ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 832 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bc491c2b-0ae2-4002-a745-435a183d8e01
< 2.0.20
MEDIUM 6.1 The Classified Listing Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in versions up t… wordfence
bc42d879-9df5-4cbd-85a8-964213fd513e MEDIUM 6.1 The Add to Header plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
bc41039e-20cc-47d7-ab8e-da0d9168de22 MEDIUM 6.1 The Hide My WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.… wordfence
bc38d7ac-916a-4d6c-ad53-24c6dadc5436
< 4.5
MEDIUM 6.1 The Custom Posts Order plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
bc2a66cb-ad13-428f-a25a-b2807450aa16
< 4.0.4.8
MEDIUM 6.1 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
bc271261-8f9d-4c34-b2a0-298f8ced29f5 MEDIUM 6.1 The Responsive Zoom In/Out Slider WordPress Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
bc26ce1b-2427-4320-8363-f635ea02aece
< 3.9.4
MEDIUM 6.1 The Atarim plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpf_graphics_excerpt' parameter… wordfence
bc0f883f-a6d7-4b23-9284-1a5e46ef396e
< 1.1.5.8
MEDIUM 6.1 The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.… wordfence
bbd641a4-a8cf-4e51-8675-53d867740ded
< 1.20.3
MEDIUM 6.1 Insufficient Input Validation in the search functionality of Wordpress plugin Out-of-the-Box prior to 1.20.3 allows unau… wordfence
bbce4588-fbd2-4b75-8f67-51c7d02892be MEDIUM 6.1 The BulkPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg witho… wordfence
bbc8ccc1-7b72-44fb-8bf5-e7cb46081ed5
< 5.0.9
MEDIUM 6.1 Open redirect vulnerability in the Redirect function in stageshow_redirect.php in the StageShow plugin before 5.0.9 for … wordfence
bbbd989c-4d69-45c9-bcb9-44f9ab98b969
< 9.0.21
MEDIUM 6.1 The Easy Updates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter … wordfence
bbb67f02-87e8-4ca3-8a9d-6663a700ab5b MEDIUM 6.1 The ImageMapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.6… wordfence
bbb32c81-1311-42ba-ba7b-d8c8793133a7 MEDIUM 6.1 The Bg Orthodox Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
bbacdde1-87e0-4b3a-8580-f1d37c130a1c
< 1.0.1
MEDIUM 6.1 Reflected XSS in wordpress plugin simplified-content v1.0.0 wordfence
bbaae72c-b5a6-4fa3-9268-94c0e6a59d1c
< 1.6.5
MEDIUM 6.1 Cross-site scripting vulnerability in Popup Maker prior to version 1.6.5 allows remote attackers to inject arbitrary web… wordfence
bba9d5ef-5aac-4dbf-8f4c-18f1675f3b02
< 1.65
MEDIUM 6.1 The FireDrum Email Marketing plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
bba7fde9-0718-4681-9a1b-7c77bc0affbd
< 1.0.47
MEDIUM 6.1 The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in a… wordfence
bb9fc87e-b376-49ce-ba69-5acef9deda4d
< 24.1015
MEDIUM 6.1 The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a… wordfence
bb967453-59d6-4b03-8c75-1906b99bff80 MEDIUM 6.1 The Everest News Pro theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in ver… wordfence
bb929679-85bb-4d5b-9a99-e6081d55019f
< 5.5.75
MEDIUM 6.1 The miniOrange's Google Authenticator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the us… wordfence
bb8640f2-d3cc-4a4a-8dfb-adaa8b77264c MEDIUM 6.1 The Soundy Audio Playlist plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
bb6ecb74-b337-4930-a737-f70799607d89 MEDIUM 6.1 The Anti Plagiarism plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'm' parameter in the 'j… wordfence
bb62772b-ac8e-48ea-9d72-1b2e7996de42 MEDIUM 6.1 The JavaScript Logic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
bb606a30-2f7c-41e9-9ebc-9f1b0b84fff8
< 2.5.5
MEDIUM 6.1 The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ par… wordfence
← Prev 829 830 831 832 833 834 835 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top