🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,942
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 21, 2026
Last Updated

39,942 vulnerabilities found (page 728 of 1598)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1bcb9ba1-63f9-4de9-b1da-405231cd1d14
< 1.0.8.2
MEDIUM 6.4 The EO4WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.8.1 du… wordfence
1bc697b3-20f6-46df-a250-f2009a60200e
< 9.97.0.0
MEDIUM 6.4 The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the child page in… wordfence
1bc6508b-f646-4d52-bc8d-bdac443ed2fe MEDIUM 6.4 The Wpik WordPress Basic Ajax Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dname' par… wordfence
1bc0aa64-57a6-44ef-974a-70991cc3820f
< 3.7.32
MEDIUM 6.4 wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing… wordfence
1bbba961-a1e6-440a-9b39-919363f7031d
< 2.5
MEDIUM 6.4 The WP Portfolio theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4 … wordfence
1bb58556-29be-4272-85fc-bb2b7c72abf4 MEDIUM 6.4 The Debt.com Business in a Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configuration'… wordfence
1bae6d3a-40eb-4af6-be4e-9bc6be1a4b07
< 7.0.5
MEDIUM 6.4 The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
1baa93da-9b55-45e7-b9a9-db331b5d0584
< 3.3
MEDIUM 6.4 The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortcode in versions… wordfence
1b902d46-ff27-486f-836d-f55a8048f08c
< 1.0.44
MEDIUM 6.4 The Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishlist_button' shortc… wordfence
1b87fe3d-a88d-477a-8d91-4d7c2dba4a43
< 2.6.9.1
MEDIUM 6.4 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute … wordfence
1b80f389-19f9-49a5-aab8-3096838ccfe5
< 2.2
MEDIUM 6.4 The WPB Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
1b75da76-1a58-4f8e-9b4f-d2e40d09f9ea
< 4.4.0.1
MEDIUM 6.4 The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise… wordfence
1b73402b-444c-47ad-9c05-7be6e6440123
< 5.5.5
MEDIUM 6.4 The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the p… wordfence
1b57cbaa-8a5f-4a00-9c77-6b187c416594
< 1.5.1
MEDIUM 6.4 The Audio Album plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.… wordfence
1b3948ef-11be-450d-ad20-e4bebc16e790
< 2.9.30
MEDIUM 6.4 The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet plugin for WordPress is vu… wordfence
1b38e7ec-6663-4253-9c60-61ed34be22c1
< 1.5.15
MEDIUM 6.4 The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s… wordfence
1b34a4aa-bcaa-4be5-a059-6f2efa3a8198
< 4.0.7
MEDIUM 6.4 The Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tabs_color value in all ve… wordfence
1af8d91a-f87f-42d4-b277-d4372d580ca0 MEDIUM 6.4 The TinyCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.1 d… wordfence
1aedd621-73e0-46e0-8d25-3511e01d7a4e MEDIUM 6.4 The EzyOnlineBookings Online Booking System Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
1aeafeec-7202-4ee6-b724-8dcf98591294 MEDIUM 6.4 The Control horas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ch_registro' short… wordfence
1aea8fe3-7c75-4d3a-847a-ce0d1f9700f1 MEDIUM 6.4 The Button Builder – Buttons X plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the btnsx shortco… wordfence
1ada39db-b316-4270-ac9c-3770b473d6a8
< 6.1.0
MEDIUM 6.4 The Bible SuperSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘selector_height’ pa… wordfence
1ac6422f-0bb1-4586-adbb-71b04b2a8e63 MEDIUM 6.4 The WP Vegas plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2 due… wordfence
1ac58649-4c1a-4c2c-a94b-a3cf08ecb4df
< 2.1.7
MEDIUM 6.4 The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field. wordfence
1ac42a0f-19e9-4ce2-9708-d7aff1609c47 MEDIUM 6.4 The Attendance Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
← Prev 725 726 727 728 729 730 731 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top