πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 444 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b930ddd7-a2a3-4b83-a1a6-ea08bbcb07a3
< 8.0.4
MEDIUM 6.5 The Quick Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
b919f11b-c57f-4511-8fd6-9e83d2855266
< 1.2.0.4
MEDIUM 6.5 The The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to arbitrary shortcode exec… wordfence
b907400c-4d90-4f53-b800-f82f6c4768ba MEDIUM 6.5 The Lead Capturing Pages plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5 due t… wordfence
b8f55759-78d5-4c90-87b9-934a4f4d9365 MEDIUM 6.5 The CountDown With Image or Video Background plugin for WordPress is vulnerable to SQL Injection in versions up to, and … wordfence
b8d4c4d2-1d86-4ee2-9ac1-240ed2aa7f72 MEDIUM 6.5 The Sliced Invoices – WordPress Invoice Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, … wordfence
b899ca76-d6f4-4369-8f66-738b144433b7
< 4.2.3
MEDIUM 6.5 The Analytify plugin for WordPress is vulnerable to authorization bypass due to a missing capability and nonce checks on… wordfence
b882ba6d-47c0-401a-bf50-5cf0bf0f3d5b MEDIUM 6.5 The Accessibility Suite by Ability, Inc plugin for WordPress is vulnerable to SQL Injection via the 'scan_id' parameter … wordfence
b87f8bd6-d00d-4062-bf27-b698a1d7e757
< 1.4.6
MEDIUM 6.5 The Protected Posts Logout Button plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing c… wordfence
b86d26e7-5879-444d-b191-6332de46428a MEDIUM 6.5 The Events Schedule - WordPress Events Calendar plugin for WordPress is vulnerable to SQL Injection in versions up to, a… wordfence
b8464cd2-eef0-419b-b368-6f86af4e8dd5
< 2.4.4
MEDIUM 6.5 The myCred WordPress plugin before 2.4.4 does not have any authorisation and CSRF checks in the mycred-tools-import-expo… wordfence
b81c8bca-ba80-4beb-aa51-6505c76a424e MEDIUM 6.5 The Vertical scroll slideshow gallery v2 plugin for WordPress is vulnerable to SQL Injection in versions up to, and incl… wordfence
b7fb23e8-dabb-4d6e-a2b2-2b27d6a38b3c
< 1.1.0
MEDIUM 6.5 The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to unauthorized access in all versions up to, and incl… wordfence
b7f6436f-60b7-4b9b-a071-93a5b95a9075
< 1.6.9.29
MEDIUM 6.5 The Simply Schedule Appointments plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1… wordfence
b7c7e45a-581e-4cf0-83ac-cbca816701f1
< 4.2.1
MEDIUM 6.5 The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This … wordfence
b7c37c4e-7a01-447c-a1d5-595c2012eb8c
< 5.1
MEDIUM 6.5 The Tooltipy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.0. Thi… wordfence
b7ac9097-b02b-4f0a-8bc3-6c6af0bdab89
< 1.3.37
MEDIUM 6.5 The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the … wordfence
b78985ad-37e5-4eb3-b3aa-716972423848
< 1.8.1
MEDIUM 6.5 The Fluent Support plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.8.0 due to in… wordfence
b7413d90-aed1-4f78-a17c-bed76efb48f8
< 2.2.18
MEDIUM 6.5 The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'addNotify' a… wordfence
b7112840-f190-4867-9408-c96408f28b7a
< 8.4.6
MEDIUM 6.5 The The Simple Link Directory plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to,… wordfence
b6c82a71-3a67-4716-9a50-d0d32e2f465d
< 10.1.4
MEDIUM 6.5 The WP Travel plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 10.1.3 due to insuff… wordfence
b6986569-a273-4aea-bc74-ef7277781661
< 5.3.9
MEDIUM 6.5 The et-core-plugin plugin for WordPress is vulnerable to arbitrary file downloads in all versions up to, and including, … wordfence
b65acc28-1f4c-47c1-a6cc-dedef58c2e3e
< 2.23
MEDIUM 6.5 The ArtPlacer Widget plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.22.9.2 due … wordfence
b64fc9d8-ea02-49e7-add1-8d83f0f41431
< 1.5.3
MEDIUM 6.5 Bit Assist plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜id’ parameter in all versions up … wordfence
b5ef3a8e-9027-4d65-a694-a7a3f4327e35 MEDIUM 6.5 The Navigation Tree Elementor plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, … wordfence
b53bccdd-ed92-4831-bc63-3b96c9aee6e2 MEDIUM 6.5 The Simple Image Manipulator plugin for WordPress is vulnerable to Remote File Download in versions up to, and including… wordfence
← Prev 441 442 443 444 445 446 447 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top