πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1292 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b7f373a8-30e6-4150-a890-5ebb702d97ee
< 1.8.39
MEDIUM 4.4 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
b7eaca63-8bc6-41c5-abf1-57d2885fcd90 MEDIUM 4.4 The Yandex Site search pinger plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
b7c630c0-b37f-48d5-a87c-8e7c60103a30
< 7.0.6
MEDIUM 4.4 The WP Full Stripe Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers… wordfence
b770224d-1146-449e-919c-b04350e828e2
< 4.15.9
MEDIUM 4.4 The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress i… wordfence
b762f8ed-2231-4c47-acda-721edfa5cc06 MEDIUM 4.4 The WP Hotjar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.0.3 … wordfence
b7417e25-be35-4134-9d38-f8ee91f0d1cf
< 2.1.0
MEDIUM 4.4 The Tabellen von faustball.com plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a… wordfence
b7085f08-5c60-4d8f-a765-95f379c3a37c MEDIUM 4.4 The wA11y – The Web Accessibility Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… wordfence
b67a677a-0425-40cd-b7c7-3c1d2a6a4b8e
< 1.4.3.1
MEDIUM 4.4 The 140+ Widgets | Best Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
b66ef488-0efe-43dd-8938-a1881ed2560a
< 2.1
MEDIUM 4.4 The Fan Page Widget by ThemeNcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i… wordfence
b63c9a5a-fa3e-46c7-9d9c-7c209fc5713a
< 1.2.5
MEDIUM 4.4 The Allow HTML in Category Descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via category d… wordfence
b62949fd-d73f-4c42-82c7-c29986bca1da
< 1.3.50
MEDIUM 4.4 The Falang multilanguage for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti… wordfence
b5c4064b-6cfa-455c-9193-3d863be34f27 MEDIUM 4.4 The Amen plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and… wordfence
b57c9e58-64a6-48e8-8ef6-25608e4131e6
< 2.4.2
MEDIUM 4.4 The Video Gallery – Best WordPress YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
b57749db-0a47-44f8-8607-d0d962c5ced2 MEDIUM 4.4 The TWW Protein Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Header' setting in… wordfence
b52e0207-4314-49f9-9c67-9b33f1ee31bc MEDIUM 4.4 The Piotnet Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, … wordfence
b515782a-d7ec-41a6-92f8-91823f2c0dcf
< 1.3.5
MEDIUM 4.4 The WishSuite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, an… wordfence
b5068daf-9baa-45e1-bf87-76630dede323 MEDIUM 4.4 The Tripadvisor Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
b4d73a55-c5fc-4a28-bcde-497051ac893b MEDIUM 4.4 The WP Edit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.4 du… wordfence
b4c36899-3c7b-41b6-a38d-86c8834b4c03
< 1.6.0
MEDIUM 4.4 The Gotham Block Extra Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all… wordfence
b4865576-9929-4ce2-a220-935f1f3e0485
< 1.1.5.2
MEDIUM 4.4 The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Room Title of the Manage Bookings f… wordfence
b472ffba-4bb8-4b46-9c6b-e80e286babd5
< 2.3.5
MEDIUM 4.4 The Favorites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to… wordfence
b405b5cb-b330-4bd6-87bd-fa97ded58460
< 2.3.2
MEDIUM 4.4 The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin slug setting in all … wordfence
b3d4f658-e9ce-490b-bcaa-1061a463dbb2
< 1.0.12
MEDIUM 4.4 The Premmerce Redirect Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a… wordfence
b3c070be-e955-4076-9878-0b1044766397
< 3.2.3
MEDIUM 4.4 The Sticky Buttons – floating buttons builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via st… wordfence
b36b9b8a-41b0-4b57-92c7-5acebe2b0bae
< 2.0.1
MEDIUM 4.4 The WP To Do plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and in… wordfence
← Prev 1289 1290 1291 1292 1293 1294 1295 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top