🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 843 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b22aaac4-39f1-482b-9fc7-79825cf2e818
< 4.1
MEDIUM 6.1 The WP Support Plus Responsive Ticket System plugin for WordPress is vulnerable to JavaScript Injection in versions up t… wordfence
b2181c89-4f40-45b9-8c12-448ca263a2f2
< 2.2.4
MEDIUM 6.1 The BuddyPress Docs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_… wordfence
b20e5257-1fb7-40b4-8ad8-798372b60972 MEDIUM 6.1 The Easy FAQ with Expanding Text WordPress plugin through 3.2.8.3.1 does not sanitise and escape its settings, allowing … wordfence
b1ef6f6a-04bf-4f9d-b6ed-21eed8c389e2 MEDIUM 6.1 The AHAthat Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI parameter in all… wordfence
b1e45860-16c4-4d13-aad9-c742a8eced37
< 3.2.0
MEDIUM 6.1 The MailMunch – Grow your Email List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the u… wordfence
b1e24114-2993-42bd-9711-45e24853feec
< 2.0.9
MEDIUM 6.1 The CM Map Locations plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
b1d8a9b5-e833-4810-a13a-fd360752e711
< 1.6.3
MEDIUM 6.1 The CataBlog plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions bef… wordfence
b1d571a0-5db2-4132-9b6c-9ffead418776 MEDIUM 6.1 The Opentracker Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
b1be1928-a278-48d5-beb2-00e3c8df3fa9
< 2.0.22
MEDIUM 6.1 The Ultimate Member plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.0.21 … wordfence
b1ae1b28-ea9e-4446-8b03-b5a8eaac1042
< 2.0.3
MEDIUM 6.1 The salient-core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all ve… wordfence
b1adb414-8945-4e11-8770-dab3285d608e
< 3.3.24
MEDIUM 6.1 The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ paramet… wordfence
b19af06d-7262-4d21-ac39-7d4ce8e75d71
< 4.0.10
MEDIUM 6.1 The Podlove Podcast Publisher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
b19aa8ca-0ce8-4a9a-8f71-7d7e67e8f99b
< 1.20
MEDIUM 6.1 The WordPress Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o… wordfence
b18abec6-c2e7-4c84-93c8-c19422ce5d1c MEDIUM 6.1 The Pay with Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … wordfence
b186c98e-6a8d-4675-aaaa-c6748319dec1
< 4.6.4
MEDIUM 6.1 The Albo Pretorio Online plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
b183587b-95bd-4e82-bfc7-db5a8fbd58f9
< 1.4
MEDIUM 6.1 The PDF Thumbnail Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_q… wordfence
b17c5b5e-26d9-485d-881e-bd4414f29f1a
< 1.2.9
MEDIUM 6.1 The Easy Digital Downloads (EDD) Pushover Notifications extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.… wordfence
b173523a-e79d-4d2d-af67-5372576df220
< 3.11.2
MEDIUM 6.1 The Fusion Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the User Register element in… wordfence
b157faa9-0d43-4ac6-ab4d-19a5911aecbd MEDIUM 6.1 The WP Controller plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
b14dec28-41f9-460f-aa6c-3e6baf2498d8
< 3.7.0.1
MEDIUM 6.1 The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin be… wordfence
b14cada2-5d04-47a1-b648-048fcbabd2b5
< 1.3.21
MEDIUM 6.1 The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter bef… wordfence
b13f1fb2-5dbc-4d7d-b4cc-b6dc6804531a
< 7.4
MEDIUM 6.1 The SEO Redirection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in … wordfence
b1351915-5f00-48d0-a768-cd9aea533b60 MEDIUM 6.1 The Smoothness Slider Shortcode plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
b133d48c-3a42-43ba-8049-05e745b96501 MEDIUM 6.1 The iCal Feeds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
b12b0a2a-3c3c-4d9c-a404-c8f170638e31
< 1.3.2
MEDIUM 6.1 The Log HTTP Requests plugin for WordPress is vulnerable to Stored Cross-Site Scripting via logged HTTP requests in vers… wordfence
← Prev 840 841 842 843 844 845 846 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top