πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1065 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c58fa0a0-0b22-42df-8d3a-c3de78e12aa7
< 1.3.7
MEDIUM 5.4 The DW Question & Answer Pro WordPress plugin through 1.3.6 does not check that the comment to edit belongs to the user … wordfence
c58d9011-a082-48ca-b702-ef5563af2c66
< 1.9.0
MEDIUM 5.4 The Saphali Woocommerce Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
c55ca7d4-6bc0-49c9-8ce0-50fff8775a76
< 7.5.39.7212
MEDIUM 5.4 The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜_fv_player_u… wordfence
c55792d6-3f31-4635-ad5c-17d03a5b2977 MEDIUM 5.4 The WordPress Related Posts plugin through 3.6.4 contains an authenticated (admin+) stored XSS vulnerability in the titl… wordfence
c544c86d-e414-49c2-ae57-3293b1a6409d
< 3.5.1
MEDIUM 5.4 The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct … wordfence
c510063e-1c64-40fa-842a-e7efd3dc550a
< 3.7.30
MEDIUM 5.4 WordPress before 5.2.3 allows XSS in shortcode previews. wordfence
c4f76e1d-23f2-4dff-98eb-c73f7e7f10cb MEDIUM 5.4 The Print Science Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
c4c2689d-be51-4907-b624-c85da39f545d
< 2.0
MEDIUM 5.4 The Easy WP Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
c4b1cae3-dc08-43b1-9a20-62b7263efeba
< 2.0.7
MEDIUM 5.4 The WPCode plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capabilit… wordfence
c46bcbd1-566d-4b21-84a1-f25e3df7ddc7
< 3.0
MEDIUM 5.4 The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulner… wordfence
c454a958-91c4-4847-91f6-dedebf857964
< 4.9.14
MEDIUM 5.4 The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capabil… wordfence
c4006612-770a-482f-a8c2-e62f607914a9
< 2.6
MEDIUM 5.4 The Product Expiry for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a miss… wordfence
c3728280-3487-4cb2-8e37-f33811bc0a22
< 2.18.17
MEDIUM 5.4 The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… wordfence
c3016491-6a6a-433f-9018-5e84f9e3e37c
< 5.5.4
MEDIUM 5.4 The Bulk Delete plugin for WordPress is vulnerable to missing authorization due to missing capability checks on several … wordfence
c2e80e6f-08e7-426b-9797-97483c3dc410
< 2.5.19
MEDIUM 5.4 Cross-site scripting (XSS) vulnerability in the Google Doc Embedder plugin before 2.5.19 for WordPress allows remote att… wordfence
c2cdf4e5-0a40-42ca-b5ac-78511fdd2b77
< 4.3.3
MEDIUM 5.4 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress … wordfence
c1f643bd-a168-4506-9606-0b8b91573ebb
< 2.1.0
MEDIUM 5.4 Stored Cross-Site Scripting (XSS) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers with… wordfence
c1c106e8-9642-4294-90fd-6838cc551b90
< 6.4.5
MEDIUM 5.4 The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
c177440a-4575-4202-be16-ac7ab0fbb90b
< 2.4.7
MEDIUM 5.4 The give plugin before 2.4.7 for WordPress has XSS via a donor name. wordfence
c13bb699-f065-4065-9ea5-bb86d24e09ab
< 2.2.1
MEDIUM 5.4 The PopupKit plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.0. Thi… wordfence
c11ab6ef-90c4-4091-8025-b182cf40f61c MEDIUM 5.4 The CF7 Submissions plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
c10600ae-1ff0-4f12-ae53-39d9342640f4 MEDIUM 5.4 The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and d… wordfence
c0daeb94-1028-4163-af9d-0a6d7a00269f
< 2.1.7
MEDIUM 5.4 The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its … wordfence
c06f9f6d-3cd0-4700-834b-435a99983453
< 1.3.3.379
MEDIUM 5.4 The Surfer plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability … wordfence
c06db4a6-fb17-4fcc-95df-f84ac59cc42c MEDIUM 5.4 The Subresource Integrity (SRI) Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
← Prev 1062 1063 1064 1065 1066 1067 1068 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top