πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1067 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b9ea24b5-ef7d-4bd5-bddb-46082a4a0763
< 5.6.2
MEDIUM 5.4 The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capabi… wordfence
b91cd230-7e84-4dbf-8aad-18b54bfdc4e7 MEDIUM 5.4 The sitetweet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2… wordfence
b8fc89c0-292d-47b4-90b3-79edf3a9e76d
< 3.5.7.7
MEDIUM 5.4 Several BeRocket Plugins for WordPress are vulnerable to authorization bypass due to missing capability checks on functi… wordfence
b8f870a6-26a5-4f98-9bd6-12736c561265
< 2.7.1
MEDIUM 5.4 The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data… wordfence
b8cf9350-d207-49ae-865a-b2e016b41b55
< 2.1
MEDIUM 5.4 The plugin Dropdown and scrollable Text for WordPress is vulnerable to Stored Cross-Site Scripting via several parameter… wordfence
b89c51fe-c056-4d85-a6e3-6678ed93b9d8
< 2.3.1
MEDIUM 5.4 The LWS Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.0… wordfence
b89185c1-f7f9-47fb-ae8b-ba4c9f4e1d3e
< 1.1.9
MEDIUM 5.4 The Client Portal – Private user pages and login plugin for WordPress is vulnerable to Cross-Site Request Forgery in v… wordfence
b84c0f8c-25a7-47c7-93cf-9b5060c07c72
< 18.4
MEDIUM 5.4 The woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure. wordfence
b83fe2b8-1579-48a6-b288-3b4dd0a1565f MEDIUM 5.4 The Subscribe to Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and i… wordfence
b7dac90c-d84a-4e93-a4c0-baaa5fee11c9 MEDIUM 5.4 Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, There is a stored XSS vulnerability via the $valu… wordfence
b7c808ff-546b-445e-af38-0b45cab3f307
< 1.5.5
MEDIUM 5.4 The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Authorization Bypass in versions u… wordfence
b76de574-2627-46cd-9817-134a009ac3bd
< 2.77.3
MEDIUM 5.4 The WP-Polls plugin for WordPress is vulnerable to SQL Injection via COOKIE in all versions up to, and including, 2.77.2… wordfence
b6de97ac-127d-47ec-8b74-03e7fa4932f6
< 2.5.3
MEDIUM 5.4 The Pz-LinkCard plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2… wordfence
b6bff35f-f881-4c60-9611-4a04727bac36
< 3.5.1
MEDIUM 5.4 The WooCommerce Eway Gateway plugin for WordPress is vulnerable to insecure direct object reference in versions up to, a… wordfence
b6846688-5716-4b22-8a1d-b96b230b0742
< 3.4.0
MEDIUM 5.4 The Quill Forms plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability chec… wordfence
b66e2537-f187-4237-b248-f8a361f9cb00
< 3.13.2
MEDIUM 5.4 The Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks o… wordfence
b64bd2b9-56d5-47d4-9532-3718bf2381a7 MEDIUM 5.4 The MainWP Broken Link Checker plugin for WordPress is vulnerable to authorization bypass in versions up to, and includi… wordfence
b6369b41-d93f-4959-8fad-be69ef724b24
< 1.0.20
MEDIUM 5.4 The Extended Post Status plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
b5abfc19-dc34-4458-a0af-5587b7d5a6b9 MEDIUM 5.4 Authenticated (contributor or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in 2J Slideshow Team'… wordfence
b59decf5-938c-4a5f-a839-47e19e978c84
< 3.3.2
MEDIUM 5.4 The Recipe Card Blocks for Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized access due to a miss… wordfence
b581e866-2b3b-4d6f-8bd3-d370c6482d12
< 2.0.2
MEDIUM 5.4 The User Registration WordPress plugin before 2.0.2 does not properly sanitise the user_registration_profile_pic_url val… wordfence
b564eacd-1561-4c42-8a9e-395d4e951723
< 1.1.5
MEDIUM 5.4 The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'd… wordfence
b535d4b1-3e57-49e3-b208-be0a64855017
< 1.2.2
MEDIUM 5.4 The Clariti plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
b5278afb-9db3-4b1d-bb2f-e6595f0ac6dc
< 3.4.4
MEDIUM 5.4 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized loss of data… wordfence
b5111eb6-b4b3-4b18-9de3-577c323eaab8
< 3.0.7
MEDIUM 5.4 The Advanced Menu Manager plugin for WordPress is vulnerable to Arbitrary Menu Creation/Deletion in versions up to, and … wordfence
← Prev 1064 1065 1066 1067 1068 1069 1070 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top