πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1291 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bcb82472-e18c-447e-acad-796724188515
< 3.5
MEDIUM 4.4 The WP Private Content Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Admin Settings in … wordfence
bcaa19b0-2d55-4a0c-98e7-9a38488dd922 MEDIUM 4.4 The Image Social Feed Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
bc903082-1047-4272-9ab8-3341b61d0378 MEDIUM 4.4 The Upload Quota per User plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
bc643a55-be6a-4a59-a267-be613ca4a55d MEDIUM 4.4 The Goracash plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1 due… wordfence
bc2c3bdb-65b9-4e0b-899f-bd08077bc8ba MEDIUM 4.4 The WordPress Social Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in vers… wordfence
bbb65d61-c7e1-4884-8b10-a26df504724c MEDIUM 4.4 The Easy Login Styler – White Label Admin Login Page for WordPress plugin for WordPress is vulnerable to Stored Cross-… wordfence
bba6567f-457b-44fd-993a-3f5380a2c3fb
< 2.2
MEDIUM 4.4 The EventON plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, … wordfence
bb9ae252-7e5f-4dc0-a162-100493b81980
< 3.1
MEDIUM 4.4 The Meta-box GalleryMeta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver… wordfence
bb98b2ee-5c51-453f-9e55-52027237e732
< 1.1.5.2
MEDIUM 4.4 The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.5.1 d… wordfence
bb88a0e9-b282-454c-8ac8-c54f5d8d6121
< 5.5.5
MEDIUM 4.4 The Volunteer Sign Up Sheets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all… wordfence
ba7d0ab4-55a5-47f4-b66e-27e963ab2268
< 1.0.4
MEDIUM 4.4 The Comment Reply Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting settings in versions up to, an… wordfence
ba08695e-009e-434a-9db0-06aa1dd6d57a
< 1.7.1
MEDIUM 4.4 The Add Customer for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in… wordfence
ba03ee30-6da7-42fc-9cc9-2408bfbb09ce
< 2.6.3
MEDIUM 4.4 The WP Abstracts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to,… wordfence
b977e3f8-46e7-4294-ab5c-e42e81c900e0 MEDIUM 4.4 The Sunny Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions u… wordfence
b947bd68-2dfa-4637-8f10-39c283fdac70
< 3.7.9
MEDIUM 4.4 The Popup Box – Best WordPress Popup Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admi… wordfence
b9458918-beaf-4bad-8abd-521547df9497 MEDIUM 4.4 The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings (D… wordfence
b94303b5-2ee6-4549-ae59-74e0a0b00fa3
< 2.1.3
MEDIUM 4.4 The Wishlist for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
b93f4595-b4b5-46ef-8a50-45c0e3ff0212
< 2.34
MEDIUM 4.4 The Multi-Step Checkout for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
b8fcf1fb-c7ed-4a02-bb03-7f0a89f4c4e1 MEDIUM 4.4 The Simple Testimonials Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all v… wordfence
b8e3a111-6327-47a0-becd-d7e2d9166118 MEDIUM 4.4 The WP No External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version… wordfence
b8ce34dc-b509-476a-8960-a0c9369a6d72
< 1.3.0
MEDIUM 4.4 The Sticky banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… wordfence
b8bd08d0-5c78-40a8-abc1-de387908df9d
< 1.8.0
MEDIUM 4.4 The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via header/footer code in … wordfence
b8b3419e-23c7-48de-898f-133a52ae286a
< 3.6.34
MEDIUM 4.4 The Ninja Forms Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all… wordfence
b861e82a-dbff-491d-8a0a-1bfb9a7798ad
< 1.0.13
MEDIUM 4.4 The FastBots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,… wordfence
b827f0e1-b8ee-4015-a608-45505f43b324 MEDIUM 4.4 The Word Replacer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'replacement' parameter in a… wordfence
← Prev 1288 1289 1290 1291 1292 1293 1294 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top