πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 554 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bd84a7b1-76f3-4c01-a935-ffec4a48b61b
< 1.4.47
MEDIUM 6.4 The Open User Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
bd7784dc-c450-4ce2-86ac-adaf9e2b61ad
< 2.7.7.1
MEDIUM 6.4 The JetElements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
bd625d24-c1e9-465d-896a-bff75d8c534f
< 2.6.9
MEDIUM 6.4 The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
bd619c85-4804-4c19-b37b-fdfbd8266760
< 1.3.0
MEDIUM 6.4 The Pie Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2… wordfence
bd581604-e2f6-42c4-81ef-10873683526b MEDIUM 6.4 The kk Youtube Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kkytv' shortcod… wordfence
bd55ce27-7d38-4d55-9b31-5b986edc7f1d MEDIUM 6.4 The amoCRM WebForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
bd3dbc56-4833-4b5d-bd6c-facc3e1878ea
< 2.0.2
MEDIUM 6.4 The Responsive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widge… wordfence
bd38d97d-db93-42ed-9d52-f70641fba442
< 3.1.12
MEDIUM 6.4 The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Full Name field parame… wordfence
bd352c95-6e76-478f-943b-938a96b372f4 MEDIUM 6.4 The Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜hex’ parameter in all v… wordfence
bd28f7f0-ed52-45d0-8d97-5ff95d17eb26
< 1.2.2.11
MEDIUM 6.4 The Easy Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in… wordfence
bd2754f9-11f7-4690-99dd-2204e69bf14b MEDIUM 6.4 The Simple Business Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'simple_business_data' sh… wordfence
bd034f43-370c-4ad9-ad02-4cae0f48d781
< 1.8.3
MEDIUM 6.4 The ITERAS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes (iteras-ordering, i… wordfence
bcf8fa7c-0d9e-41ef-af60-0c33328fc5cc
< 2.7.7.26
MEDIUM 6.4 The Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
bcde42fb-6f61-4174-a44a-bb28e4855062
< 2.1.1
MEDIUM 6.4 The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
bcdbd108-5e17-4e67-a2a2-0f1464c1ba6c
< 5.1.1
MEDIUM 6.4 The MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
bcd9384c-5af3-4544-8179-c2f5550dd152
< 2.1.4
MEDIUM 6.4 The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets … wordfence
bcd6c085-9fd8-43d9-b244-ab91146f610f
< 2.2.8
MEDIUM 6.4 The Enter Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown and Image … wordfence
bcd28bc3-f893-4eb7-946f-34a2e9c7ff27
< 1.6.4
MEDIUM 6.4 The Back Button Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) i… wordfence
bcd25ec7-e594-4261-a743-174ceb130cf5 MEDIUM 6.4 The WPB Image Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
bcbcad73-ce2a-4eb2-9b7f-91d47a93e16d MEDIUM 6.4 The WP Count Down Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the… wordfence
bcbc8ce6-5eb7-4599-b844-72eb2ff3093c MEDIUM 6.4 Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled SimpleLightbox Jav… wordfence
bcad1d05-96a1-4559-9957-fce93c287c07 MEDIUM 6.4 The Events Manager – OpenStreetMaps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
bca16579-d852-4c68-932e-44b69a01b8ce
< 3.2.27
MEDIUM 6.4 The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPre… wordfence
bca0e8a0-d837-42d8-a9d3-35e0c820eb43
< 9.7.7
MEDIUM 6.4 The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'… wordfence
bc684cd2-f01a-4c2d-b979-a47b83d01bd2
< 12.6.6.1
MEDIUM 6.4 The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is … wordfence
← Prev 551 552 553 554 555 556 557 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top