🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 835 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b94d4e13-c093-4143-b011-8a89a7477e1e MEDIUM 6.1 The Fast Tube plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
b9412cb1-54b5-4544-8571-0a1185e7f456 MEDIUM 6.1 The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_location XSS. wordfence
b93af9cc-cd9a-4bbb-8cb1-bf45c59e469c
< 7.6.7
MEDIUM 6.1 The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the searchll parameter in all … wordfence
b92ebcd6-8508-4fcd-a6e6-da16063324ed
< 51.1.76
MEDIUM 6.1 The King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Build… wordfence
b924261f-1e1a-4565-a22e-ba592912d270
< 3.8.1
MEDIUM 6.1 wordfence
b91ec428-8444-4304-8901-4bc3ef146e3e MEDIUM 6.1 The Easy WordPress Subscribe – Optin Hound plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to… wordfence
b91d979f-4043-4d55-9d01-6eda967b0a37
< 3.0.0
MEDIUM 6.1 The Mailing Group Listserv plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
b90d8b14-8f98-498a-89d2-71f47aceb9c3
< 6.5.9
MEDIUM 6.1 The FS Poster plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.5… wordfence
b901f593-3691-4ea1-8ab6-1ddd68fa2e36 MEDIUM 6.1 The VNPAY Payment gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramet… wordfence
b8f53053-5150-4fba-b8d6-3d6c9df32c69
< 6.5.1
MEDIUM 6.1 The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulner… wordfence
b8e64950-4f01-4391-8c65-2f25ff5bcc06
< 10.9
MEDIUM 6.1 The Salon Booking System plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 10.8.… wordfence
b8e3f779-9d25-4525-a827-8ce743bd889e
< 2.4.1
MEDIUM 6.1 The New User Approve plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_ar… wordfence
b8daa685-d366-4b08-9f30-b14700fdee03
< 1.3.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 for WordPress allows re… wordfence
b8da640d-8965-45bb-be68-57d4eb598759
< 3.2.4
MEDIUM 6.1 The StaffList plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2… wordfence
b8c66ddd-8a01-40e0-8893-668551b527d1 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in inc/raf_form.php in the Recommend to a friend plugin 2.2.2 for WordPress all… wordfence
b89a1265-6e26-498c-a2b4-da12d38463c9 MEDIUM 6.1 The Login Configurator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
b899296a-01df-45af-b966-2b80685c6853
< 1.0.6.4
MEDIUM 6.1 The Active Products Tables for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all v… wordfence
b879d6a9-dd75-4c53-867b-dd36a9afe4b3
< 2.34.1
MEDIUM 6.1 The AffiliateWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2… wordfence
b876ed30-66f5-4cad-a60c-104a0a793033 MEDIUM 6.1 The Multiplayer Games WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_S… wordfence
b86170aa-e21d-4841-be82-e7727ca10da5 MEDIUM 6.1 The Simple Custom Admin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
b85e9bf4-0006-402a-ae46-a02fa854d995
< 1.0.54
MEDIUM 6.1 The Corner Ad plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘codepeople_promote_banner_… wordfence
b85d8451-5283-4a76-8565-c667a3d2d917
< 1.3.7.1
MEDIUM 6.1 The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_da… wordfence
b8580107-bbc1-4d6e-bb72-f1efc404d7b3
< 0.3
MEDIUM 6.1 The Latest Posts by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category… wordfence
b8564dbb-6be8-4999-be65-d28609e05451
< 1.0.12
MEDIUM 6.1 The Website Article Monetization By MageNet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'a… wordfence
b8520d91-9c31-413e-a7ac-f03cb48cb992 MEDIUM 6.1 The Kodex Posts likes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
← Prev 832 833 834 835 836 837 838 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top