πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 132 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cbff92c1-8492-4d0d-bd90-8fd33625bf6f
< 67.2.0
HIGH 8.8 The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing … wordfence
cbfbb06c-f048-4912-9ff7-59aa10bc96bd
< 4.7.0
HIGH 8.8 The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.6.9 … wordfence
cbe8cf6c-b1fa-4f71-bb63-c8b181e54882
< 6.6.11
HIGH 8.8 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authe… wordfence
cbcd978b-e81f-4c39-b2f7-adc948d21b1b
< 3.2.7
HIGH 8.8 The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to privilege escalation due t… wordfence
cbb51383-1eab-4490-aa4c-bd1488312400
< 1.2.3
HIGH 8.8 The Trust Payments Gateway (3DS2) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
cb37b784-b1ff-4cee-889d-751218e5b95d
< 5.3.3
HIGH 8.8 The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type… wordfence
cb1dc7e4-a339-4760-9f63-aaa6590bd5e0
< 2.3.29
HIGH 8.8 The GigPress plugin for WordPress is vulnerable to SQL Injection via shortcode attributes in versions up to, and includi… wordfence
cb158acc-69d7-4a7d-b356-7de1f6b37019
< 5.1.9
HIGH 8.8 The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.… wordfence
cb105ff0-5085-4813-81a6-b1f0798d576c
< 4.0.8
HIGH 8.8 Several MainWP extensions for WordPress are vulnerable to Cross-Site Request Forgery due to missing or incorrect nonce v… wordfence
cabb9be3-581a-48d9-afa2-929921eae52d
< 1.3.1
HIGH 8.8 The Consulting Elementor Widgets plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and … wordfence
cab9f082-6f9d-443c-8cf0-4cfe2516e39c
< 1.4.6
HIGH 8.8 The Material Dashboard plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.… wordfence
cab2f0d7-f288-4462-b2a7-7a999cd47466
< 1.2.66
HIGH 8.8 The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF. wordfence
ca9c10b6-6d32-45c9-beb1-7a5c84d0863d
< 3.7.3
HIGH 8.8 The I Recommend This plugin for WordPress is vulnerable to SQL Injection via the 'post_type' attribute called via the pl… wordfence
ca64692b-b194-4ceb-975e-72e4041252f2 HIGH 8.8 The Link Optimizer Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in vers… wordfence
ca564941-4780-4da2-b937-c9bd45966d81
< 3.6.0
HIGH 8.8 The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
ca46ea28-3115-4db1-8aeb-cbef731b0376
< 2.1.0
HIGH 8.8 The wpForo Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.… wordfence
ca132d26-e927-41f1-be57-0c3bdeace2e6
< 0.4.13
HIGH 8.8 The Fontsampler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ajax_get_mock_fontsampler func… wordfence
ca064db0-2718-4521-9467-335b59208858
< 1.2.4
HIGH 8.8 The JVM Gutenberg Rich Text Icons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type … wordfence
c9fc747c-3b13-4a49-a181-fe6a952a4ce3
< 1.1.2
HIGH 8.8 The Error Log Viewer WordPress plugin through 1.1.1 does not perform nonce check when deleting a log file and does not h… wordfence
c9f8e9b5-f4bf-48e3-b315-1b9b24be6e93
< 1.0.13
HIGH 8.8 The Journey Analytics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
c9d58fde-54f6-4892-b5ed-2029593c3fa4
< 2.2.7
HIGH 8.8 The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF bug with Reflected XSS. wordfence
c9cf97a6-38bb-4499-98f0-ca2b7111f654 HIGH 8.8 The UltraPress theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.2 via… wordfence
c9c2fb7f-a05b-4852-97eb-7befe880d703
< 7.1.8
HIGH 8.8 The Booster Elite for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type … wordfence
c9c29130-1b42-4edd-ad62-6f635e03ae31
< 3.7
HIGH 8.8 The Cyr to Lat plugin for WordPress is vulnerable to authenticated SQL Injection via the 'ctl_sanitize_title' function i… wordfence
c9b09489-9f32-41f6-befd-7c08612d3edc
< 0.3.4
HIGH 8.8 The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.3.… wordfence
← Prev 129 130 131 132 133 134 135 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top