πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 443 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bd53bc57-b10e-47a7-8c10-96bf1f1e82a5 MEDIUM 6.5 The All in One B2B for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
bd46a2c3-f24d-4dff-b899-a95acb6310f7
< 2.1.13
MEDIUM 6.5 The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms. wordfence
bd31e8b0-6089-4521-a80f-e65e61ad062f MEDIUM 6.5 The Word Replacer Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in ver… wordfence
bcca7ade-8b35-4ba1-a8b4-b1e815b025e3
< 5.4.9
MEDIUM 6.5 The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8… wordfence
bcaa5d0e-b764-4566-bd46-2d41dc391c36
< 2.4.2
MEDIUM 6.5 The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… wordfence
bca9d9a2-6c96-4653-9408-2e20f4a9d5f4 MEDIUM 6.5 The The Armania - Fashion, Furniture, Organic, Food Multipurpose Elementor WooCommerce Theme (RTL Supported) theme for W… wordfence
bc5e3932-809c-46d7-bb8d-1dffac9877a4
< 2.53.9
MEDIUM 6.5 The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions wi… wordfence
bc53ad70-d630-4d4a-bcca-79732134e6a6
< 2.76.0
MEDIUM 6.5 The WP-Polls plugin for WordPress is vulnerable to IP Validation Bypass in versions up to, and including, 2.75.6. This i… wordfence
bc3b5faa-1a29-4fa7-9146-d782adce0b1f
< 1.1.6
MEDIUM 6.5 The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulne… wordfence
bc2e883b-fb91-425c-a779-89a34eed2ba8
< 1.3.56
MEDIUM 6.5 The Royal Elementor Addons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check … wordfence
bc045440-a8ca-40d3-b198-421b197e6928
< 2.0.3
MEDIUM 6.5 Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerability in Cloudways Breeze plugin <= 2.0.2 on WordPr… wordfence
bbedad66-a5a6-4fb5-b03e-0ecf9fbef19a
< 3.9.1
MEDIUM 6.5 The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive informati… wordfence
bb5178f4-356b-4352-96ca-500e49006f8a
< 2.1.5
MEDIUM 6.5 The following plugins and themes for WordPress are vulnerable to arbitrary option deletion and user data manipulation: T… wordfence
bb0625ec-5ac9-4896-ac11-87fc9287f68a
< 2.1.10
MEDIUM 6.5 The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direc… wordfence
bb036338-abd7-4061-835d-038b765c68a6
< 6.1.18
MEDIUM 6.5 The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and … wordfence
baff5795-f164-489e-8f57-536174867ec5
< 1.4.17
MEDIUM 6.5 The Open User Map plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.16. Thi… wordfence
bafadafe-4aa5-4349-8a9c-89b21ada47ba MEDIUM 6.5 The WP Bannerize WordPress plugin is vulnerable to authenticated SQL injection via the id parameter found in the ~/Class… wordfence
ba98a282-39ee-4a84-b988-ecfc0c4cd297
< 1.0.114
MEDIUM 6.5 The Brizy - Page Builder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check an… wordfence
b9ed7e26-34f0-4e5d-b560-03b1de9c5c95
< 1.2.0
MEDIUM 6.5 The PS PHPCaptcha pluginfor WordPress is vulnerable to Denial of Service in versions up to, and including, 1.1.0. This i… wordfence
b9cc0348-396e-4be1-92f5-851d20804ef5
< 4.16.3
MEDIUM 6.5 The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to … wordfence
b9c273a3-c8b5-4f00-8daa-76fa486df0f2
< 3.4.3
MEDIUM 6.5 The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery i… wordfence
b99e9fc4-a028-4616-9f6d-aad1972151b0 MEDIUM 6.5 The Private Content plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 8.11.5 due… wordfence
b9860e0e-e330-42fc-8a74-336ceb787f39
< 4.13.2
MEDIUM 6.5 The The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to arbitrary shortcode ex… wordfence
b9502669-ddbb-40c3-9d98-95c862f47a9a
< 2.0
MEDIUM 6.5 The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous par… wordfence
b937940c-a3e0-49d3-b066-550b78351b54
< 1.1.5
MEDIUM 6.5 The WP Fastest Cache plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including,… wordfence
← Prev 440 441 442 443 444 445 446 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top