🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 564 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b3a3fe11-76cc-4304-91b7-b9bc61f0ff70 MEDIUM 6.4 The Storely theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all version… wordfence
b39e17c5-711f-4229-90f4-213ea65a190d
< 2.2.9
MEDIUM 6.4 The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flickr widget in all versions … wordfence
b399929a-db33-419f-9218-b86ee88a9f1a
< 3.2.47
MEDIUM 6.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter… wordfence
b3992176-1eca-480a-9c80-039346addb7d
< 2.0.4
MEDIUM 6.4 The WP Views Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
b38a69c7-91d4-43be-8650-eb1f0029bd44
< 3.2.32
MEDIUM 6.4 The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
b372ad3a-0056-45fb-9a0e-7604f4fdf240 MEDIUM 6.4 The UMich OIDC Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'umich_oidc_butt… wordfence
b36303d6-ad28-4354-9f60-acc7df15f468
< 5.7.26
MEDIUM 6.4 The Quick Paypal Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s… wordfence
b3621a53-0e31-4245-96c0-08b5f4faf116 MEDIUM 6.4 The RSS in Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.… wordfence
b35e5228-7f1a-43e1-b65d-d13bdd6bcfaf MEDIUM 6.4 The Donation Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, a… wordfence
b3498ebe-5e13-4ced-b92d-4908b8775996
< 4.8.9
MEDIUM 6.4 The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
b34478a9-6eb6-4482-adfe-bd9e770c9a5d MEDIUM 6.4 The Step by Step plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.4… wordfence
b3439710-1159-4677-93c9-14bacfbf0b55
< 1.5.5
MEDIUM 6.4 The WP jQuery Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ attribute i… wordfence
b340eda1-e9d2-40b6-89f9-41d995ce3555
< 3.8.3
MEDIUM 6.4 The EmbedPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedpress_calendar' shortcode… wordfence
b32c1b63-564c-4c38-a149-d5adabda8a8b
< 1.4.19
MEDIUM 6.4 The ViewMedica 9 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'viewmedica' shortco… wordfence
b3247bb3-3d9a-49b5-99ec-f4b305d37ae5
< 2.7.95
MEDIUM 6.4 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file name of the uploaded… wordfence
b3219b17-03b8-44c3-bf35-36b8b7457f8a MEDIUM 6.4 The Best-wp-google-map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'latitude' and 'longitu… wordfence
b31d1d82-d0ee-465c-b56b-381df3b6fcfc
< 1.7.0.1
MEDIUM 6.4 The Kahuna theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.0 due … wordfence
b30261e0-1fa1-4794-98f6-851532b7615c
< 2.25.2
MEDIUM 6.4 The GiveWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.25.1 du… wordfence
b2f3c007-6ecc-4003-87ed-352984b9a83c
< 1.8.3
MEDIUM 6.4 ajax_policy_generator in admin/modules/cli-policy-generator/classes/class-policy-generator-ajax.php in GDPR Cookie Conse… wordfence
b2f16704-6c96-4ff1-b1b1-75c4f16df039
< 3.3
MEDIUM 6.4 The WP Mobile Detector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘websitez_options’ … wordfence
b2ce9854-06df-44a8-b998-de21bf52a5d8
< 1.4.8
MEDIUM 6.4 The Post Category Image With Grid and Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p… wordfence
b2ae4226-0089-47fb-87b9-94e9faf764e4
< 1.0.274
MEDIUM 6.4 The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_bre… wordfence
b2acd36d-013b-4833-95ea-27d6b6db64a0
< 1.2.8
MEDIUM 6.4 The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
b2a537a9-a1db-465e-8e04-2306e0d6998c
< 1.7.4
MEDIUM 6.4 The WP JobSearch WordPress plugin before 1.7.4 did not sanitise or escape multiple of its parameters from the my-resume … wordfence
b2a01ccc-c98e-4fcc-8eaf-721ec46584fc MEDIUM 6.4 The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthoriz… wordfence
← Prev 561 562 563 564 565 566 567 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top