ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 839 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b5a07a44-98f9-4795-8615-c73a9b161c74 MEDIUM 6.1 The All In One Redirection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
b5a065d7-54de-46b4-ba88-9467d0724d33 MEDIUM 6.1 The TransFinanz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tf_antr_sort_erstattung_en… wordfence
b59f13b9-8ad3-44a7-90a0-1f959ba55700
< 1.7.6
MEDIUM 6.1 The WooCommerce Store Exporter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' & 'dat… wordfence
b597e8a5-043e-440e-aaa2-38fb3eeb0731
< 5.4.9.1
MEDIUM 6.1 The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulner… wordfence
b5930612-e37f-4886-bc47-ecc35821f4a2 MEDIUM 6.1 The Addressbook plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3… wordfence
b58e7192-2159-4f77-baba-05a57a545c7b
< 3.0.15
MEDIUM 6.1 The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
b58b0c43-8564-4aa4-8c30-8d3e1839c0e6 MEDIUM 6.1 The Content Mirror plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
b58ab962-955d-4c77-93f7-40b9845b05c8 MEDIUM 6.1 The Stencies plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.58… wordfence
b588b8d0-5d71-4e95-ad97-821e47b013c8
< 1.1.2
MEDIUM 6.1 The Video & Photo Gallery for Ultimate Member plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t… wordfence
b57dc78f-b28e-449e-8993-72836babc12e MEDIUM 6.1 The WP AutoKeyword plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
b5675962-7d7f-46f4-b588-e46af212e9c8 MEDIUM 6.1 The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outpu… wordfence
b5639c00-f34c-45e3-8ff1-dfde7856a80e
< 4.6.1
MEDIUM 6.1 The WPML plugin for WordPress is vulnerable to Cross-Site Scripting in versions prior to 4.6.1 due to insufficient input… wordfence
b53c66f6-337b-426d-a471-03c4ebadd5cf MEDIUM 6.1 The Cyber Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includi… wordfence
b51ea91f-247c-4ea6-b60c-7ad49b676cb1
< 1.8.3
MEDIUM 6.1 The raygun4wp plugin before 1.8.3 for WordPress has XSS in the settings, a different issue than CVE-2017-9288. wordfence
b51a7670-9fa6-4df9-bef6-c7ebe6b09c5c
< 1.2.2
MEDIUM 6.1 The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflecte… wordfence
b512f9a9-6c83-416c-bacc-ee3bba8dfe29
< 1.5.5
MEDIUM 6.1 The Contact Forms by Cimatti plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'form-field-id… wordfence
b50772e5-5142-4f50-b5c0-6116a8821cba
< 5.2.6
MEDIUM 6.1 The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scri… wordfence
b5031140-9a48-43da-b946-00ce9c70258b MEDIUM 6.1 The Click To Tweet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
b4fc9628-b254-405b-a7cc-bb955618bc35 MEDIUM 6.1 The Machic Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
b4ec9001-c4aa-4db3-b7d7-29afa243f78a
< 3.0.36
MEDIUM 6.1 The Rank Math SEO PRO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in v… wordfence
b4e9f1d7-9b80-4903-80dd-6b74f847c018
< 3.2.5
MEDIUM 6.1 The MicroPayments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
b4df1fc3-ea7e-4f41-a5f0-d3928f8add70 MEDIUM 6.1 The AGP Font Awesome Collection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
b4cf2331-ec19-488a-9d72-ec54fb9a82c9
< 4.0
MEDIUM 6.1 The CopySafe Web Protection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
b4ce2353-e4ec-4f55-a341-c1b11be86642 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in tpls/editmedia.php in the Hot Files: File Sharing and Download Manager (wpho… wordfence
b4c6930a-b413-4acc-a0a4-9940bb8474cc
< 3.2.7
MEDIUM 6.1 The Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘alert’ parameter in the… wordfence
← Prev 836 837 838 839 840 841 842 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top