🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1287 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c9fd7c6b-9ba3-4e27-9b3d-8b1fbcc5e26f
< 2.0.6
MEDIUM 4.4 The Email Reminders plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
c9de6f14-67e4-40c2-8efb-7e9cad659d37
< 2.8
MEDIUM 4.4 The Floating Contact Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … wordfence
c9cbacbf-5ce2-4dd3-9f0b-6049b83a16c6
< 2.1.8
MEDIUM 4.4 The Add Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers… wordfence
c9ab868b-51ab-4dad-b662-8302cda9c0e7 MEDIUM 4.4 The WWM Social Share On Image Hover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings… wordfence
c9842bb5-0a71-40a9-83bc-f1841b660693
< 2.1.8
MEDIUM 4.4 The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions… wordfence
c8fe4c70-c196-4f20-b787-bea223726fab
< 4.2.2
MEDIUM 4.4 The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
c8ebbf22-9bce-4d82-aecf-82080386e7e2
< 3.5.4
MEDIUM 4.4 The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
c8db0c54-0a68-41bc-832f-1e0e1a92d167
< 1.10
MEDIUM 4.4 The Embed Peertube Playlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and… wordfence
c8b87b01-e445-4372-b687-6e0b54de66d3
< 3.2.10
MEDIUM 4.4 The Nested Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2… wordfence
c879123c-531e-43d8-a7d3-16a3c86b68a3
< 1.2.41
MEDIUM 4.4 The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
c877af68-1caa-412c-818a-031bd788660a
< 1.0.2
MEDIUM 4.4 The 404 Page by SeedProd plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
c83df43e-286d-4695-9c37-bee2870fd3b5
< 2023
MEDIUM 4.4 The Stop Spammers Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versi… wordfence
c8032213-52e7-4222-a9a5-13fa64d66213
< 1.9.0
MEDIUM 4.4 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
c7c0a72a-08fe-4365-b762-93a96455a589 MEDIUM 4.4 The CB (legacy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
c78ec44e-c3e4-410e-9937-46657664d6cb
< 0.10.1
MEDIUM 4.4 The CodeColorer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, … wordfence
c787d28e-c942-415d-8227-ce3e940fd0cc
< 7.2.2
MEDIUM 4.4 The AGCA – Custom Dashboard & Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin s… wordfence
c76e7110-ff61-4fa9-8a29-b1b562187bb5
< 2.0.9
MEDIUM 4.4 The WP Announcement plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
c70865c8-3c63-4988-a1fd-f8f10c20228f
< 3.2.9.1
MEDIUM 4.4 The WordPress CRM Plugin – WP-CRM System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin s… wordfence
c6f61e13-20fb-4cef-bae7-2cd5fa038175 MEDIUM 4.4 The User Language Switch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tab_color_picker_lan… wordfence
c6c52046-c85d-46af-b36c-41c70dad5426 MEDIUM 4.4 The Link Hopper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hop_name’ parameter in al… wordfence
c6c1a446-055b-4ac4-bceb-451c0fbe6369 MEDIUM 4.4 The MF Gig Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions… wordfence
c69c9119-9360-401c-956b-0e782122784f MEDIUM 4.4 The Powie's Uptime Robot plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
c6927b4f-f47e-47fc-a5bf-b7fa42c31412
< 2.6.8
MEDIUM 4.4 The Email Customizer for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email templat… wordfence
c681956c-7d96-4e32-af81-a573a0840bb6
< 3.2.24
MEDIUM 4.4 The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
c60f68e6-67f7-4a08-916c-83a1ab34fea6 MEDIUM 4.4 The ImageMagick Sharpen Resized Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti… wordfence
← Prev 1284 1285 1286 1287 1288 1289 1290 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top