🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1064 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cb649fb2-2d0e-4fe3-89d5-90bcbc0bcfcf
< 1.18.0
MEDIUM 5.4 The Popup Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
cb5f5e33-e066-4a85-9367-4b8c2f948adf MEDIUM 5.4 The PDF Catalog for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pdfcatalog' A… wordfence
cb4e3b3c-20f4-4591-af0a-539b405d675e
< 4.2.3
MEDIUM 5.4 The Ultimate Product Catalog plugin for WordPress is vulnerable to SQL Injection via the ‘CatID’ parameter in versio… wordfence
cb47b6cc-87e4-4d29-bbc7-6d7552bc3943
< 1.3.60
MEDIUM 5.4 The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compa… wordfence
cb08cf02-4766-4093-9306-3b4581f54f77 MEDIUM 5.4 The Responsive Image Gallery, Gallery Album plugin for WordPress is vulnerable to unauthorized modification of data and … wordfence
cb0261c6-0477-4769-b92a-b49a192df4bb
< 4.10.32
MEDIUM 5.4 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Glob… wordfence
cae1e209-96f3-49ed-a233-768db8e36c5b
< 3.8.5
MEDIUM 5.4 The Event Management, Events Calendar, RSVP Event Tickets Plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
cac9614d-3fe5-4657-af6b-81acb71f51f1
< 3.2.18
MEDIUM 5.4 The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup… wordfence
ca66afc3-a749-4ddc-8e2f-959f65cebd45
< 3.3.3
MEDIUM 5.4 The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
ca17fd4a-fd14-46e6-9348-19b74fec5df8
< 1.5.0
MEDIUM 5.4 The Display Post Metadata for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_fields’ parameter… wordfence
ca058dde-48fd-46f4-b16c-97cdf79578ff
< 4.9.24
MEDIUM 5.4 The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Cross-Site Request Forgery in versio… wordfence
c95505e3-6851-476e-af40-bb841eb01be7
< 3.7.31
MEDIUM 5.4 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider t… wordfence
c9176a81-fe51-48dd-a151-4596443b430f
< 6.5.8
MEDIUM 5.4 The WP Ultimate CSV Importer plugin for WordPress is vulnerable to authorization bypass due to a missing capability chec… wordfence
c89d56e2-68aa-4caf-bc1b-9aa32ec11ba3
< 2.0.7
MEDIUM 5.4 WordPress Plugin Gravity Forms is prone to a cross-site scripting vulnerability because it fails to properly sanitize us… wordfence
c829217a-c5be-4713-bbf4-c1ba829c1187
< 4.8.0
MEDIUM 5.4 The Affiliate For WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability che… wordfence
c79fd08c-97bc-4d55-832e-92d0897bc3dc
< 1.4.5
MEDIUM 5.4 The Protected Posts Logout Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
c75e6d27-7f6b-4bec-b653-c2024504f427
< 8.0.9
MEDIUM 5.4 The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
c6f0b546-efd2-4592-a9c1-4784e13209d8
< 3.7
MEDIUM 5.4 The WP Clone any post type plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.6… wordfence
c6b3d91c-591b-444d-888b-1b443e72afca
< 1.0.17
MEDIUM 5.4 The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it b… wordfence
c674bb2a-8ecf-4aea-a729-c9bdf4ee35fd
< 3.7.15
MEDIUM 5.4 WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute fr… wordfence
c6683edc-8c77-446c-bd7e-e97b8c5d0c57
< 1.0.0.29
MEDIUM 5.4 The WordPress plugin Gallery for Social Photo is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
c62860e2-8c89-4f1c-a7d8-ef13f545ad52
< 2.3.4
MEDIUM 5.4 In the GetPaid WordPress plugin before 2.3.4, users with the contributor role and above can create a new Payment Form, h… wordfence
c60ddcba-99e7-4cba-8bee-f2b01369b025 MEDIUM 5.4 The Spreadconnect plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
c5e516d6-eece-42d3-9349-29be685a3509
< 2.23
MEDIUM 5.4 The Pure Chat plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2… wordfence
c5b67927-5993-4e21-af52-8ebe7fee48ab
< 3.9.13
MEDIUM 5.4 The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gu… wordfence
← Prev 1061 1062 1063 1064 1065 1066 1067 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top