🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 842 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b320c501-ed90-470b-a46f-d6dbe649bbd8 MEDIUM 6.1 The Js O3 Lite theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5… wordfence
b3052631-4034-4235-b228-bb919777915a MEDIUM 6.1 The Random Posts, Mp3 Player + ShareButton plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all v… wordfence
b3023fda-d6ed-417f-b668-1cc63114805a
< 1.0.3
MEDIUM 6.1 The Goodlayers Blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
b2ef036e-14a5-40df-93c3-ab1a1d9accc0 MEDIUM 6.1 The WordPress RokBox plugin is vulnerable to Cross-Site Scripting via the 'src' and 'abouttext' parameters in the 'thumb… wordfence
b2dbf510-d99f-4918-8462-66696b68003c
< 1.7.30
MEDIUM 6.1 The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
b2d31521-5fe1-48ce-881c-4cacdbe08f21
< 2.0.11
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow rem… wordfence
b2ca965b-0d0c-4785-9666-69829e4cb1a4
< 1.3.0
MEDIUM 6.1 The Limit Attempts by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… wordfence
b2b62226-cf9b-4713-9734-67bf1c48895b MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Conversador plugin 2.61 and earlier for WordPress allows remote attacker… wordfence
b2af416b-4510-468f-81ef-aa09f2fd51ac
< 1.3.1
MEDIUM 6.1 wordfence
b2ac2e50-1eef-46e6-8d57-c9d2dc04f933
< 2.5.1
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in the Calls to Action plugin before 2.5.1 for WordPress allow remot… wordfence
b2a0b560-3f5a-4d09-9cc1-e22b2a19dfe6 MEDIUM 6.1 The WP Emoticon Rating plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
b28ba929-d057-43f9-b839-62347c06c1bd
< 9.3
MEDIUM 6.1 The WP Spell Check plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ and 'wpsc-sc… wordfence
b2780bc1-e044-4396-9f6e-de9e0a8ef841
< 2.7.7.27
MEDIUM 6.1 The Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
b274af9b-071c-4f8d-a2e0-7f02b631c19a MEDIUM 6.1 The Securimage-WP-Fixed WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP… wordfence
b269a5c9-9f0e-4dba-a06e-2d8dd94643b4
< 1.1
MEDIUM 6.1 The WP Ultimate Exporter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘export_name’ … wordfence
b2694fd0-0ad6-4b64-b332-aa7bc2f74cd5 MEDIUM 6.1 A cross-site scripting (XSS) vulnerability in the custom-map plugin through 1.1 for WordPress allows remote attackers to… wordfence
b2599d30-7ce5-4a25-b46c-e743d9d88dc6
< 1.5.3
MEDIUM 6.1 The Druco theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.5.… wordfence
b2594fcc-ae07-4f3f-a4fe-0c19524b0193
< 1.5.6
MEDIUM 6.1 The Survey Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions… wordfence
b249d628-a6aa-4fc6-b1f7-91b674054fc8 MEDIUM 6.1 The FancyBox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, … wordfence
b24506c2-bf5e-4c71-94a5-c557a09f9f0d MEDIUM 6.1 The 评论小秘书 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` … wordfence
b2413083-262c-4646-91fa-f9b51010f3e3 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in asset-studio/icons-launcher.php in the WP App Maker plugin 1.0.16.4 and earl… wordfence
b23d4868-068a-4ee9-8253-8f7063cdb03e
< 7.10.43
MEDIUM 6.1 The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO. wordfence
b23b6df6-e723-4b25-aa5d-6b3be05c6f98 MEDIUM 6.1 The Seven Stars - Modern Responsive MultiPurpose Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripti… wordfence
b23989c2-6cd7-4e55-b019-324644e7521a
< 6.4.1
MEDIUM 6.1 The ARForms - Premium WordPress Form Builder Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
b239185f-c368-4768-8f6a-ef9bc593929d
< 14.9
MEDIUM 6.1 The Yoast SEO: Local plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
← Prev 839 840 841 842 843 844 845 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top