🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 560 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b721bbe2-22ef-48b5-9acc-a8e868fbeff3
< 2.4.5
MEDIUM 6.4 The All Currencies for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
b710538a-e9b2-4c3e-a4de-84685df302ee MEDIUM 6.4 The BWD Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
b70b04bc-8c33-4108-afed-3fcf74e9e948
< 3.9.2
MEDIUM 6.4 The wp-mpdf plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.9.1 du… wordfence
b7084498-2918-4cb4-856e-aec818de79b7
< 1.9.14
MEDIUM 6.4 The Accordion Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
b702f507-475a-4d45-8bb1-635f5f377c88 MEDIUM 6.4 The Custom Post Type List Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's s… wordfence
b6fe2905-c667-4e10-89d6-387eb233f33b MEDIUM 6.4 The Download Button for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
b6eea36b-e80a-4b21-8997-d828cc8da6a3
< 1.52.2
MEDIUM 6.4 The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.52… wordfence
b6e3fb4d-985f-4fb7-bcf1-523792d8dac6
< 7.3.5
MEDIUM 6.4 The Quiz And Survey Master plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in v… wordfence
b6e106a7-2b7d-4d9d-aa0a-01e6a2b1a88b
< 4.5.7
MEDIUM 6.4 The WooCommerce Fortnox Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
b6e02a2b-9033-4022-a7d7-1c81a7f02f83
< 3.27
MEDIUM 6.4 The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mla_tag_c… wordfence
b6d874a2-f0cd-49d2-b531-5d780db7d25d
< 6.4
MEDIUM 6.4 The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulner… wordfence
b6d8212d-7e72-487d-a4e8-0582fa72f602
< 2.8.2
MEDIUM 6.4 The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor… wordfence
b6bbd7bd-e787-41aa-a4b2-004eaba07f50
< 2.4.5
MEDIUM 6.4 The WP Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2… wordfence
b6ba3ce1-7c50-4e9d-b9e0-bcefc9ca74fe
< 2.6.9.1
MEDIUM 6.4 The Exclusive Addons Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
b6ad38a3-adb1-4c82-8e8c-f5883ba0f10e
< 6.8.2505.01
MEDIUM 6.4 The CarDealerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘saleclass' parameter in … wordfence
b6a54d91-da79-43a3-affd-e8026e342d95
< 1.2.5.8
MEDIUM 6.4 The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
b6a228f6-5c72-4c26-8b02-61158b96bd8e
< 3.7.1
MEDIUM 6.4 The Cost of Goods for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
b69a79cf-d838-4a82-acfa-c1c6f82cc931
< 1.27.9
MEDIUM 6.4 The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Server-Side … wordfence
b6851bb9-f15a-4d37-8a15-f4677bd5d62e
< 4.1.0
MEDIUM 6.4 The EmbedPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.1… wordfence
b6840637-9b0f-4f3d-bb73-9e4527a5f326
< 1.5.4
MEDIUM 6.4 The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable… wordfence
b66faf40-94d1-4972-a518-9baca69e7af8
< 2.0.19
MEDIUM 6.4 The jAlbum Bridge plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
b66bb56c-4953-473c-b1cc-c843447d8d76 MEDIUM 6.4 The WP PagSeguro Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
b66ab7c4-7963-424f-afec-0e52b987c6b3 MEDIUM 6.4 The Paypal Donation Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortco… wordfence
b665be9b-51e2-4ed8-9ebd-5180ae5350f1 MEDIUM 6.4 The Bulk Me Now! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmn' shortcode in a… wordfence
b66540ec-7a01-431c-a8bf-dbced505bf1e
< 1.4.2
MEDIUM 6.4 The Podcast Subscribe Buttons WordPress plugin before 1.4.2 allows users with any role capable of editing or adding post… wordfence
← Prev 557 558 559 560 561 562 563 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top