🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 830 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
be60027e-9d6a-4740-b20c-6be3e115d9fe
< 1.8.7
MEDIUM 6.1 The Easy Digital Downloads (EDD) core component 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x befor… wordfence
be53bdbd-e797-4198-8ef9-bc01b5da68f4 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the bib2html plugin 0.9.3 for WordPress allows remote attackers to inject ar… wordfence
be4f5da0-77ec-41eb-85bd-c019e71d4c9d
< 2.3.11
MEDIUM 6.1 The GigPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘gp-page’ parameter in ver… wordfence
be44a7e0-f0e0-4e2e-ac1e-0550d8e5d994
< 2.13.3
MEDIUM 6.1 The SpeakOut! Email Petitions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘searchStri… wordfence
be3208c8-aceb-4ac9-91e1-d5de5a85f74d
< 5.1
MEDIUM 6.1 The which template file plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 5.0… wordfence
be16c229-1092-4090-83bc-38e42f6377b6 MEDIUM 6.1 The flog plugin 0.1 for WordPress has XSS via the url parameter. wordfence
be151552-827c-43a6-a0e0-da19884448fd MEDIUM 6.1 The 10Web Social Post Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu… wordfence
be0e9e67-efc1-4a21-ba32-4a963166350d
< 1.2.8
MEDIUM 6.1 The Injection Guard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_URI']… wordfence
be03bf77-69ec-466b-bad1-22174e0d5e89 MEDIUM 6.1 The WPCHURCH plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.7.… wordfence
bddbbcdf-dfcb-47dd-97e7-8563eaf70cbd MEDIUM 6.1 The Tax Rate Upload plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
bdd0bdf3-6952-4b87-a3e8-156757d22e74
< 4.11.0.2
MEDIUM 6.1 The WooCommerce Affiliate Plugin – Coupon Affiliates plugin for WordPress is vulnerable to Reflected Cross-Site Script… wordfence
bdce01f2-7c79-4b1d-8da2-f6ce118856a1
< 1.2.27
MEDIUM 6.1 The ARI Stream Quiz – WordPress Quizzes Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v… wordfence
bdc8f6e2-ee2a-4a8e-9c6f-2c69b0b597e5 MEDIUM 6.1 The Custom Smilies plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
bdc39e21-f39c-4581-895a-04e352e9b383
< 3.3.7
MEDIUM 6.1 The Wordfence plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘email’ parameter in vers… wordfence
bdc33ecc-da54-4852-8426-bfafe0dca41b
< 5.1
MEDIUM 6.1 The WP Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attachment_id’ para… wordfence
bdc21e2e-288e-459b-86d3-739aa4acb32d MEDIUM 6.1 The EmailPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… wordfence
bdb7e239-75c4-480e-a283-dc2354fe3375
< 1.2.21
MEDIUM 6.1 The All In One Slider plugin (formerly known as All In One Carousel) for WordPress is vulnerable to Reflected Cross-Site… wordfence
bda3c8f8-fd0f-432d-a382-e8ac55d34bb9 MEDIUM 6.1 The Markdown on Save Improved plugin 2.5 for WordPress has a stored XSS vulnerability in the content of a post. wordfence
bd9ef48f-b501-4fca-a6a5-78452c316497 MEDIUM 6.1 The WP Google Maps Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` param… wordfence
bd9e97df-2082-45d2-aa26-65383522de7d MEDIUM 6.1 The Google News plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2… wordfence
bd879bd9-d195-4146-b9dc-3ba7252645de
< 1.0.17
MEDIUM 6.1 The10WebFAQ plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.0.14 due to i… wordfence
bd861a13-4215-4a69-adb5-cd28dce4509b
< 5.4.9
MEDIUM 6.1 The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_delete_role parameter bef… wordfence
bd7bf023-4a18-4918-9600-12720c1b4ad8
< 2.3.0
MEDIUM 6.1 The Hebrew Date plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.0… wordfence
bd748b6c-110a-46b6-a609-64d093dfc3e5
< 2.4.7
MEDIUM 6.1 The Seraphinite Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due … wordfence
bd718f4a-bad4-4e6a-ab4b-b0fb6bd25da3 MEDIUM 6.1 The Social Crowd plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
← Prev 827 828 829 830 831 832 833 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top