🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 841 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b403b1f3-cc04-48fb-b2ae-c6c234fad29f MEDIUM 6.1 wordfence
b40070af-3f2c-4bd1-bd33-1a0aa37c6e62
< 1.3.0
MEDIUM 6.1 The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
b3ff4379-81f6-4c58-8658-2bd2a26883d1
< 3.9.5
MEDIUM 6.1 The Architecturer theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and excluding, … wordfence
b3f666a3-6287-4c9b-94d3-7bc457701af2
< 1.2.2
MEDIUM 6.1 The Proofreading plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all v… wordfence
b3ecec49-9185-409e-8dd8-1363bdbfdd04
< 1.5.20
MEDIUM 6.1 The Access Areas plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
b3d9af8b-1168-462d-a767-d16ee660f646
< 2.6.0
MEDIUM 6.1 The LaTeX2HTML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ver' or 'date' parameter in… wordfence
b3cc372f-7696-48a6-9664-c43d9c07fb2c
< 1.0.9
MEDIUM 6.1 The Fabrica Synced Pattern Instances plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up… wordfence
b3c511a5-3c2b-40c0-b3d1-bb7c83c67513
< 1.1
MEDIUM 6.1 The PopCash.Net Code Integration Tool plugin before 1.1 for WordPress has XSS via the tab parameter to wp-admin/admin.ph… wordfence
b3c3115b-8921-429d-b517-b946edab1cd5
< 9.0.29
MEDIUM 6.1 The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ma… wordfence
b3b62264-35f2-49a5-8abe-ec5d6c8d2c2c MEDIUM 6.1 The Advanced Fancybox plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
b3b39055-aa2a-4db8-838b-e4baaea105b4 MEDIUM 6.1 The Real WYSIWYG WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of PHP_SELF in the ~/re… wordfence
b3b0fa3c-ec17-49a3-a00c-a2b22df16964
< 1.7.3
MEDIUM 6.1 The Awesome Shortcodes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
b3af900c-4048-4f4f-93e9-c60ca34d015b
< 2.9.1
MEDIUM 6.1 The WP HTML Mail plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 2.9.0.3 due to i… wordfence
b3ae93da-57ee-4966-83af-b8c57f9ad7d9
< 5.2.8
MEDIUM 6.1 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site R… wordfence
b3abd265-f1b0-49e5-ba50-5af91e855f5f MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in wu-ratepost.php in the Wu-Rating plugin 1.0 12319 and earlier for WordPress … wordfence
b37fc473-d71e-47d6-b0fe-e323868244f1
< 4.0
MEDIUM 6.1 The iFrame plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘get_params_from_url’ option… wordfence
b37099ed-153e-4df9-8141-9242ed36859d MEDIUM 6.1 The WP-BlackCheck plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
b37087a4-83b2-4355-89f0-6ff0aa8d0013
< 4.1.5
MEDIUM 6.1 The KBucket: Your Curated Content in WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via … wordfence
b3678907-c781-4fb4-9add-daf395eb53f4 MEDIUM 6.1 The RSS Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0… wordfence
b3669af4-06b4-4088-ae23-c167ba65f79c MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in wp-safe-search/wp-safe-search-jx.php in the Safe Search plugin 0.7 for WordP… wordfence
b34db1a8-13ee-45dd-9d05-90410bc3604d MEDIUM 6.1 The KNR Author List Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
b34a82c5-4d70-47d3-9a02-7eeaa13ff677
< 4.19
MEDIUM 6.1 The Ajax Search Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4… wordfence
b3461327-9195-48ed-b9c3-7b33198e9438
< 1.30
MEDIUM 6.1 The LH Add Media From Url plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘lh_add_media_f… wordfence
b33fd509-1cc3-48de-bd4a-7c9749da1cf8
< 1.1.19
MEDIUM 6.1 The SliceWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1.1… wordfence
b33760d8-323a-4d0b-9a54-b84152bd4367
< 5.7.4
MEDIUM 6.1 The YOP Poll plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘yop_poll_set_wordpress_vote… wordfence
← Prev 838 839 840 841 842 843 844 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top