ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 565 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b29f0fea-a2db-4b2e-b7b8-d15b2395e9e6
< 5.0.0
MEDIUM 6.4 The IndieWeb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Telephone' parameter in all vers… wordfence
b2992b29-5f48-4389-ae27-6cb6b54d2ba5 MEDIUM 6.4 The Form to Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
b297a6f3-7743-4b86-bd72-93ea0cd85bfa
< 7.8
MEDIUM 6.4 The SEOPress – On-site SEO plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 7… wordfence
b28ad91f-40fa-476e-b41f-da4dd2372e21
< 5.6.9
MEDIUM 6.4 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the … wordfence
b2839fdc-5904-4c3b-894f-7bf7e8b2986a
< 1.8.2
MEDIUM 6.4 The Campaign URL Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s)… wordfence
b27ecbf7-e97d-42c0-98d4-c235edf40669 MEDIUM 6.4 The Multi Post Carousel by Category plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slides' s… wordfence
b27c7002-985c-4de9-b46a-440adf2a1662 MEDIUM 6.4 The Sudoku Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
b276b1f7-e618-491f-beb4-675228632fa0
< 1.4.0
MEDIUM 6.4 The Product Subtitle for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmlTa… wordfence
b27201c7-453b-4953-b364-42ca7bf012f0
< 3.1.7
MEDIUM 6.4 The MailMunch – Grow your Email List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'… wordfence
b2683b4e-b993-4c84-b7cc-a2cb511b4097
< 1.1.4
MEDIUM 6.4 The Gutentools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Slider block's block_id at… wordfence
b25f939c-1dfe-4d4f-a27a-1f9022da6965
< 1.9.4
MEDIUM 6.4 The Simple Logo Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in… wordfence
b25c27ee-0d50-4b1e-ac07-469c99e601d1
< 1.1.9
MEDIUM 6.4 The Hester Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.… wordfence
b258fa40-4e76-4c84-b32f-e6c46fee770a
< 2.11.9
MEDIUM 6.4 The Tourfic plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.11.8 d… wordfence
b258b76c-abb1-413e-a7b9-b9b0b71c1f82
< 3.20.0.2
MEDIUM 6.4 The Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.19.4 du… wordfence
b252e2a7-f037-43a1-828f-10b3172548cd MEDIUM 6.4 The Sheet2Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.1… wordfence
b21f9cfa-8113-42bc-a9dc-4d891bd9821b
< 1.41
MEDIUM 6.4 The igumbi Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'igumbi_cal… wordfence
b20e0787-4514-475f-9ed2-a63857ee59a1 MEDIUM 6.4 The WP Agenda plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0 du… wordfence
b20a11c1-9aa0-4f5d-af3d-89fb9bf4e1d0 MEDIUM 6.4 wordfence
b1f482d3-d2f6-4161-8bcf-3d43d5ac10ee
< 1.3.3.1
MEDIUM 6.4 The WordPress Meta Data and Taxonomies Filter (MDTF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting i… wordfence
b1ed1ef4-8867-499b-8f73-296280573462 MEDIUM 6.4 The Steel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn shortcode in all versio… wordfence
b1ec9dce-d0fb-4b7b-a8e4-4ccb474c9d57 MEDIUM 6.4 The Frictionless plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'frictionless_form' … wordfence
b1eb6896-2de3-4d4d-9b5f-253aaffd193b
< 5.0.13
MEDIUM 6.4 The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SV… wordfence
b1c44ad9-e61e-4f29-9c0b-7c0a89b0c8da
< 3.1.0
MEDIUM 6.4 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown wid… wordfence
b1b3edcf-c089-4bb8-b1e8-05e00abca1a5
< 2.9.9
MEDIUM 6.4 The Paid Memberships Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s)… wordfence
b1acc5f8-bd77-42e0-96d5-636039a533a1
< 1.2.0
MEDIUM 6.4 The Dino Game – Embed Google Chrome Dinosaur Game in WordPress plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
← Prev 562 563 564 565 566 567 568 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top