🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 836 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b85d8451-5283-4a76-8565-c667a3d2d917
< 1.3.7.1
MEDIUM 6.1 The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_da… wordfence
b8580107-bbc1-4d6e-bb72-f1efc404d7b3
< 0.3
MEDIUM 6.1 The Latest Posts by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category… wordfence
b8564dbb-6be8-4999-be65-d28609e05451
< 1.0.12
MEDIUM 6.1 The Website Article Monetization By MageNet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'a… wordfence
b8520d91-9c31-413e-a7ac-f03cb48cb992 MEDIUM 6.1 The Kodex Posts likes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
b847d10d-254b-40e5-b5f9-1391834d63b4 MEDIUM 6.1 The dTabs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ tab’ parameter in versions … wordfence
b825f4c2-8373-4aba-ab01-880cf0553b54
< 3.0.0
MEDIUM 6.1 The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
b81e12f9-0e04-4cbf-829f-fa3edfa8ecdf
< 3.7.9
MEDIUM 6.1 The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting i… wordfence
b8139f3d-6e92-43aa-b161-f374875adc18 MEDIUM 6.1 The Mind3doM RyeBread Widgets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to… wordfence
b80eb9fd-81f6-4bbf-ada1-125977a2ac01
< 1.5.3
MEDIUM 6.1 The JobSearch WP Job Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
b809ca97-ea82-4d56-a90a-e1ea9e7235ff MEDIUM 6.1 The MM-Breaking News plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER['REQUEST_URI'] in… wordfence
b80802cd-6fcc-4cdb-b6d7-a9171cadcc83 MEDIUM 6.1 The Out Of Stock Badge plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
b804bc7a-20e7-4e31-a5e9-daddfc891ba4 MEDIUM 6.1 The ReadMe Creator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
b802b6bf-e70f-47ab-a72d-35f6341920eb MEDIUM 6.1 The Widget Control Powered By Everyblock for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘idDrop… wordfence
b7fcaf39-bf37-4229-89ff-8e6e819017dc
< 5.4.4
MEDIUM 6.1 The Online Marksheet Creator : eMarksheet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all ve… wordfence
b7ea6312-2703-47d1-909e-8c5fd05d9929
< 1.7.4
MEDIUM 6.1 The Web Directory Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
b7e599b1-20fb-4260-bdc3-ef0653719b26
< 4.5.6
MEDIUM 6.1 The BizPrint plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.5. T… wordfence
b7df753a-5399-45ff-894f-8f35868fe072
< 2.5.1
MEDIUM 6.1 The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputt… wordfence
b7dce0db-792f-4be2-a55d-b4fb7442b548
< 12.8
MEDIUM 6.1 The Indeed Membership Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
b7d2e351-6ee2-4865-b1d2-909e76e1ecb5
< 1.0.13
MEDIUM 6.1 The GSheetConnector for Forminator Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in version… wordfence
b7d1c57c-7aa2-4317-94ac-3fc48f87b98c
< 7.0.0
MEDIUM 6.1 The Conversios.io plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versi… wordfence
b7d109b6-47fb-4cda-9067-96e31d3b4308 MEDIUM 6.1 The Nifty Backups plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
b7b29589-804b-4d37-a3f4-919f0c1126c2 MEDIUM 6.1 An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q paramete… wordfence
b79b9d79-d22b-421b-b355-35d95a0820b2 MEDIUM 6.1 The DsgnWrks Twitter Importer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to… wordfence
b7886d0a-941d-4bb3-850e-84ed09e83f05
< 2.8.0
MEDIUM 6.1 The Pagopar – WooCommerce Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
b76b12ed-1bb4-4aa9-ab9f-06084c667f40
< 1.1.0.26
MEDIUM 6.1 The BizCalendar Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all … wordfence
← Prev 833 834 835 836 837 838 839 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top