πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1288 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c5f9bc43-6a93-495d-b2af-954aafcf3dfe
< 4.7.8
MEDIUM 4.4 The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to Stored Cros… wordfence
c5da24e6-442f-450c-91d3-581719dc7210 MEDIUM 4.4 The ClickSold IDX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… wordfence
c5c3dd80-c6e0-4e7f-a921-712f3c3257a3
< 2.2.0
MEDIUM 4.4 The The GDPR Framework By Data443 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i… wordfence
c5a9df99-3b0a-4689-ade3-a09d0cd2a049
< 3.2.13
MEDIUM 4.4 The Nested Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up… wordfence
c596c278-4f16-4830-8e6e-5e1392d4d118 MEDIUM 4.4 The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
c592887c-718c-46d7-8dc3-d337711471ee MEDIUM 4.4 The Next Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in versions up to, and incl… wordfence
c575f3f5-3a0b-4b88-9d9a-5e8212a02144
< 5.3
MEDIUM 4.4 The Comment Approved Notifier Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
c525344a-fb62-48c9-bfd2-a77f59da3470 MEDIUM 4.4 The Pocket Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… wordfence
c51b066c-84d2-4791-b863-6a98b954e4a3
< 1.4.4
MEDIUM 4.4 The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
c4f8e79b-a1ba-486c-8f64-d216ef5bb2f7
< 1.4
MEDIUM 4.4 The Social Share Buttons, Social Sharing Icons, Click to Tweet β€” Social Media Plugin by Social Snap plugin for WordPre… wordfence
c4cad108-6574-4f14-8a37-89c4c10279d6 MEDIUM 4.4 The wpView plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and i… wordfence
c4ab6fcd-9c03-4bab-8e31-57b57e67e1e3
< 2.3.8
MEDIUM 4.4 The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settin… wordfence
c4a6b786-d0ef-41f6-b2bf-83307ec02b91
< 1.3.5
MEDIUM 4.4 The Insert PHP Code Snippet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user's name when a… wordfence
c468a56c-4411-49fc-8014-fc9b71a645c3
< 2.9.8
MEDIUM 4.4 The RSS Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions… wordfence
c44232a9-7b97-449c-b584-ca3c26d63581
< 1.5.8
MEDIUM 4.4 The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ce_venue_name' parameter… wordfence
c41b6c52-4da8-427b-8f5d-6a3339dad3cd
< 2.4.15
MEDIUM 4.4 The Flying Images: Optimize and Lazy Load Images for Faster Page Speed plugin for WordPress is vulnerable to Stored Cros… wordfence
c40752df-1337-475b-8b5e-0d171946bfe9
< 4.5.5
MEDIUM 4.4 The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, a… wordfence
c3fa13d6-e8c7-4f89-8dc2-d2be0055830b
< 2.2.0
MEDIUM 4.4 The Welcome Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.… wordfence
c3f0032e-a6f4-47f5-b3eb-6f1c9bf9670c
< 6.0.10
MEDIUM 4.4 The Simple File List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up… wordfence
c37686f8-6bd7-4c06-b80a-7d6849bbc7b0
< 1.5.8
MEDIUM 4.4 The Snap Pixel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, a… wordfence
c3508b46-6920-48b9-9acb-620ea34e07e2
< 3.4.9
MEDIUM 4.4 The Branda plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and i… wordfence
c346b7d8-d1d4-473d-9388-e38631658c78 MEDIUM 4.4 The WP Carticon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carticon_js_script' parameter… wordfence
c33d9295-0c7f-45a0-9d62-4293c8bbef0b
< 3.32
MEDIUM 4.4 The Admin Page Spider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio… wordfence
c339bf65-c522-4954-8aed-275c51298aea
< 7.4.4
MEDIUM 4.4 The List View Google Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event descriptio… wordfence
c328cdb2-2ca9-4bad-9d6d-be10e0cb3765
< 3.1.9
MEDIUM 4.4 The Chartify plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.7 d… wordfence
← Prev 1285 1286 1287 1288 1289 1290 1291 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top