🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 566 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b1acaf41-76b1-40d7-af6d-d512234986f6 MEDIUM 6.4 The Video Gallery – Vimeo and YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ver… wordfence
b1a9a274-fc42-4fca-a4f1-aa2834aa748d MEDIUM 6.4 The Audiomack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.8 … wordfence
b1a97776-03c7-403d-b803-023647b9d0f2
< 2.6.6
MEDIUM 6.4 The Auto Listings – Car Listings & Car Dealership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cr… wordfence
b1954340-397c-4cc0-ba9d-d698d94ea608 MEDIUM 6.4 The Mediabay – Media Library Folders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown … wordfence
b18f6817-86db-4a72-a2e9-a9e047e05bc5
< 1.0.4
MEDIUM 6.4 The WP Post List Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpb_post_list… wordfence
b1886db3-e01d-4cb1-8134-8cddff6503ac
< 1.1.2
MEDIUM 6.4 The isMobile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘device’ parameter in all ver… wordfence
b17b522d-997f-443e-a39f-2da0ebf14aaa
< 1.9.4
MEDIUM 6.4 The Apollo13 Framework Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
b174204a-30d3-406c-a405-1670bcdab39d MEDIUM 6.4 The Mighty Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
b1623bef-09c8-43e0-a6a1-f5b9aa3ba7eb
< 2.11.10
MEDIUM 6.4 The Football Pool plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'answer' parameter in versio… wordfence
b1541aaf-9f35-44b5-a985-1b8d33228f0a
< 2.1.16
MEDIUM 6.4 The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp-crowdfunding/search blo… wordfence
b148926d-090d-4fab-991c-89105078a263 MEDIUM 6.4 The Multiple Post Type Order plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mpto' s… wordfence
b139260b-7741-4e35-b23f-896f23719739
< 2.6.7
MEDIUM 6.4 The Spectra plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 2.6.6 vi… wordfence
b133888c-7673-4796-917c-486bff1b6b12
< 2.20.02.27
MEDIUM 6.4 The Async JavaScript plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
b1305be5-8267-475f-b962-62e3930116e1
< 3.25.8
MEDIUM 6.4 The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
b120d99e-5906-4c7f-b10a-1f915a8ff6d6
< 2.0.1
MEDIUM 6.4 The B Blocks - The ultimate block collection plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
b117d77b-2c11-451c-b236-b55e8af68a9a MEDIUM 6.4 The Easy GitHub Gist Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter… wordfence
b1146350-4491-4fa0-8b78-6dbc00903160
< 3.7.12
MEDIUM 6.4 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Stored C… wordfence
b111bfd5-3eff-4255-9123-cae38bfb73c3
< 3.5.44
MEDIUM 6.4 The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slid… wordfence
b10333f8-fd90-43a7-8404-71954ee29e47
< 3.8.6
MEDIUM 6.4 The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ para… wordfence
b0f2c7f0-ff24-4489-9fb4-8a98ac6dc09a
< 1.21.0
MEDIUM 6.4 The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple fields in versions up… wordfence
b0eedeba-cdff-4e84-8182-1bebf48c76e0
< 1.9.2
MEDIUM 6.4 The Cloak Front End Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes … wordfence
b0ea041b-f09d-4c62-aada-26afbc60b6f2
< 2.3.3
MEDIUM 6.4 The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
b0e35280-0c2a-4fe1-bfbe-3321338ff1a5 MEDIUM 6.4 The Ultimate Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's b… wordfence
b0cf3015-cdc9-4ac9-82f3-e9b4d1203e22 MEDIUM 6.4 The JQuery Accordion Menu Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dcwp-jquery-acco… wordfence
b0ce06d3-491e-4565-8b26-f33937aee3e8
< 1.6.9
MEDIUM 6.4 The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'all-items' sh… wordfence
← Prev 563 564 565 566 567 568 569 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top