πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1290 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bfa1192b-34f5-4b71-8fff-14f2d4ac4aca
< 1.8.31
MEDIUM 4.4 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
bf5e5eaf-b42d-49b9-8f55-6025e64748c9
< 1.1
MEDIUM 4.4 The Cyberus Key plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'uid' in 'cyberkey_settings' p… wordfence
bf2ffdb1-fe10-475b-9c05-553a95d7b3bc MEDIUM 4.4 The Full Screen (Page) Background Image Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
bf29bc2a-876a-484a-983f-a751cf2070c0
< 1.9.2
MEDIUM 4.4 The Laposta WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
bef1d842-5e04-47ea-b318-55f94c941be0
< 1.3.8
MEDIUM 4.4 The Intagrate Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … wordfence
bee43fe3-d39a-475e-90c5-24fa569c646a
< 11.9
MEDIUM 4.4 The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… wordfence
beb1268c-b680-4ebe-8fe2-65f656390038
< 3.0.7
MEDIUM 4.4 The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulne… wordfence
be841d6b-e3b6-46d2-aba8-fee20c21e933
< 5.2.4
MEDIUM 4.4 The Quick Page/Post Redirect plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in ve… wordfence
be7c6cfa-6cac-46d2-8eb9-9fef8049f6e7
< 5.1.20
MEDIUM 4.4 The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner… wordfence
be6f660f-041a-42f2-ab5b-72aedf75727d MEDIUM 4.4 The About Me 3000 widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version… wordfence
be60b94f-d7bc-46e1-b47b-42d044597cc6
< 2.13.4
MEDIUM 4.4 The Registrations for the Events Calendar – Event Registration Plugin plugin for WordPress is vulnerable to Stored Cro… wordfence
be3a1bff-c20a-43c6-9f7f-3190d5b9c563
< 1.4.0
MEDIUM 4.4 The Pixeline's Email Protector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a… wordfence
be320456-acab-478b-a4b5-807feb7fb9b4
< 1.34.4
MEDIUM 4.4 The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
be2d005f-a056-4c53-91a6-7de422cdec89
< 3.0.4
MEDIUM 4.4 The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website … wordfence
be0e9463-359a-4db5-ba76-5d9995adceee
< 3.4.10
MEDIUM 4.4 The Terms descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
be0dc9be-f597-46d8-badd-452e442a6d1a MEDIUM 4.4 The WP Open Social plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up t… wordfence
bde8b267-2bfe-4ec2-a489-6edd6269ba6e
< 1.2.18
MEDIUM 4.4 The Email Template Customizer for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… wordfence
bdd35d61-0777-4e64-8a51-55fe928e75ba
< 1.0.41
MEDIUM 4.4 The Flo Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, an… wordfence
bd5a1ab9-8d59-464a-a227-9f6ee768e35c MEDIUM 4.4 The enigma-chartjs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the chart functionality in vers… wordfence
bd50d7bf-33a9-4a35-855b-7278080695a5 MEDIUM 4.4 The PDPA Consent for Thailand plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
bd2bc2e7-960e-40db-9dcc-a6a60117bd83
< 1.12.8
MEDIUM 4.4 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ver… wordfence
bcf6a12e-969b-4627-80c8-b51bb9b710cf
< 4.0.6
MEDIUM 4.4 The Survey Maker – Best WordPress Survey Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
bcf4e969-82de-4505-8406-8638217b5cb7
< 8.1.17
MEDIUM 4.4 The ActiveCampaign plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8… wordfence
bcd9df9c-e1f8-467a-8f1c-ab5c402004da
< 2.9.9.2.9
MEDIUM 4.4 The Pinpoint Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in vers… wordfence
bcbb65eb-28f8-4b09-abc9-0f8b7d050f2f
< 3.2.1
MEDIUM 4.4 The Clearout Email Validator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
← Prev 1287 1288 1289 1290 1291 1292 1293 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top