ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 838 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b6623d07-9716-49e2-a883-7eebabf3ea58
< 1.8.0
MEDIUM 6.1 The Plugin Oficial – Getnet para WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in v… wordfence
b65ab6a1-8f94-4437-b54f-97a044b4960c MEDIUM 6.1 The Are you robot google recaptcha for wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… wordfence
b65184e6-8072-4dd7-8291-c92817e55beb
< 1.2.0
MEDIUM 6.1 The Stock Exporter for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple par… wordfence
b6422375-a819-4e92-92af-a0a4591dea26
< 2.1.11
MEDIUM 6.1 The Portfolio Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in ver… wordfence
b63d8238-267f-4a40-9af0-37ae8b9ba26b MEDIUM 6.1 The Plainview Protect Passwords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via admin settings … wordfence
b63ccc9a-222d-4119-909b-d04bab78d663 MEDIUM 6.1 The EG-Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘paged’ parameter in… wordfence
b631ba7f-105d-4fe4-9173-4f7eade92d54
< 1.0.5
MEDIUM 6.1 The BestWebSoft's Pinterest plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
b630d7fa-8a6a-473a-82df-fce8393a7401 MEDIUM 6.1 The HTML5 Lyrics Karaoke Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
b6208023-23d7-43e8-b4c5-748a1504c173 MEDIUM 6.1 The Simple catalogue plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… wordfence
b616bb6c-0861-4920-a589-f2c5bb819164 MEDIUM 6.1 The Easy Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add… wordfence
b6155327-ac4a-4c97-9a41-e0c5311379bc MEDIUM 6.1 The BookPress – For Book Authors plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
b614aab2-a3e3-410a-917b-cc33634503ce
< 3.5.0
MEDIUM 6.1 The MyBookTable Bookstore plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
b611fc1e-9567-4008-ab8c-55db52783d64
< 0.4.7.6
MEDIUM 6.1 The Media Downloader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inc… wordfence
b5f07017-e2b6-4051-8df8-3d0cfa59c7d9
< 6.8.9
MEDIUM 6.1 The Easy Forms for Mailchimp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
b5e6d73c-0fa7-4ae2-be3b-5ab8f1721aa6
< 2.2.9
MEDIUM 6.1 The redirection plugin before 2.2.9 for WordPress has XSS in the admin menu, a different issue than CVE-2011-4562. wordfence
b5d69895-2fe6-40cf-8d4d-aa274067495a
< 1.7.0
MEDIUM 6.1 The feed-them-social plugin before 1.7.0 for WordPress has reflected XSS in the Facebook Feeds load more button. wordfence
b5c61212-e68e-4198-b078-18121576b767
< 4.9.26
MEDIUM 6.1 The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t… wordfence
b5c171fb-5053-455d-8aa0-db51b80f7a65
< 1.17.0
MEDIUM 6.1 The FiboSearch WordPress plugin before 1.17.0 does not sanitise and escape some of its settings, which could allow high … wordfence
b5be7952-77cb-4b69-a41d-58edf80b24bb MEDIUM 6.1 The Team Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
b5bd19ba-cca0-463b-84f2-3bb9a378dee1 MEDIUM 6.1 The vcOS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.4.… wordfence
b5ba2813-56ff-45d0-966a-f83da862ec13
< 1.6.6
MEDIUM 6.1 The Slideshow Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'method' parameter in… wordfence
b5b24f80-d3a4-452b-bc83-3576bdc62829
< 2.0.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the EWWW Image Optimizer plugin before 2.0.2 for WordPress allows remote att… wordfence
b5b1d979-e366-454e-af90-4f5523a11e24 MEDIUM 6.1 The DesignThemes Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
b5a99c97-19a4-41ab-a24f-3cc8f4be7073
< 1.0.2
MEDIUM 6.1 The WooCommerce Green Wallet Gateway WordPress plugin before 1.0.2 does not escape the error_envision query parameter be… wordfence
b5a45b0d-aa47-45ac-80a9-0a30af3f91ce
< 2.8.7
MEDIUM 6.1 The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Refl… wordfence
← Prev 835 836 837 838 839 840 841 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top