🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 563 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b495d7e4-09fd-4e38-9912-bed3f6a7a745 MEDIUM 6.4 The Embed Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
b4905ca1-3096-45c5-838b-1237888fb969 MEDIUM 6.4 The WP Flot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linechart' shortcode in … wordfence
b48df04d-1f96-44fb-96d7-122597da2efa MEDIUM 6.4 The Themedy Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
b4827732-41ff-4a14-bb5e-4f7888ffd733 MEDIUM 6.4 The GHActivity plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.0… wordfence
b478d88d-1423-4a33-b8ef-08b9e66a5d98
< 3.2.94
MEDIUM 6.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_logi… wordfence
b47505a5-fb7f-4e41-a6de-6f0b330aa495
< 1.0.6
MEDIUM 6.4 The Mini Course Generator | Embed mini-courses and interactive content plugin for WordPress is vulnerable to Stored Cros… wordfence
b4737bb2-1bb4-4986-9df5-5978fc46f2ec MEDIUM 6.4 The Theron Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the … wordfence
b46e9771-37ff-4825-9af9-02ecde424653 MEDIUM 6.4 The WP Radio – Worldwide Online Radio Stations Directory for WordPress plugin for WordPress is vulnerable to unauthori… wordfence
b46c3f25-6879-47b1-9026-4297fdd003b0
< 5.3.6
MEDIUM 6.4 The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first and last name fields in… wordfence
b4603b58-0972-4e04-91ac-ffc846964722
< 2.10.31
MEDIUM 6.4 The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form widget addr2_w… wordfence
b4540b21-ef63-4cd2-b605-c66a7b76934f MEDIUM 6.4 The 소셜 공유 버튼 By 코스모스팜 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… wordfence
b44ef21f-464e-487a-ba5a-fe889e4c488c
< 3.16.5
MEDIUM 6.4 The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the get_inline_svg()… wordfence
b44b3cf5-a976-407f-b23b-4b7448a18263 MEDIUM 6.4 The Typing Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.… wordfence
b43a61f4-2d1c-47ce-ae0d-a5969bdb43f1 MEDIUM 6.4 The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
b4347123-83a9-46be-9216-759906531d73 MEDIUM 6.4 The User Specific Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
b421d80f-408e-4fb0-9894-b7e5707d8d5f
< 1.3.7
MEDIUM 6.4 The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
b40a40d1-d12f-4fe6-b155-83a1f1a5a494
< 2.19.1
MEDIUM 6.4 The Seriously Simple Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versi… wordfence
b406f0b8-16b5-49ca-88d8-7717bef1ae61
< 3.3.2
MEDIUM 6.4 The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress… wordfence
b3e95dc2-0f50-4009-9cc0-a02f9977ce58 MEDIUM 6.4 The VI: Include Post By plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_container' attr… wordfence
b3db2be5-a9d2-4bc0-a8cf-d67da024c0e6 MEDIUM 6.4 The 3D Presentation plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
b3c84ad1-10c7-4b2f-82f3-7546fc8e337d MEDIUM 6.4 The Map My Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'map_my_location… wordfence
b3bae191-9395-481c-93bf-b17cf5f87271
< 1.1.9.1
MEDIUM 6.4 The Chained Quiz for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘chained_admin_subject', 'chained_… wordfence
b3b40b73-4dec-4a96-a634-3bd3d74616ba
< 1.3.2
MEDIUM 6.4 The WordPress Book Plugin for Displaying Books in Grid, Flip, Slider, Popup Layout and more plugin for WordPress is vuln… wordfence
b3ae99bb-03c3-4869-9314-0dbd76ca25c0
< 3.0.7
MEDIUM 6.4 The ElementsKit Elementor addons Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
b3aa7b27-a335-4f82-a50a-45becdd5ef4e
< 5.16.5
MEDIUM 6.4 Unvalidated input and lack of output encoding in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.… wordfence
← Prev 560 561 562 563 564 565 566 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top