πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 837 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b761292e-375c-4657-a7a8-e11af28f45fa
< 0.7.7
MEDIUM 6.1 iThemes Builder Style Manager before 0.7.7 for WordPress has XSS via add_query_arg() and remove_query_arg(). wordfence
b751191b-35a8-4331-ac3f-f6090221c65f MEDIUM 6.1 The PT Sign Ups plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.… wordfence
b73fd138-5565-4c80-a061-be8e970c7ea6 MEDIUM 6.1 The Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
b73198e8-2b00-4ed3-9f6d-a5dc12856059 MEDIUM 6.1 The Replace Default Words plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
b72e0a4c-5de5-4396-b515-8c0f2f4de5ed MEDIUM 6.1 The SHOUT plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.3 d… wordfence
b72dcc68-df81-47ac-bd73-6aee87611b90
< 2022
MEDIUM 6.1 The Advanced iFrame WordPress plugin before 2022 does not sanitise and escape the ai_config_id parameter before outputti… wordfence
b7290317-418d-4e5c-85fa-f931cc4a865b MEDIUM 6.1 The AlT Monitoring plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
b7240711-e575-41ff-ba39-0255ca2aa9f5 MEDIUM 6.1 The Comment Extra Fields plugin for WordPress is vulnerable to Cross-Site Scripting via the swfupload.swf file in versio… wordfence
b7210fd7-0812-47bc-bc62-d69280253e0a MEDIUM 6.1 The Browser Sniff plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
b71bc259-d800-4f32-96a9-21da71472a6d
< 2.3.2
MEDIUM 6.1 The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versio… wordfence
b7162b78-65b7-4f80-83f0-47d9afc2ed65
< 2.0.4
MEDIUM 6.1 core/lib/upload/um-file-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerabili… wordfence
b70a1344-2b55-40c9-a314-80d581e0b019 MEDIUM 6.1 The WP Contact Form7 Email Spam Blocker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'po… wordfence
b709f1f5-e89f-4d67-9460-2c65c138dc8f
< 0.7.1
MEDIUM 6.1 The Logo Manager For Enamad plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
b708b72f-d906-47c9-9bf7-a9397956db3d
< 1.3.2.1
MEDIUM 6.1 The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pointsf' parameter on the… wordfence
b6f7c956-16ce-4739-845b-15f426968808
< 6.3.9
MEDIUM 6.1 The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msg' parameter i… wordfence
b6ec05f2-5a85-41ca-8bd0-ca6d1d8a5da5
< 1.14
MEDIUM 6.1 The Platform.ly Official plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
b6e3e59b-837b-4058-b7bc-a22cff22afb4
< 6.6.5
MEDIUM 6.1 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site… wordfence
b6e26846-9fcf-4078-9b45-660463ec5b04
< 2.0
MEDIUM 6.1 The GdeSlon Affiliate Shop plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.5.5 v… wordfence
b6c08ff0-1f36-4b39-80b1-5b6d7ac9e96e MEDIUM 6.1 The Court Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
b6bb8fea-8b2c-42da-a224-0719a584d92b
< 1.3.2.4
MEDIUM 6.1 The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date' parameter on the 'c… wordfence
b6b61731-ded2-4ac1-83f6-686daf92441e
< 2.1.5
MEDIUM 6.1 The WP Datepicker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpdp_get_selected_datepi… wordfence
b6ad08fb-d029-4f84-818c-911ae2d97f33
< 3.1.61
MEDIUM 6.1 The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Reflected … wordfence
b6a706ce-da98-4bad-a5a7-5e579bf60b25 MEDIUM 6.1 The Flagged Content plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
b680132a-f397-4636-98b2-bcd8c168e822
< 1.9.9
MEDIUM 6.1 The WP to LinkedIn Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in … wordfence
b67c9137-4368-4ecf-9091-8ae0773c47e8 MEDIUM 6.1 The Kento WordPress Stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
← Prev 834 835 836 837 838 839 840 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top