πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 362 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b7d85921-9d70-4812-9c5f-11ee1d0821be
< 1.12.9
HIGH 7.2 The WP ERP plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in versions up to, and including, 1… wordfence
b7c70db1-5058-45e5-bd12-3e2cab0338ad
< 3.3.2
HIGH 7.2 Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors… wordfence
b7c0efd8-08c0-4283-a0bf-2f6ca3998668
< 1.0.3
HIGH 7.2 The Plezi WordPress plugin before 1.0.3 has a REST endpoint allowing unauthenticated users to update the plz_configurati… wordfence
b77e31cf-f5fd-4ae4-84bd-e92fe34690da
< 1.4
HIGH 7.2 The Traveler Layout Essential For Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all ver… wordfence
b73edf8f-7017-4239-8ddc-038481d3f65f
< 3.5.0
HIGH 7.2 The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalati… wordfence
b72cfc20-b133-4682-91e1-497236aba035 HIGH 7.2 The WP-TopBar plugin for WordPress is vulnerable to blind SQL Injection in versions up to, and including, 5.36 due to in… wordfence
b6fe5f1a-787e-4662-915f-c6f04961e194 HIGH 7.2 The WH Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters such as wh… wordfence
b6f0fe85-1b70-49b4-9c89-d00584362459
< 1.7.6
HIGH 7.2 The tagDiv Opt-In Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
b6e587fb-118b-44b6-a2bb-1d621f02845c HIGH 7.2 The Popup Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
b6e4d8c3-f3ab-40f9-a8d2-77b53a8dba72
< 13.2.9
HIGH 7.2 The WP Statistics plugin for WordPress is vulnerable to SQL Injection via the $search_engine value in versions up to, an… wordfence
b6d448c2-5acc-47f8-8e86-9ef10fa01513 HIGH 7.2 The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 … wordfence
b6ca5856-9010-4bb3-a024-92b3b4d500b4 HIGH 7.2 The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save… wordfence
b6310a0c-5a96-4dbc-940e-025c9b907c7d HIGH 7.2 The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, … wordfence
b6056cc5-1848-4c0c-8de2-9c6310687902
< 1.6.15
HIGH 7.2 The Product Addons – WowAddons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
b5f09c7a-a8f5-4885-97fe-9347d20b8817
< 7.6.60
HIGH 7.2 The wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.6.59 … wordfence
b5bb14c1-8713-4aa1-b50a-53bed07a5f80
< 1.3.1
HIGH 7.2 The Easy Email Subscription plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter i… wordfence
b591b7df-8492-4f66-8884-b4b27c0f0a11
< 2.37
HIGH 7.2 The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to Remote Code Ex… wordfence
b56a3e53-ae1a-4bec-8350-3df157c4ab3c
< 3.8.13.1
HIGH 7.2 The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.13… wordfence
b556bb3b-0fea-48a9-a893-3ad015559f3d
< 1.7.1
HIGH 7.2 The GD Security Headers plugin for WordPress is vulnerable to union-based SQL Injection via the 'filter-vd' and 'filter-… wordfence
b5318c2d-7b58-4830-bbc0-6d160968290f HIGH 7.2 The WassUp Real Time Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via spoofed IP Addresse… wordfence
b526b331-8c02-44b1-9555-156afe7ad45a
< 2.8.3
HIGH 7.2 WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability wordfence
b4f2554d-c047-4be2-a4e6-2ae51f077376
< 2.7.11.1
HIGH 7.2 The Groundhogg plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.7.11 due to insuf… wordfence
b4e61162-dba8-4cb8-b953-031b963de208
< 1.5.3
HIGH 7.2 The Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database plugin for WordPress is vulnerable to Stored… wordfence
b4e1638a-ddfb-44e5-951e-3e779971a3a7
< 3.3.1
HIGH 7.2 The Better Search – Relevant search results for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
b4b2587a-e84e-4149-b9ac-ecf36451f815
< 1.5.5
HIGH 7.2 The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form pa… wordfence
← Prev 359 360 361 362 363 364 365 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top