🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 829 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bfb63667-6a47-4308-83c5-3d763ea69e13 MEDIUM 6.1 The Content Syndication Toolkit Reader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … wordfence
bfb329da-00df-4178-ad40-9b0b718dc30e
< 1.04
MEDIUM 6.1 The Add Custom Post Type into Post Query plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in version… wordfence
bf90d284-9db8-464b-ae01-f1979408b351
< 2.9.50
MEDIUM 6.1 The WordPress Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting parameter in version… wordfence
bf852d93-6d56-46a2-aebc-b222b1b73fb1
< 1.9.17
MEDIUM 6.1 The GD Star Rating plugin for WordPress is vulnerable to Cross-Site Scripting via the 'tpl_section' parameter in version… wordfence
bf808fec-8d84-43ab-85bc-b3b60ab4df31
< 2.0.0
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in check.php in the Validated plugin 1.0.2 and earlier for WordPress allows rem… wordfence
bf4cb79e-e62b-4991-8ee5-493dafe38b80
< 3.1.78
MEDIUM 6.1 The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerab… wordfence
bf3b9e43-ca89-4931-950c-b73a0bac81b8 MEDIUM 6.1 The WP Mail Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
bf391432-d569-4458-947f-fe4a2ebcf8f1
< 0.5.2
MEDIUM 6.1 The Formula theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in the 'quali… wordfence
bf356066-fb25-4f6a-8600-91c7f1d098bf
< 3.1.3
MEDIUM 6.1 The Easy Digital Downloads (EDD) Commissions extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before … wordfence
bf238e9d-be91-4c9a-8506-ee01927f5173
< 2.0.52
MEDIUM 6.1 The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations. wordfence
bf0f87fe-d318-4f49-993c-3255f4e77ef1
< 5.1.2
MEDIUM 6.1 The wp-database-backup plugin before 5.1.2 for WordPress has XSS. wordfence
bf0bbd5e-0fec-445e-9baa-e383524da648
< 7.6.1
MEDIUM 6.1 The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
bf0a1568-e97c-41ea-b2c3-ba335f0b4360
< 2.2.0
MEDIUM 6.1 The WPGlobus Translate Options plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ p… wordfence
bf03a656-7a3b-4227-9493-88f522d7bc13
< 3.0.0
MEDIUM 6.1 The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versio… wordfence
befe5e99-204e-470e-bbbb-285b5ba0b1fb MEDIUM 6.1 The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
befd6971-29e1-477e-95b8-e7385fbd247d
< 3.8.0
MEDIUM 6.1 The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature. wordfence
befa92c2-7761-44df-a162-10f3deb9439e
< 1.0.2
MEDIUM 6.1 The Tags to Keywords plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
bed6b603-c811-4624-9053-1e12029ba73b
< 4.26
MEDIUM 6.1 The SP Project & Document Manager WordPress plugin is vulnerable to attribute-based Reflected Cross-Site Scripting via t… wordfence
becee157-8519-4f1f-b369-5f932773f282 MEDIUM 6.1 The auto-thickbox-plus plugin through 1.9 for WordPress has wp-content/plugins/auto-thickbox-plus/download.min.php?file=… wordfence
bec97055-ebe1-4529-9f3b-db2745300f69 MEDIUM 6.1 The Order Audit Log for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions… wordfence
beaea592-5eb5-4400-a4a8-b73f9b94198b MEDIUM 6.1 The Simple Headline Rotator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
be94ba55-24e3-4d61-9f2b-e2a4699bc6f6 MEDIUM 6.1 The flickr-slideshow-wrapper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… wordfence
be7ec812-ee9e-4b19-bb99-27e8016b8013 MEDIUM 6.1 The SpiderContacts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'serch_or_not' parameter… wordfence
be76a310-d99f-43d8-a845-6bf20eb9a11d
< 2.3.10
MEDIUM 6.1 The Post Timeline plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
be62e2ea-0861-4815-b98a-1ea508df952d MEDIUM 6.1 The Media Folder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
← Prev 826 827 828 829 830 831 832 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top