🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1410 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b96273e8-29a8-4802-8c83-1ce5ab9600b6
< 5.5.7
MEDIUM 4.3 The JoomSport plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … wordfence
b949d563-3d1d-469d-9793-c2613efbfaa8 MEDIUM 4.3 The WordPress Admin Bar Improved plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
b93e9e84-1675-4128-a018-03833ff75943
< 6.3.0
MEDIUM 4.3 The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to arbitrary custom field access in all versions up … wordfence
b92deadd-a50c-406d-afdf-301453967880
< 1.0.35
MEDIUM 4.3 The NewsMash theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.34. T… wordfence
b9216875-8cb6-45a7-b23b-19d13f8b49dc MEDIUM 4.3 The MP Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up t… wordfence
b90f76d9-3eb3-4ffe-aac7-95953de9972d
< 1.1.1
MEDIUM 4.3 The Freetobook Responsive Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
b90b7f6c-df7f-48a5-b283-cf5facbd71e5
< 1.58.0.0
MEDIUM 4.3 The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_options' function in ver… wordfence
b8fe4fe5-2b13-4001-a177-0d182aa2af30
< 2.0.10
MEDIUM 4.3 The PropertyHive plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… wordfence
b8faa34a-17fd-4a2e-b8bf-ed40fc7a88d9
< 2.4.0
MEDIUM 4.3 The Stock Sync for WooCommerce plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to a missing c… wordfence
b8f31f8e-03a0-436c-bfa3-bc41d70e8e2a MEDIUM 4.3 The Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid plugin for WordPress is vulnerable to Cross-Si… wordfence
b8d88cc2-91e4-4e53-8c46-93d6ce8bc320
< 1.0.14
MEDIUM 4.3 The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin… wordfence
b8d73c3d-e8b1-400d-8fed-d26a045026c2 MEDIUM 4.3 The Table of content plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
b8d5fa2d-07ee-46ef-bbcf-e7e45a4bbf69
< 2.3.8
MEDIUM 4.3 The Easy Elementor Addons – Addons Pack for Elementor Page Builder plugin for WordPress is vulnerable to Cross-Site Re… wordfence
b8d0638e-06c5-4884-a14d-4b28ae3ef3f3 MEDIUM 4.3 The Cache Sniper for Nginx plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
b8add6b9-8d53-4239-bbbc-d32a562fd9b9
< 2.18.2
MEDIUM 4.3 The NextMove Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1… wordfence
b8a82989-e7e7-484a-b619-3897d88872b9 MEDIUM 4.3 The Professional Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
b8a4ec9b-218a-4811-ad8b-236fc8e960fa MEDIUM 4.3 The occupancyplan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0… wordfence
b8a26695-4793-418b-9a23-6709fe79ea4f
< 2.0.3
MEDIUM 4.3 The Constant Contact Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… wordfence
b89cf8ef-9fa0-4ede-8ec9-c166d0db74fe MEDIUM 4.3 The wpMandrill plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th… wordfence
b8954061-cb8f-49fc-84d9-50851f7f48a2
< 1.8.7
MEDIUM 4.3 The WP Blast | SEO & Performance Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
b889440b-33f9-410b-b3d5-f41e08bcee82 MEDIUM 4.3 The Easy WP Optimizer – Optimize DB & WordPress plugin for WordPress is vulnerable to unauthorized access due to a mis… wordfence
b871ac5e-a62a-499e-9ef2-a38d105ed020
< 2.4.0
MEDIUM 4.3 The JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is vulnerable to Cross-Sit… wordfence
b854d8ba-2dc4-45f7-8128-8d2737fbb7d4 MEDIUM 4.3 The Ahmeti Wp Güzel Sözler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
b843e8f7-e854-4572-9b1f-b1b27f752f07
< 6.0.8
MEDIUM 4.3 The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to Cross-Site … wordfence
b83abce2-077e-4892-908b-8de88cd0a298 MEDIUM 4.3 The HL Twitter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 20… wordfence
← Prev 1407 1408 1409 1410 1411 1412 1413 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top