πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 562 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b579dd6a-6bbe-4302-b1d5-6624537f874c MEDIUM 6.4 The Popular Posts by Webline plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
b563f0a0-4d9e-4b6c-baeb-437f9c48b557 MEDIUM 6.4 The Allegiant theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.7 d… wordfence
b55722f9-a0b9-4484-bd3b-c21dbe5716ee
< 7.0
MEDIUM 6.4 The Enfold theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.9 … wordfence
b54fa719-0ac2-4017-b312-4b4a9bced16d
< 3.2.5
MEDIUM 6.4 The Blockspare plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.4… wordfence
b5451529-2e3f-414e-884e-cc6761431262
< 4.0.6
MEDIUM 6.4 The Eventin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.5 du… wordfence
b54307fb-ecbc-4742-9deb-59dbb85b4a7c
< 3.79150
MEDIUM 6.4 The WordPress.com Editing Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up t… wordfence
b507462d-1ce2-4463-93bf-635ee78274f6
< 2.8.4
MEDIUM 6.4 The WaveSurfer-WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's audio shortcode in … wordfence
b4fe5d61-2607-48a1-938b-f008c18c7c81 MEDIUM 6.4 The Simple Vertical Timeline plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
b4f77508-b1e6-4a13-b384-f086ec64fe85
< 1.5.3
MEDIUM 6.4 The Easy Table plugin for WordPress is vulnerable to Cross-Site Scripting via easy-table-test-area parameter in versions… wordfence
b4e812f2-78f2-4dde-96ec-2ee114ebaa60
< 1.10.4
MEDIUM 6.4 The Geo Mashup plugin before 1.10.4 for WordPress has insufficient sanitization of post editor and other user input. wordfence
b4e7786c-a447-4a77-9f66-702db53773dc
< 6.3.0
MEDIUM 6.4 The PDF for Elementor Forms + Drag And Drop Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
b4e1fe83-678f-4368-9810-16d9cd50b15c
< 1.4.9
MEDIUM 6.4 The Store Locator WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode… wordfence
b4e0df34-1947-4b63-a489-83d9d3f1e7ca
< 4.2.2
MEDIUM 6.4 The Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.… wordfence
b4dfeb49-38d3-495d-af96-d67a29b339fa
< 2.16.2
MEDIUM 6.4 The Popup Builder by OptinMonster – WordPress Popups for Optins, Email Newsletters and Lead Generation plugin for Word… wordfence
b4da6327-9ad1-4a53-b2c4-a4c31f56d0e5
< 0.3.6
MEDIUM 6.4 The Pliska theme for WordPress is vulnerable to Stored Cross-Site Scripting via author display names in all versions up … wordfence
b4c9b125-4cea-448b-8b31-c033857346b3
< 2.9.5.5
MEDIUM 6.4 The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.5… wordfence
b4c35e6a-a1f4-49f1-8024-6abb2486b5e8
< 1.3.3
MEDIUM 6.4 The Charity Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
b4c17377-a634-47ad-828b-2ed1f3b188f0
< 5.5.2
MEDIUM 6.4 The Meow Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5… wordfence
b4c13600-0791-4ade-9c28-f43f164aedae
< 2.3.4
MEDIUM 6.4 The Click to Chat – WP Support All-in-One Floating Widget plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
b4c06548-238d-4b75-8f20-d7de6fc21539
< 2.11.1
MEDIUM 6.4 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… wordfence
b4b6cbb5-d82d-4035-b0c8-5c1aaee31993
< 2.3.0
MEDIUM 6.4 The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpsl_address' post meta … wordfence
b4aebb45-b47b-4b5a-8281-400a4b786689 MEDIUM 6.4 The WM JqMath plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' shortcode attribute of t… wordfence
b4aa1dce-de3d-4049-a24d-cadb59912ad1
< 2.38
MEDIUM 6.4 The Simple Blog Card plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includ… wordfence
b4a82562-1368-4071-bedf-8a84d82e88ef
< 0.8
MEDIUM 6.4 The Qyrr – simply and modern QR-Code creation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
b49d166f-4df0-4997-a078-0be8fcd92576
< 4.10.32
MEDIUM 6.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fanc… wordfence
← Prev 559 560 561 562 563 564 565 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top