🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 556 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bb4f8066-1185-41c7-a901-6c585fea0499 MEDIUM 6.4 The EZ InLinkz linkup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
bb41862a-0cde-46f0-bd86-5a04e76f7345
< 17.0.34
MEDIUM 6.4 The Multi-column Tag Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mctagmap sho… wordfence
bb3b0a0e-9f2a-47b1-b2ba-7bb96e581e26
< 1.1.33
MEDIUM 6.4 The Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including… wordfence
bb386ab5-1fb9-4649-99a6-0e3f971a02f8 MEDIUM 6.4 The Accordion Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'accordion_… wordfence
bb36fd27-bcea-481c-a7aa-815dc684ed8b MEDIUM 6.4 The wp-twitpic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'twitpic… wordfence
bb302539-97e7-4b2c-865d-bd81919647ae
< 3.1.3
MEDIUM 6.4 The The Events Calendar Shortcode & Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
bb2a67ff-a452-4ecb-9fd7-bf05fe43a2f7
< 6.23.0
MEDIUM 6.4 The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Cross-Site Scripting in versions u… wordfence
bb27da72-ba3e-4578-9b2b-c716019c20ed MEDIUM 6.4 The AwesomePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0… wordfence
bb228bda-5094-4e54-a197-3b66376e2216
< 1.6.5
MEDIUM 6.4 The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter i… wordfence
bb1b93ee-8641-4ddb-8b6b-2e9d30fe338d
< 1.69.0
MEDIUM 6.4 The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-url` DOM E… wordfence
bb0dca75-af56-404f-856c-41edd76b72a1
< 1.3.2
MEDIUM 6.4 The Charity Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
bb0888d6-30e6-4957-b270-1968eace462e
< 1.13
MEDIUM 6.4 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'icon_align' attr… wordfence
bb06d1ac-e436-40ec-8d3f-f336fcb3e3ec MEDIUM 6.4 The Advanced Video Player with Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
baf55ce7-8a33-426c-a6a4-158a95a13a5c
< 2.0.0
MEDIUM 6.4 The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includi… wordfence
baf138c1-44ab-4ebf-8963-4ce807a16f40
< 1.6
MEDIUM 6.4 The Bicycleshop theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5 d… wordfence
baf12413-eb45-44c3-a6c9-f5a048d6500d
< 6.8
MEDIUM 6.4 The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘successredirect’ parameter i… wordfence
baee7e34-0ed0-4702-9ccc-94177b6284c3 MEDIUM 6.4 The Sidebar Widgets by CodeLights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in ver… wordfence
bada73df-8dfb-4f88-a623-cf98173b25c8
< 1.2.11
MEDIUM 6.4 The Post Layouts for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
babc2e50-27a5-413b-8611-0e9e9db33deb MEDIUM 6.4 The Voltax Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in … wordfence
bab22f2e-0998-4401-ae9f-45bdce658c4f
< 1.3.2
MEDIUM 6.4 The Bandsintown Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bandsintown_e… wordfence
baad17ba-4ea0-44d7-8665-91d7fc63678f MEDIUM 6.4 The Weaver Themes Shortcode Compatibility plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
baa92aee-a0a0-45d4-aa12-1449a829930c
< 5.9.12
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
baa15567-78cd-40ac-99ac-c1ad77914420
< 2.0.7
MEDIUM 6.4 The Responsive Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
ba965a6a-68ed-4383-93a7-593418df34a5
< 2.15.16
MEDIUM 6.4 The Spoki – Chat Buttons and WooCommerce Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
ba8625eb-b710-4dd5-b08f-d212e2fd9013
< 1.7.02
MEDIUM 6.4 The Gallery - Video Gallery and YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via u… wordfence
← Prev 553 554 555 556 557 558 559 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top