πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 567 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b0b84c2a-7297-4d96-8fa7-638b2b9953f4
< 0.6.41
MEDIUM 6.4 The YaMaps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `yamap` shortcode par… wordfence
b0b1fbb1-fc2c-4eb9-89c6-364ca8c385db MEDIUM 6.4 The Paypal Payment Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'buttom_image' pa… wordfence
b0ace1a3-81e2-4887-be27-606b49f77357
< 1.0.72
MEDIUM 6.4 The 10WebMapBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in ver… wordfence
b0a5fdb9-4e36-43ce-88ce-cd75bb1d1e25
< 1.0.97
MEDIUM 6.4 The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG Fi… wordfence
b09a3b74-a359-456a-b945-f6173f579e9b
< 1.4.9
MEDIUM 6.4 The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
b0925ceb-581c-4748-abfb-9962e53b7db9 MEDIUM 6.4 The Blogmentor – Blog Layouts for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
b084ba1c-0910-44f0-ad77-41552ec25589
< 0.8.41
MEDIUM 6.4 The Social Like Box and Page by WpDevArt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
b08284ad-717f-4bdb-8eaa-f44e9447ff25
< 2.3.2
MEDIUM 6.4 The WP Accessibility plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'alt' attribute… wordfence
b0781264-ed26-4e4b-a7ab-40e65bc71571
< 3.1.3
MEDIUM 6.4 The Yet Another Stars Rating plugin for WordPress is vulnerable to Cross-Site Scripting via shortcode in versions up to,… wordfence
b0660d9a-9f36-42a6-bffa-15ac1afcfaf3
< 0.6.12
MEDIUM 6.4 The Table Block by Tableberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
b05f4ef4-aa64-4cf4-a278-604df8407d12
< 1.0.2
MEDIUM 6.4 The Affiliate AI Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'asin' shortcode attribu… wordfence
b04aaf8f-c02a-4fa9-a2fc-96c224a3c1ef
< 3.4.5
MEDIUM 6.4 The Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.… wordfence
b03125e6-689b-46d7-8a39-3260d46fb17d MEDIUM 6.4 The FAT Services Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and in… wordfence
b02bdf2a-1d99-4cc3-8f75-822ff0792e44 MEDIUM 6.4 The jQuery Hover Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Footnote Qualifier ('{{… wordfence
b01be0e9-832f-4aa5-a082-b82e0cfe4518 MEDIUM 6.4 The Data Dash plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.… wordfence
b019bd50-eaf3-48f3-a0b3-f730d463ccd2
< 14.0
MEDIUM 6.4 The WP Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
affa8b39-94b8-474d-9310-a93ebdb7c1b8 MEDIUM 6.4 The Elegant Addons for elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widg… wordfence
afec9b5b-da37-4e12-935e-9d3bb3ca01f0
< 2.9.3.1
MEDIUM 6.4 wordfence
afe37170-dc5e-498a-ac6a-4edcfd946897 MEDIUM 6.4 The Easy Social Sharebar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
afe2b2e5-601f-4b6b-940a-b82f723b8776
< 2.9.8
MEDIUM 6.4 The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor… wordfence
afd7fe73-1f24-4e47-a0c4-5a08662c4dbe MEDIUM 6.4 The Smart PopUp Blaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spb-button' … wordfence
afd35195-0f4f-4306-a125-6f81207e10ca
< 1.3.8
MEDIUM 6.4 The Meks Flexible Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
afd2f09c-4bd5-47a5-8d4f-7345aa8925f8 MEDIUM 6.4 The Animated Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animatedcounte… wordfence
afc22a4f-7fb8-428a-974d-e80065a36254 MEDIUM 6.4 The WP Delete User Accounts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
afbf1813-9023-4e3d-989a-19ddd6f6d358
< 2.5.5.3
MEDIUM 6.4 The Beaver Builder – WordPress Page Builder for WordPress is vulnerable to Stored Cross-Site Scripting via the 'captio… wordfence
← Prev 564 565 566 567 568 569 570 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top