πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 559 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b847f463-2837-4f91-bae6-a8058f36a7db MEDIUM 6.4 The UltraAddons Elementor Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
b8428a92-8b0a-4a9a-8f7e-571c252973c2
< 1.4.9.1
MEDIUM 6.4 The Beaver Themer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all… wordfence
b839c597-5230-4702-b4ac-b4c127d0b6d2
< 1.51.3
MEDIUM 6.4 The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.51… wordfence
b824cab6-d340-487d-90ba-5b554db1da14
< 11.3.2
MEDIUM 6.4 The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Members/Groups block p… wordfence
b805b1d1-7f3f-4bd8-9f88-eced0b2556f8
< 2.2.1
MEDIUM 6.4 The Accessibility Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget settings in versio… wordfence
b7fca965-86f8-4ee4-a9d6-cb18fe5f098e
< 20230902
MEDIUM 6.4 The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes i… wordfence
b7eb185f-3958-4bc4-b904-8f26a71d8953
< 1.4.11
MEDIUM 6.4 The Xpro Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
b7e504ef-9989-468f-9bd0-dd8416f16d85 MEDIUM 6.4 The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size', 'type', and '… wordfence
b7db3bf3-25df-4e16-9aed-dd544a8435d3
< 3.1
MEDIUM 6.4 The Surbma | Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
b7d9a50f-695c-4fed-b472-4a37a1ee7f42
< 2.3.0
MEDIUM 6.4 The Tockify Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
b7d9200b-af1c-4cd2-9d34-eaff97d56967
< 1.3.5
MEDIUM 6.4 The Meks Flexible Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcod… wordfence
b7d84cb9-175f-433c-ab5c-d89621847b4d
< 1.5.79
MEDIUM 6.4 The Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
b7beaa9e-517b-4717-b896-3e37424e27a3
< 6.3.5
MEDIUM 6.4 The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a … wordfence
b7b86b0b-84df-4b58-b50a-d61af6e3c1d3
< 3.6
MEDIUM 6.4 The Classic Addons – WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
b7a07827-74bd-45ef-8035-277c35565d54
< 1.1.3
MEDIUM 6.4 The Bravada theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.2 due… wordfence
b79d5483-eaa3-4fc8-97d1-4c883d4ea480
< 1.7
MEDIUM 6.4 The Woobox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6 due t… wordfence
b79ade88-335b-40ac-a20f-d73823eabbf4 MEDIUM 6.4 The Easy Flash Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
b7926ec6-3441-4062-93b2-6c2120c9f406
< 1.61.0
MEDIUM 6.4 The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteor… wordfence
b77ea258-dced-4c36-bd0d-8977a347d1c9
< 3.0.0
MEDIUM 6.4 The RSS Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rfw-youtube-video… wordfence
b7787311-df2a-4229-b8c5-935b103dfd17
< 1.3.1
MEDIUM 6.4 The Responsive Block Control plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
b76bddf3-96ad-4bb0-a37b-33b451da6713
< 6.5.5
MEDIUM 6.4 The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored C… wordfence
b766971c-c966-4ce1-814d-95efc988cfd9
< 7.1.5
MEDIUM 6.4 The Shortcodes Ultimate Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and… wordfence
b7570c97-4eb7-4614-af8f-1a2a9695de08
< 2.4.7
MEDIUM 6.4 The Free Shipping Bar: Amount Left for Free Shipping for WooCommerce plugin for WordPress is vulnerable to Stored Cross-… wordfence
b72c746a-0975-4acf-bcf3-caddb95b73c3 MEDIUM 6.4 The Sell Media File with Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
b72a26dd-0d20-462e-bb71-ed83eae6766e
< 3.4
MEDIUM 6.4 The WP SVG images WordPress plugin before 3.4 did not sanitise the SVG files uploaded, which could allow low privilege u… wordfence
← Prev 556 557 558 559 560 561 562 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top