🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1068 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b5086b8d-6c74-4970-9937-5ddc5b528495
< 5.5.0
MEDIUM 5.4 The WooCommerce Weight Based Shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
b4bb3067-7953-466d-a469-8a101450f133 MEDIUM 5.4 The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Serv… wordfence
b47f9624-1829-42b7-8afb-fe25b234df72
< 3.6
MEDIUM 5.4 Multiple XSS vulnerabilities in the Easy Testimonials plugin before 3.6 for WordPress allow remote attackers to inject a… wordfence
b415f998-b0e5-4f22-817c-02bfdc0c405d MEDIUM 5.4 The Custom top bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
b3a83683-c159-4af1-b3ba-881a107d9ad6
< 2.0.0
MEDIUM 5.4 The Joli Table of Contents plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
b380b053-9847-48a8-ba12-d07db9df2baf
< 2.1.4
MEDIUM 5.4 The WC Price History for Omnibus plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
b37766e2-95d2-4a95-9381-ed65ce09b3d6
< 2.6.3
MEDIUM 5.4 The Workreap theme for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, but not including,… wordfence
b33bf55c-0397-44a2-8c18-ea5f8f1e2ec9
< 4.4.8
MEDIUM 5.4 The AI ChatBot plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on… wordfence
b335fc19-2998-4711-8813-6cb68d7447bd
< 5.5.2
MEDIUM 5.4 The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
b2d75e43-cd46-4c23-bea4-3564e0334a32
< 3.3.9
MEDIUM 5.4 The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site S… wordfence
b2ca838d-165d-4670-94ad-652eedf512ea
< 4.971
MEDIUM 5.4 The WPLMS theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… wordfence
b2833265-f1e5-4cfd-ad2f-ca28a59de82f
< 3.1.5
MEDIUM 5.4 The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme plugin for Wor… wordfence
b27b2e40-c703-4fa0-bff0-788e7a0351c6
< 2.8.4
MEDIUM 5.4 The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on a… wordfence
b2340ae3-3b22-4b14-9fce-4b845f2866b1
< 6.8
MEDIUM 5.4 The “Livemesh Addons for Elementor” WordPress Plugin before 6.8 has several widgets that are vulnerable to stored Cr… wordfence
b1faf343-1859-4bee-a2d5-f494f44c70ad
< 3.4.34
MEDIUM 5.4 The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordP… wordfence
b1faa178-e4b1-4d2e-85f1-b852fbf3ab17
< 1.2.0
MEDIUM 5.4 The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… wordfence
b1e421fb-4839-4e2d-911f-e2fa8c756744
< 3.0.9
MEDIUM 5.4 The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Referenc… wordfence
b19ce745-2cc4-48eb-b5f3-5011be7cceec
< 0.9.7.4
MEDIUM 5.4 The W3 Total Cache plugin for WordPress is vulnerable to Server Side Request Forgery in versions up to, and including 0.… wordfence
b1977c26-ae70-43ce-92c4-9d61ffd4e116 MEDIUM 5.4 The Photography theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
b1749bef-0952-4530-b607-4574765d2700
< 2.2.2
MEDIUM 5.4 The Total theme for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and includ… wordfence
b1355e9f-fa3a-439a-a13f-49b10dd4473a
< 1.2.3
MEDIUM 5.4 The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to improper LDAP value e… wordfence
b12a7e57-a45f-407a-9dd9-843a628d73ac
< 2.0.6.1
MEDIUM 5.4 The Library Viewer plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 2.0.6. This is … wordfence
b0bfe80d-f9d5-4fc0-a8dd-717c31020b8d
< 1.2.4
MEDIUM 5.4 The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow… wordfence
b08531b2-968e-4a00-ad7a-7abfe8cf0bd3
< 1.6.8
MEDIUM 5.4 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to unauthorized access due to insufficient … wordfence
afd05b33-a347-49f6-81f0-879606819ca6
< 3.1.1
MEDIUM 5.4 Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers… wordfence
← Prev 1065 1066 1067 1068 1069 1070 1071 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top