πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 833 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bb5c765d-2d80-42fd-823c-070777348f62 MEDIUM 6.1 The Add Linked Images To Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
bb581a8a-8e68-4f5a-8f05-d5b91b0f70d4
< 2.82
MEDIUM 6.1 The Media Library Assistant plugin before 2.82 for Wordpress suffers from multiple XSS vulnerabilities in all Settings/M… wordfence
bb545a42-6c66-412b-a686-e486b0a58dc5
< 3.6.0
MEDIUM 6.1 The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '… wordfence
bb302392-bde0-4c29-adae-649110d032a7 MEDIUM 6.1 The Geotagged Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
bb2df482-30bf-49e5-b1e2-06e102d2dd1b MEDIUM 6.1 The searchterms-tagging-2 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `count` parameter… wordfence
bb2897fc-c38b-419f-8651-0620a31b50ec
< 4.14.8
MEDIUM 6.1 The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting i… wordfence
bb1ae910-c562-48a7-b81d-3bc5dd7913e1 MEDIUM 6.1 The Ui Slider Filter By Price plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
bb1095e8-41f0-4cce-8381-0ef79c3c73de MEDIUM 6.1 The GDReseller plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
bb0e99c7-003a-4795-8acb-e6dafca34b8c
< 1.0.9.22
MEDIUM 6.1 The plugin CO2ok: carbon offsetting for e-commerce is vulnerable to Cross-Site Scripting via the several parameters in v… wordfence
baf54eb2-0b29-4718-a994-f722cefd7317
< 3.30.2
MEDIUM 6.1 The Leyka plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stage' parameter in versions up … wordfence
baebd08b-1f40-4cb2-8158-c4421af68c06 MEDIUM 6.1 The Appointment Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
bada2872-aa45-41a7-aa52-c0be1c3f2b59
< 1.7.9
MEDIUM 6.1 The Web Directory Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
bacc29c3-a1fc-4e75-a3e2-cd3d6aac9554
< 1.3.2
MEDIUM 6.1 The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before … wordfence
baac847b-3c5e-44c4-bccf-fcbde1adf37f MEDIUM 6.1 The Category Dropdown List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_S… wordfence
baab325d-58c2-446b-af70-6951eeef3bb1
< 2.0.28
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User… wordfence
baa8b5ce-7ef8-4ca8-9957-2c3469f55dda
< 1.12
MEDIUM 6.1 The Additional Order Filters for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th… wordfence
baa720d6-1891-4557-a744-830be56862e9
< 4.9.4
MEDIUM 6.1 The WordPress Shortcodes Plugin β€” Shortcodes Ultimate plugin for WordPress is vulnerable to Reflected Cross-Site Scrip… wordfence
ba8c88e9-e84c-4fe7-a3b1-ee77c49d5590 MEDIUM 6.1 The Smooth Gallery Replacement plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
ba8c5db5-48d4-4ce1-84b9-5743c7444a3a MEDIUM 6.1 wordfence
ba88a1f5-9ebf-4899-81b3-e65587ae2fe2
< 13.1
MEDIUM 6.1 The WP Statistic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
ba7ff5b1-ef17-4bfb-9bed-e12c143b760d MEDIUM 6.1 The Limit Bio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0… wordfence
ba79c58c-2048-4759-a096-c0ce05003a2e MEDIUM 6.1 The GNUPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.2.… wordfence
ba796adc-db76-4b9d-a6f9-f0f51f070240 MEDIUM 6.1 The WordPress Captcha Plugin by Captcha Bank plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to… wordfence
ba779595-2674-4d84-bc41-889ae60bd6a4 MEDIUM 6.1 The Timeline Event History plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `id` parameter i… wordfence
ba62b804-f101-4e29-8304-fb2b7dad333c
< 2.11.2
MEDIUM 6.1 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… wordfence
← Prev 830 831 832 833 834 835 836 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top