🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1028 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cc6f017d-b0ba-494d-9ad1-8b6cdca48fb1
< 1.0.77.33
MEDIUM 5.5 Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP … wordfence
cc0e133d-b1c7-42c4-bd1f-7b91f0ec4fb3
< 3.8.2
MEDIUM 5.5 Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in René Hermenau's Social Media Share Buttons pl… wordfence
cb610baa-093d-4a41-8e28-c65fdb0e32aa
< 7.6
MEDIUM 5.5 The ANAC XML Bandi di Gara plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in… wordfence
cb56b00c-31dd-4076-aeaf-9b249f04f1c6
< 1.6.6
MEDIUM 5.5 The WBW Currency Switcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blockip’ parame… wordfence
ca6b7886-790a-4f00-855c-6dc913ea01db
< 1.10.2
MEDIUM 5.5 The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘exclusion_list’ p… wordfence
ca1316be-1978-46c1-8685-10a8d4c34bdb
< 1.15.32
MEDIUM 5.5 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Store… wordfence
c96b9599-b1a5-4aa6-85fe-7af3f12d1776
< 7.1
MEDIUM 5.5 The LiteSpeed Cache plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includi… wordfence
c85f6c1b-673d-4fe9-acef-a15d90fcf414 MEDIUM 5.5 The Quizlord plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unspecified parameter in versions … wordfence
c8582af5-92e9-43ef-836f-d87d5cf827d8
< 2.9.14
MEDIUM 5.5 The Affiliates Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parame… wordfence
c83a2c4d-a264-49ec-85f1-e3f48715d725
< 4.7.34
MEDIUM 5.5 WordPress Core is vulnerable to CSS Injection in all versions up to, and including, 7.0.2 due to insufficient sanitizati… wordfence
c825723b-2ec5-4af8-91a1-454d35a7f1bb
< 1.1.7
MEDIUM 5.5 The WP Live Chat + Chatbots Plugin for WordPress – Chaport plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
c7d215e9-e615-46ab-b0b8-b37f10cfae98
< 1.0.12
MEDIUM 5.5 The ZeroBounce Email Verification & Validation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm… wordfence
c7112f34-3055-4033-82ba-d59489cd8c6b
< 2.8.4
MEDIUM 5.5 The Wise Chat plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.8.3. This allows u… wordfence
c6d45e18-7aa0-4f73-bf07-069870b467f4
< 2.1.9
MEDIUM 5.5 The WP-Paginate WordPress plugin before 2.1.9 does not escape one of its settings, which could allow high privilege user… wordfence
c6cd7986-6d3b-426b-a539-8dc11f0d7b04 MEDIUM 5.5 The Client Dash plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.2.0 due t… wordfence
c6b079f5-715d-4fb3-bcaf-539412d5e956 MEDIUM 5.5 The MyBB Cross-Poster WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation… wordfence
c68a9b05-5e60-4d5f-9d00-a9a5b85271f2
< 5.2.1
MEDIUM 5.5 The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters i… wordfence
c648fbb1-cc12-4334-b334-0f784542ab6d
< 1.2.6
MEDIUM 5.5 The FormCraft WordPress plugin before 1.2.6 does not sanitise and escape Field Labels, allowing high privilege users suc… wordfence
c5a2d57d-eaa1-4a8a-86cb-f28adf13fab2
< 5.9.6
MEDIUM 5.5 The Icegram Express Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inc… wordfence
c59871cc-2d62-4eea-a78b-19810570c47d
< 3.2.1
MEDIUM 5.5 The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new soci… wordfence
c56b1dca-3841-48df-837e-7973940e74e3
< 2.1.4
MEDIUM 5.5 The Breeze plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘breeze_api_token’ parameter in… wordfence
c53ebf2f-44ab-4d0f-ac3d-c08806c07343 MEDIUM 5.5 The Live Gold Price & Silver Price Charts Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
c5203a17-cc4f-4545-a231-dfbfb900f0fd
< 1.3.6
MEDIUM 5.5 The BuddyPress xProfile Checkout Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bf… wordfence
c4d552a7-499f-4946-b0ec-5f733c01a365
< 3.4
MEDIUM 5.5 The WP eBay Product Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters … wordfence
c476d9af-9060-4294-874a-86e550253d3b
< 27.0
MEDIUM 5.5 The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 du… wordfence
← Prev 1025 1026 1027 1028 1029 1030 1031 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top