd6be6be
< 3.3.26
MEDIUM 5.4 The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in a… wordfence
ba5e93a2-8f42-4747-86fa-297ba709be8f
< 1.10.2
MEDIUM 5.4 The Bricks theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘customTag' attribute in versions … wordfence
ba5656b9-615d-4764-974a-301d3dd748e8
< 1.5
MEDIUM 5.4 Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, wh… wordfence
ba44ec7c-7c71-4c19-8b1e-5d78bb3a3a03
< 3.5.3
MEDIUM 5.4 The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description fiel… wordfence
← Prev 1063 1064 1065 1066 1067 1068 1069 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top