πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 558 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b964df21-5648-4fe1-b2a7-99f8a0f02026
< 2.10.3
MEDIUM 6.4 Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post. There were no che… wordfence
b95c1bf7-bb05-44d3-a185-7e38e62b7201
< 1.5.4
MEDIUM 6.4 The Blog Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'AWL-BlogFilter' shortcode in vers… wordfence
b95baf58-bd99-4682-b2eb-46a402c62c03
< 2.7.3
MEDIUM 6.4 The Full frame theme for WordPress is vulnerable to Stored Cross-Site Scripting parameter in versions up to, and includi… wordfence
b957eb0d-882d-4646-ad84-9c64f957be14
< 1.7.1021
MEDIUM 6.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜_e… wordfence
b94f388a-c4af-4d3a-bd41-9b2d5d990672 MEDIUM 6.4 The Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin plugin for WordPress is vulnerable to Store… wordfence
b937cbfb-d43c-4cda-b247-921661cbc0ad
< 2.0.32
MEDIUM 6.4 The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Newsletter widg… wordfence
b93214ec-5738-4f10-b48c-1d74aad52acb MEDIUM 6.4 The AI Content Pipelines plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all v… wordfence
b913ad87-4d49-4cb6-82f4-5d953cbabd96
< 4.1.0
MEDIUM 6.4 The Kama Click Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
b91364fa-7046-427f-84ee-6a36d49bb80f
< 2.2.14
MEDIUM 6.4 The BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library plugi… wordfence
b90c1a07-2a6d-4c9c-a2a7-e515a1556163 MEDIUM 6.4 The WP Visual Sitemap plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
b90267c6-e6b4-4ca0-8779-c20f62016eeb
< 1.6.0
MEDIUM 6.4 The VDZ Google Analytics or Google Tag Manager / GTM plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
b8fbede5-95b5-4630-bc7f-f24fddf006ec
< 4.0.25
MEDIUM 6.4 The WordPress Event Manager, Event Calendar and Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site S… wordfence
b8e921f4-d889-490f-a817-53d132a56f83
< 3.23.5
MEDIUM 6.4 The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,… wordfence
b8d399f3-5517-4c5d-b792-94eb8b0cc0f4
< 2.0.7.3
MEDIUM 6.4 The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin fo… wordfence
b8c89d80-0ae5-4849-b739-0881fec188bf MEDIUM 6.4 The Schema Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `itemscope` shor… wordfence
b8c87463-76fe-4687-92c2-4bcdbdaf374f MEDIUM 6.4 The Beacon For Help Scout plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
b8c7cca2-94d2-4a86-bc69-d7b2b0f068ba
< 1.2.8
MEDIUM 6.4 The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the broken preg_rep… wordfence
b8ad763e-838a-483d-b080-f956a229188c
< 2.1.7
MEDIUM 6.4 The Cozy Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.… wordfence
b899d06f-a4e3-4cc5-a610-43372511b7da
< 3.3.1
MEDIUM 6.4 The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all version… wordfence
b897b16a-7580-47e2-a5cc-b4a08bc05ad2 MEDIUM 6.4 The Septera theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.1 due… wordfence
b865df96-335c-4856-a5e5-e728fb0645d3 MEDIUM 6.4 The Masy Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'justified-gallery' … wordfence
b85b314d-a155-4cec-95c9-0db4b9d8e59b
< 1.2.0
MEDIUM 6.4 The Lottie Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up … wordfence
b857e64c-a345-4ed3-b690-5b9d1a0cae15
< 2.6.31
MEDIUM 6.4 The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
b84d88af-62b7-4f82-94c6-24c1513bfd57
< 2.4.32
MEDIUM 6.4 The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Head… wordfence
b84b5bc9-27eb-40b0-abe4-42959b033afb MEDIUM 6.4 The X Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
← Prev 555 556 557 558 559 560 561 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top