πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1293 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b35ee801-f04d-4b22-8238-053b02a6ee0c
< 2.2.9
MEDIUM 4.4 The WP Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜pec_coupon[code]’… wordfence
b3552de0-3e0b-4529-a757-a31c69a06122
< 6.3.6.3
MEDIUM 4.4 The Advanced Custom Fields & Secure Custom Fields plugins for WordPress are vulnerable to Stored Cross-Site Scripting vi… wordfence
b329c9f9-e71b-4738-89f9-ea2761afeb0c
< 2.2
MEDIUM 4.4 The Submission DOM tracking for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers… wordfence
b3267339-2f28-40b9-b6ff-fdfe0d67bdc8 MEDIUM 4.4 The Social Metrics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up t… wordfence
b2e8f9b7-1fce-46be-8198-eeff58a563c6
< 1.0.12
MEDIUM 4.4 The Premmerce Redirect Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in v… wordfence
b2e336d3-edd9-4664-bfa5-deec4064ee0b
< 2.7.28
MEDIUM 4.4 The Lightbox & Modal Popup WordPress Plugin – FooBox plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
b2bdb698-3a07-4e8b-a498-b156accadc0a
< 3.2
MEDIUM 4.4 The Read More Without Refresh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ve… wordfence
b2ac9211-c21b-4bb9-9069-0c2cc10fb70f MEDIUM 4.4 The Comment Form WP – Customize Default Comment Form plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
b28634d1-6489-4ac2-9d64-2b7409fd462e
< 1.2.17
MEDIUM 4.4 The Astra Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
b27338c7-2fbc-4985-a25e-8e2a9fdef8c3
< 5.13
MEDIUM 4.4 The Customer Service Software & Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
b25efc5b-406a-47a5-995c-c2b85e34a8f2
< 3.0.0
MEDIUM 4.4 The Auto Prune Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
b23d276c-69c5-47e0-99bd-f20ff1d45904
< 3.2.0
MEDIUM 4.4 The CM Answers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, a… wordfence
b2371b84-bb56-4e5d-afce-cd33f2ee9316
< 4.5.0
MEDIUM 4.4 The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to … wordfence
b2136a08-93be-4611-9eff-6a9258401b96
< 7.1.0
MEDIUM 4.4 The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti… wordfence
b20ec769-822a-4d9b-9824-6e29d3677ac3
< 1.2.5
MEDIUM 4.4 The Filr – Secure document library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in a… wordfence
b1ea7e04-d3b3-43fa-be9a-a2d5ac3e34c3
< 1.0.8
MEDIUM 4.4 The Simple Site Verify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions … wordfence
b1bc2300-bd8d-4e4a-8ab5-a541f62133ca
< 1.8.31
MEDIUM 4.4 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
b1703f90-17ad-4988-a60c-e56f88f3a317
< 0.10.7
MEDIUM 4.4 The Maspik – Spam Blacklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in al… wordfence
b13ee51b-9f23-428f-9cef-4a9b9b06b0c4 MEDIUM 4.4 The Solidres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'currency_name' parameter in vers… wordfence
b128ecb7-325d-43c1-8187-c5949242e760 MEDIUM 4.4 The WP Editor.md – The Perfect WordPress Markdown Editor plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
b11ccbbd-c909-4160-af36-8f0b50fb1285 MEDIUM 4.4 The WP Testimonial Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… wordfence
b108e2e9-e5af-464a-98d9-bb40a2b65c14
< 1.0.219
MEDIUM 4.4 The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
b1043c80-e1fc-4264-8e51-218f89fdd162
< 5.0.3
MEDIUM 4.4 The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0… wordfence
b0fdad22-5aee-468f-885c-f65c068cf413
< 0.18.4
MEDIUM 4.4 The Theater for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… wordfence
b0d1cf3b-5631-49bd-a7aa-86de2ee4b5b9
< 1.5.3
MEDIUM 4.4 The Announce from the Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in … wordfence
← Prev 1290 1291 1292 1293 1294 1295 1296 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top