🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 561 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b65e3a9f-55b7-458c-81ef-0e29fc8733d9
< 4.0.4
MEDIUM 6.4 The Kama Click Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
b6572733-3b3a-49c5-9ee3-52a7ab61c98d
< 1.1.9
MEDIUM 6.4 The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versio… wordfence
b64b589d-ff37-444b-a040-f4ff80d5a382 MEDIUM 6.4 The Email Address Security by WebEmailProtector plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ver… wordfence
b63f0862-d817-49c6-8ac2-6143d21abc32
< 4.7.1
MEDIUM 6.4 The PDF Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.6… wordfence
b63a8253-b6cc-4cca-baec-4d0e32e1b8d5 MEDIUM 6.4 The WP TradingView plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includin… wordfence
b6306222-8b0c-4060-ade8-f4797d41ebc3
< 1.9.12
MEDIUM 6.4 The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.1… wordfence
b620b10c-0d76-4ecf-9ab9-9bc5f9687a4a
< 2.3.17
MEDIUM 6.4 The Firelight Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
b61eb8b7-0d89-47ef-831c-1772d01e2c85
< 3.10.4
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_meta_… wordfence
b616e275-855d-461e-8fcb-c96098e41dfd
< 2.4.5
MEDIUM 6.4 The Embed PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' and 'width' para… wordfence
b611f3ba-ac36-49fc-a75f-10003c5ca955 MEDIUM 6.4 The Credit Tracker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
b6066883-20e0-440d-9a96-7f4b06c670d2
< 3.7.22
MEDIUM 6.4 Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual edi… wordfence
b5fd4dbe-6f44-45ef-9d49-4bc624fdcc57
< 3.2.26
MEDIUM 6.4 The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
b5fd2163-b8ef-4dd1-a12b-cd9187145134
< 2.7.35
MEDIUM 6.4 The Lightbox & Modal Popup WordPress Plugin – FooBox plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
b5f0dc1a-6b6a-4370-a368-3687cffb43fc
< 2.6.3
MEDIUM 6.4 The Simple Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name' post meta… wordfence
b5f06850-6312-4e87-9b2e-a1421efc91e6
< 1.8.6
MEDIUM 6.4 The Import Social Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
b5e6b059-773a-463f-83c4-28b95bfd6182
< 2.1.5
MEDIUM 6.4 The Instant AI Image Generator – Create & Import Images plugin for WordPress is vulnerable to Server-Side Request Forg… wordfence
b5e64a33-6165-4257-b324-0bbab4129e54
< 3.7.1
MEDIUM 6.4 The affiliate-toolkit – WP Affiliate Plugin with Amazon plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
b5d5fa87-3cac-46ac-b802-dd9acf3f1fd2
< 1.1.7
MEDIUM 6.4 The Directorist AddonsKit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
b5d5d6ec-bb23-4619-b5d9-9bd965b049b5 MEDIUM 6.4 The Qzzr Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qzzr' shortcode in all ver… wordfence
b5c600b4-10d6-4b0b-9ca0-7c629d383d33
< 2.2.1
MEDIUM 6.4 The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
b5bdf526-8378-413f-b51e-24351dd0774b
< 3.5.8
MEDIUM 6.4 The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in… wordfence
b5ab022c-c16c-488b-b004-a7351f8fa3d3
< 1.6.36
MEDIUM 6.4 The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url att… wordfence
b5a24a4a-654c-487e-af68-13db63961896
< 1.0.7
MEDIUM 6.4 The List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all… wordfence
b59ac36c-41b7-46eb-9677-639e45187992
< 3.5.3
MEDIUM 6.4 The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authen… wordfence
b58403df-af09-4d74-88e6-140e3f2f291b MEDIUM 6.4 The Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite plugin for WordPress is vulnerable to Stored… wordfence
← Prev 558 559 560 561 562 563 564 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top