πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1294 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b0bc4476-bf6a-4af4-8da0-7df65226fbf2 MEDIUM 4.4 The WP Proposals plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, a… wordfence
b0ad4949-b7e8-4c50-af64-c59e053cfd0e
< 5.8002
MEDIUM 4.4 The Ebook Store plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
b0ac43ba-cc49-4688-9efa-585551f3c40c
< 3.8.6
MEDIUM 4.4 The WooCommerce Ship to Multiple Addresses plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versi… wordfence
b07f3ade-5f10-4621-99a2-18eeab993403
< 5.1.1
MEDIUM 4.4 The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Store… wordfence
b066f1fe-b416-4fe8-891d-b9c33664df89 MEDIUM 4.4 The Simple Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
b066da10-f842-4ff2-a4da-2d469169f423
< 1.2.59
MEDIUM 4.4 The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad… wordfence
b050fa45-05b7-49ff-bb24-179150f3f959 MEDIUM 4.4 The Binge Site Verification using Meta Tag plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin s… wordfence
afb5206a-9019-4de4-89b4-adffd11d1466
< 1.15.31
MEDIUM 4.4 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Store… wordfence
af9e9e8e-2a07-477e-b840-8f7dd8883caa
< 9.4.0
MEDIUM 4.4 The WP Travel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.3.1 … wordfence
af88a631-c4ec-47ec-ad9b-1ef38ea1be09 MEDIUM 4.4 The Private WP suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Exceptions' setting in a… wordfence
af742451-b2d6-445a-9a10-e950490f6c7c
< 1.26.7
MEDIUM 4.4 The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user… wordfence
af343eab-8327-4b13-91b9-f58535014d47
< 3.95.0
MEDIUM 4.4 The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Sto… wordfence
af1075a5-9efa-4b86-9798-6dbafcba4db5
< 1.15.25
MEDIUM 4.4 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Store… wordfence
aee1d4ea-a740-4015-9167-200ed1e2564c
< 1.5.1
MEDIUM 4.4 The ShMapper by Teplitsa plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and in… wordfence
aed90a59-9b66-4332-bb71-d738b1469156
< 2.4.28
MEDIUM 4.4 The Smart Post Show – Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Lates… wordfence
aec279e9-0469-45c7-a332-2d7151e11639 MEDIUM 4.4 The Color Your Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
ae9b5d77-32e8-4205-8f0a-5e53788674f0 MEDIUM 4.4 The Social Pixel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… wordfence
ae7c41fd-6ad6-49da-a213-686157e029d4 MEDIUM 4.4 The CPT – Speakers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via unspecified settings paramete… wordfence
ae66f460-ca84-49fb-9ef0-46bcca77996b
< 4.2.7.2
MEDIUM 4.4 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin sett… wordfence
adff1d97-84d7-4407-9eed-dd81177b5898
< 1.8.0
MEDIUM 4.4 The Behance Portfolio Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
ad98db62-4253-4fd5-90b3-c28a563c7697
< 3.4.24
MEDIUM 4.4 The My Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via events in all versions up to, and … wordfence
ad896d7d-2c75-466c-9a79-b6a9cfb0bc15 MEDIUM 4.4 The Popup contact form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions … wordfence
ad88c661-601c-411f-9495-2c3b8a568c6b MEDIUM 4.4 The Team Members Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve… wordfence
ad870543-2179-4022-be6b-01d7c7b80f3e
< 15.2.7
MEDIUM 4.4 The Inventory Presser plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
ad854478-37b5-4dbd-9517-73fdbd5d023e MEDIUM 4.4 The Search Cloud One plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
← Prev 1291 1292 1293 1294 1295 1296 1297 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top