πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 23, 2026
Last Updated

40,117 vulnerabilities found (page 844 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b11babc0-285e-4ea3-a3cc-21938af5d83c MEDIUM 6.1 The Error Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
b1106654-a36d-47a5-9db8-a897a0a45ef3
< 1.4
MEDIUM 6.1 The LeadLab by wiredminds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, an… wordfence
b10c0b70-5aa7-4ec6-9041-6ca7b714905b MEDIUM 6.1 The Newsletter subscription optin module plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
b10303e0-c864-4088-91d1-d38c24094812
< 1.8.1.3
MEDIUM 6.1 The Contact Form by WPForms (Free and Premium) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in v… wordfence
b0f2bdbf-96a5-4f3a-88c1-455b938eba03 MEDIUM 6.1 The Simple Poll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
b0e73380-6eab-47d9-b328-f0eb5c7e763d MEDIUM 6.1 The Hamburger Icon Menu Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
b0e340d7-72ad-4a48-8c7c-e5ca61108007
< 2.3.0
MEDIUM 6.1 The MBE eShip plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
b0d9362f-3f34-4602-b19f-2d283e4fe22d
< 3.1.10
MEDIUM 6.1 The my-calendar plugin before 3.1.10 for WordPress has XSS. wordfence
b0d7e56d-453f-4df0-8cf5-32d8bafc60d5
< 3.0.0
MEDIUM 6.1 The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows atta… wordfence
b0cde64f-2533-46e0-9268-b9d100fb0a82
< 2.2.2
MEDIUM 6.1 The Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | WordPress plugin… wordfence
b0b71f57-a641-4320-bec1-670bbbfbc708
< 2.4.2
MEDIUM 6.1 The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues. wordfence
b0b68f4f-654b-4f28-a2d7-2ce657151d57 MEDIUM 6.1 The WOOEXIM – WooCommerce Export Import Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… wordfence
b0b223e8-7659-4220-acb6-70dfd4c101f4
< 2.12.0
MEDIUM 6.1 The WooCommerce Menu Cart plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_que… wordfence
b09f50b7-6d2d-4de0-8a31-6e03d54d188b
< 4.4.8
MEDIUM 6.1 The lbg-audio4-html5-shoutcast plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up t… wordfence
b09dc4dc-d2b9-452a-b005-b69feffdbecf
< 1.4.8
MEDIUM 6.1 The WooCommerce Additional Fees On Checkout (Free) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
b09c98f2-6492-41e1-8d87-e10ed2ef5f9f
< 2.1.9
MEDIUM 6.1 The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripti… wordfence
b09a8d0a-6940-4244-b116-25a1e82cccf7 MEDIUM 6.1 The PostLists plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI in all versions up to… wordfence
b092bee4-3e33-48cb-a88d-05231b1d4905 MEDIUM 6.1 The LMS theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 9.7 due to… wordfence
b08b8a3a-3acd-41e7-b6e4-aa8c61a5f80c
< 1.5.1
MEDIUM 6.1 The Nooni theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 1.5.1 due to insufficien… wordfence
b075e806-4833-44cb-9a51-108ed79faae4 MEDIUM 6.1 The WP-Ban-User plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
b06cb3cf-e2da-4e18-9a09-c30cebddf5c2
< 3.4.0
MEDIUM 6.1 The Sugar Calendar – Simple Event Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due … wordfence
b061fbf2-4bb3-4ccc-ba90-1e947365435e
< 2.1
MEDIUM 6.1 The Binary MLM Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
b05b42d8-057b-4889-add9-e2830633023c MEDIUM 6.1 The Easy Automatic Newsletter Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions … wordfence
b0485897-4d1d-442d-9c81-4b4bb40e3983
< 2.0.8
MEDIUM 6.1 The Easy Digital Downloads (EDD) Content Restriction extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x… wordfence
b02b5ea6-e112-4255-833c-87ee939986b0
< 3.3.0
MEDIUM 6.1 The `Kudos Donations – Easy donations and payments with Mollie` plugin for WordPress is vulnerable to Reflected Cross-… wordfence
← Prev 841 842 843 844 845 846 847 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top