ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 831 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bd6cc95c-451b-4ad7-bb5b-bbb9bc3c89c2
< 2.5.0
MEDIUM 6.1 The Creative Image Slider – Responsive Slider Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Script… wordfence
bd652388-ab0d-406a-99d1-6d1d0cbb54dd MEDIUM 6.1 The HQ60 Fidelity Card plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
bd5bfa76-eb14-4fab-8497-782353342af5 MEDIUM 6.1 The Form To Online Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
bd5a7bf6-5c9d-4c0f-a7fd-738c0d7f90bd
< 6.0
MEDIUM 6.1 The Sponsered Link plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
bd43628d-1320-44a8-a397-37455096e191
< 2.5.1
MEDIUM 6.1 The eHive Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
bd3d3fe1-8fdd-404c-a8f7-2b9893ff6c0d
< 1.9.5
MEDIUM 6.1 The WP Video Lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_URI… wordfence
bd387fe3-ffc5-4981-93d7-2b0b14cc11d5 MEDIUM 6.1 The Auto Post Scheduler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
bd22eaa1-e76d-4192-8d08-9bb984b08439
< 1.6.11
MEDIUM 6.1 The Listeo WordPress theme before 1.6.11 did not properly sanitise some parameters in its Search, Booking Confirmation a… wordfence
bd1a98d4-bf67-4678-b30b-ca13e63c665a
< 1.1.7
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the save_order function in class-floating-social-bar.php in the Floating Soc… wordfence
bd0cfbc6-051b-44f4-9400-fa638bea50b9 MEDIUM 6.1 The Blue Wrench Video Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to,… wordfence
bce942af-db4f-4b73-83e3-6bb6520f3543 MEDIUM 6.1 The WP Voting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
bcd981fb-ef75-4ed3-a18f-4ad9eaa148f4
< 12.0.5
MEDIUM 6.1 Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitra… wordfence
bcbb7d4d-5b4c-47d3-a815-bd9e026fc03d
< 2.20
MEDIUM 6.1 The bbPress Notify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
bcaff8ab-2db9-4d91-9b7a-f7f49f5952b9
< 4.7.5
MEDIUM 6.1 The All-in-One Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'vi' parameter… wordfence
bcaf9b92-5e59-47c5-a04e-3ef5c53a2640
< 2.0.9
MEDIUM 6.1 The Tutor LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions 2.0.0-2.0.8 due to insuff… wordfence
bcad7322-a5d9-4d72-9983-276f9c05c27d
< 7.3.14.727
MEDIUM 6.1 The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS. wordfence
bc9efc98-7815-4b9b-a180-71f1095c9b0a MEDIUM 6.1 The jQuery Tagline Rotator WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['… wordfence
bc91449a-7013-430d-bf7c-70175ea45114
< 3.2.7.3
MEDIUM 6.1 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab… wordfence
bc8ccaee-058b-476f-9d92-08db23df024b
< 1.51.8
MEDIUM 6.1 The Broadstreet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
bc6fce33-af42-466e-8e76-1e027d5d52ec MEDIUM 6.1 The Featured Posts with Multiple Custom Groups (FPMCG) plugin for WordPress is vulnerable to Reflected Cross-Site Script… wordfence
bc698c40-4a2b-4dab-93f0-647e4db79d2c
< 3.1.0
MEDIUM 6.1 The Bridge Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in version… wordfence
bc590a99-0c9d-4c38-b7ec-b8a0dc7f6f0a
< 1.4.3
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in book_ajax.php in the Rezgo plugin 1.4.2 and earlier for WordPress allows rem… wordfence
bc56fe18-f0f4-4f7b-96c2-40d376e0fd74 MEDIUM 6.1 The Daily Inspiration Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post_ref… wordfence
bc547d3d-9b08-472a-937d-d9c815c33087
< 1.0.4
MEDIUM 6.1 The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting in al… wordfence
bc4bfa81-c781-42df-91c7-3daed1e6a6f4 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in redirect_to_zeenshare.php in the ZeenShare plugin 1.0.1 and earlier for Word… wordfence
← Prev 828 829 830 831 832 833 834 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top