ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,117
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 24, 2026
Last Updated

40,117 vulnerabilities found (page 984 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1bea55b5-b2d7-4eaf-8868-d2645ce18619
< 2.0.19.9
MEDIUM 6.1 The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to t… wordfence
1bdae07c-cb80-4566-9b90-7b144c6ceeb0 MEDIUM 6.1 The Complag plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable… wordfence
1bd61124-d4af-4c88-be96-579c735b7b49 MEDIUM 6.1 The yContributors plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
1bce11fa-428d-4f44-9ce4-e12e79c43ff1 MEDIUM 6.1 The Allure Real Estate Theme for Placester theme for WordPress is vulnerable to Cross-Site Scripting via the 'ZeroClipbo… wordfence
1bc9d02d-7916-4845-bb9d-f5eb2666b772 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in getNetworkSites.php in the CBI Referral Manager plugin 1.2.1 and earlier for… wordfence
1bb9259e-f65a-4cb3-9401-35be0212c182 MEDIUM 6.1 The Widget Logic Visual plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
1bb2b1f9-fd76-440e-a64c-ff11622efec1
< 1.4.3
MEDIUM 6.1 The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the… wordfence
1bb1db1b-bf25-4a09-9c8a-e7b1ef42cc7a MEDIUM 6.1 The Jet Footer Code plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
1bae23a4-0f25-430f-8bad-6ec7b2de3dbe
< 2.7.1
MEDIUM 6.1 The WooCommerce Stored Exporter WordPress plugin before 2.7.1 was affected by a Reflected Cross-Site Scripting (XSS) vul… wordfence
1bad3803-77c3-4c9f-906c-ba5b1886c997 MEDIUM 6.1 The GB Team Stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘data’ parameter in v… wordfence
1ba1844f-96fb-458e-b428-bbc896977cd1 MEDIUM 6.1 The EZ Form Calculator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
1ba077d6-b3d3-4a28-8b08-b8bf947e900c
< 1.2.6
MEDIUM 6.1 The Hive Support plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, … wordfence
1b996e76-770f-41cc-9601-4e1a3e0127bf
< 2.4.1
MEDIUM 6.1 Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugi… wordfence
1b92f42e-d596-434f-b42e-2cd34f6f95a1 MEDIUM 6.1 The Custom Users Order plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
1b8b0f14-f31a-45cd-bb98-0b717059aa80
< 1.8.12
MEDIUM 6.1 Several themes for WordPress by DeoThemes are vulnerable to Reflected Cross-Site Scripting via breadcrumbs in various ve… wordfence
1b89910b-ca2c-45a0-8b82-2bb9607fbe20
< 0.1.0
MEDIUM 6.1 The Neom Blog theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.0.… wordfence
1b8085e5-073a-4de1-95d7-6a1aa331d6f6
< 4.9.4
MEDIUM 6.1 The WP Front User Submit / Front Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions… wordfence
1b71eae9-9727-49c9-9926-85689286983f
< 2.0.5
MEDIUM 6.1 The Social Slider Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_… wordfence
1b69831e-19ab-4812-b657-dc4febe15077
< 0.4.5
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPr… wordfence
1b68ff1e-ef79-4c11-a73c-591177d8dffe
< 2.0.4
MEDIUM 6.1 The Run Contests, Raffles, and Giveaways with ContestsWP plugin for WordPress is vulnerable to Reflected Cross-Site Scri… wordfence
1b5dee10-7dd3-4ce7-9e37-e54fc98dbc7b MEDIUM 6.1 The Nepali Date Utilities plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
1b583679-898f-47c3-aea5-0e3667c4043d
< 2.20
MEDIUM 6.1 The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up … wordfence
1b423aca-e0d2-487d-a861-a2b589c2a62e
< 1.12.1
MEDIUM 6.1 The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell. wordfence
1b3b4b45-5964-490a-991b-c9eb79c670e2
< 1.9.1
MEDIUM 6.1 The WPO365 | Mail Integration for Office 365 / Outlook plugin for WordPress is vulnerable to reflected Cross-Site Script… wordfence
1b384e1a-4e6d-4272-b9b2-bbb6b9baa5d2
< 1.5.3
MEDIUM 6.1 The Assistant – Every Day Productivity Apps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in al… wordfence
← Prev 981 982 983 984 985 986 987 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top