πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 834 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ba5d1bd4-da0d-43f4-b28f-4a4a2702b3b0
< 2.6.10
MEDIUM 6.1 The Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms plugin for WordP… wordfence
ba5b7e1f-7479-47bd-99ed-3d57eb209464
< 1.0.11
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Nofollow Links plugin before 1.0.11 for WordPress allows remote attacker… wordfence
ba49d38d-2838-4b8c-98f9-37e0c7d8f060 MEDIUM 6.1 The Extra Options – Favicons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
ba4638be-29d3-4638-84d3-6a9d540bfa33 MEDIUM 6.1 The WP Affiliate Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
ba435b26-a6f1-41cf-acb8-fffd8a18fea7
< 2.21.1
MEDIUM 6.1 The RabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and… wordfence
ba426d2f-aa05-4316-86ca-228f21785f63
< 0.1.9
MEDIUM 6.1 The Testimonials by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
ba4180a5-90b9-4e8b-8b2f-5debc46b67e2 MEDIUM 6.1 The Responsive Data Table plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
ba385261-bee2-491d-9b31-a1624d740dff
< 7.0.1
MEDIUM 6.1 The Show All Comments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sac_posts' parameter… wordfence
ba0f166f-87ef-4b5d-ada4-16529d93e10f MEDIUM 6.1 The Giga Messenger – Express plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_instance_i… wordfence
ba0efad3-1364-4b71-9d4d-522cb6381dfd MEDIUM 6.1 The Floating Video Player plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
ba06e298-308d-4378-96b8-5ac4e7cc63c0
< 2.2.13
MEDIUM 6.1 The Sign-up Sheets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['REQU… wordfence
ba035b43-7459-47a9-bbc4-981cc847bd7a
< 3.7.0
MEDIUM 6.1 The Inline Related Posts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and… wordfence
b9f5b68f-bf81-4157-920a-f14eb29390a6
< 1.0.3
MEDIUM 6.1 The Multiple Domain plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.0.2 d… wordfence
b9ebeb96-2f39-488e-aef6-d5af0a37c24a
< 6.10.12
MEDIUM 6.1 The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all… wordfence
b9de8d95-4e07-4c52-912b-1a4e2d7e5ed0
< 2.2.10
MEDIUM 6.1 The Kangu para WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'etiqueta' param… wordfence
b9db221b-facd-4808-b5d0-3e26b509def1
< 3.1.1
MEDIUM 6.1 The Restaurante theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.… wordfence
b9d67773-518e-4293-8d5f-3df29d96730c MEDIUM 6.1 The Youtube Video Grid | Youmax plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up … wordfence
b9aacc69-aa46-4cdb-a301-c0bf2836d441 MEDIUM 6.1 The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'old_domain' par… wordfence
b9a73bcf-cd20-4081-83d4-4bcfe0482f59 MEDIUM 6.1 The wp-login customizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
b9a603ee-183d-4130-8e03-12deb86466ce MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for eShop plugin 3.7.0 and earlier for… wordfence
b9a2d413-ac7d-4385-a429-2bfa7abe6777
< 1.4.1
MEDIUM 6.1 The Fancy Roller Scroller plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
b983d22b-6cd2-4450-99e2-88bb149091fe
< 6.8
MEDIUM 6.1 The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress… wordfence
b980b8e2-73e6-4afc-a24c-c7c98283e85b
< 2.8.11
MEDIUM 6.1 The Google Translate Plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 2.8.10. This … wordfence
b96c5ba8-e0a6-42b9-8ba1-637d52476d64
< 3.0.70
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in Best Gallery Albums Plugin before 3.0.70 for WordPress allows remote attacke… wordfence
b96349da-e2b4-4b29-94b4-1039427bce8e
< 2.15
MEDIUM 6.1 The WooCommerce PDF Invoices & Packing Slips plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in ve… wordfence
← Prev 831 832 833 834 835 836 837 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top