πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 840 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b4b82bb0-8d8a-42eb-a142-1d9af34b2c66 MEDIUM 6.1 The WeChat Subscribers Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
b4b7adcf-c58b-4019-89ff-a69ebf8262bc
< 4.5.4
MEDIUM 6.1 The Simple Membership plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.5.3. T… wordfence
b4b61b5b-e5e8-41d4-bf37-d9427a204ea6 MEDIUM 6.1 The FLOWFACT WP Connector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter … wordfence
b4ad6f96-22a3-420c-9ccb-a7b118fa2810 MEDIUM 6.1 The WordPress HelpDesk & Support Ticket System Plugin – Octrace Support plugin for WordPress is vulnerable to Reflecte… wordfence
b4a229be-2991-40f3-a0e7-e322009a3ed2 MEDIUM 6.1 The Simple Load More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
b49c1e95-7ef4-45d7-9fdf-dd5adffd2eb0
< 1.5.122
MEDIUM 6.1 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected C… wordfence
b4983c2f-f9f6-4bd9-9c38-0ad3756f92b6
< 1.5.5
MEDIUM 6.1 The Catch Breadcrumb plugin before 1.5.4 for WordPress allows Reflected XSS via the s parameter (a search query). Also a… wordfence
b4971d77-1312-43ac-ab14-970bd4ec5688 MEDIUM 6.1 The Popping Content Light plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
b489427e-f925-4058-8924-7a9557fc4ebf
< 6.3.1
MEDIUM 6.1 The Gravity PDF plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wit… wordfence
b483e274-94e6-4b22-8431-d3a7638218db MEDIUM 6.1 The Mobile Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
b47b1230-bf08-4960-9fc9-56a5b37da8b5 MEDIUM 6.1 The WPCode Content Ratio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
b4764fe2-7bdf-4b08-ae9f-ccb46929c50a MEDIUM 6.1 The Wp-ImageZoom plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameter in all versi… wordfence
b46e2755-24df-4569-bf38-968bf890431e MEDIUM 6.1 The Revamp CRM for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
b467fc26-242f-47c4-bcfd-38980489a0c3 MEDIUM 6.1 The Snapshot Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
b45ba98f-4cd1-406a-8661-e19d5b4c3ba8
< 1.6.1
MEDIUM 6.1 The MC4WP: Mailchimp Top Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_… wordfence
b457db06-84c8-4b7b-b7c1-091771a11a35 MEDIUM 6.1 The Lock Your Updates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includ… wordfence
b4533554-52e4-44b4-9230-b6e3feb2e4a1 MEDIUM 6.1 The SEO by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all ve… wordfence
b4521959-416e-4ff5-96c0-bc4dbb0187b7 MEDIUM 6.1 The Folder Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'foldergallery' sh… wordfence
b44a4d74-5c2b-454a-992a-74a3a71fa5dd
< 1.6
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in index.php in the WordPress Classic 1.5 theme in WordPress before 2.1.3 allow… wordfence
b4309271-f93a-46ac-8b0b-d6193487ac98
< 2.2.11
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.11 for WordPress allows remote attackers t… wordfence
b42c0e51-676f-4f06-9e5c-b6b74bea89b5
< 3.0.5
MEDIUM 6.1 The WP-TopBar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to inclusion of a vulnerable vers… wordfence
b42be363-30b4-487b-9ffc-bfa3efbd1250
< 1.1.17
MEDIUM 6.1 The Header Footer Code Manager plugin <= 1.1.16 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via … wordfence
b42882f6-ccea-4d8f-940b-1ad95b1ab760 MEDIUM 6.1 The Ultimate WooCommerce CSV Importer WordPress plugin through 2.0 does not sanitise and escape the imported data before… wordfence
b41a91fc-86ee-4795-acb6-2ffd22c4f7af
< 1.1.2
MEDIUM 6.1 The PDF Generator for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via vendored exampl… wordfence
b404c6c4-cc05-4040-b96a-7be750020acc
< 1.2.8
MEDIUM 6.1 The SW Ajax WooCommerce Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
← Prev 837 838 839 840 841 842 843 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top