🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 133 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c9a9675f-76f5-4551-8d2d-60ae7a8378d1 HIGH 8.8 The Marketing Automation by AZEXO plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and … wordfence
c99e7f4c-ba91-4d64-b8d4-23940381e79a
< 2.0.0
HIGH 8.8 The Simple Personal Message plugin for WordPress is vulnerable to SQL Injection via the ‘message’ parameter in versi… wordfence
c964c99b-f751-4e81-b6bf-f10a3b1106ba
< 1.3.13
HIGH 8.8 The WP Posts Carousel plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.1… wordfence
c958880e-6068-4e7d-a780-1251f3ab9bf7
< 5.2.8
HIGH 8.8 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege es… wordfence
c943cf0b-0e99-4d47-808d-2b803369d53a
< 3.6
HIGH 8.8 The Popup with fancybox plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to… wordfence
c90844e1-0502-4d08-888f-4835f63f8dd0
< 3.7.38
HIGH 8.8 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object … wordfence
c906a988-ad45-49cc-9d77-6b501445ddc5
< 1.0.0.27
HIGH 8.8 The plugin Gallery for Social Photo is vulnerable to SQL Injection via the post parameter in the function gifeed_duplica… wordfence
c901f85d-fcdb-43e5-8626-f2410e4e328f
< 1.7.9
HIGH 8.8 The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.7.… wordfence
c8dc9fd0-929e-447f-be05-085be98e4d0f
< 1.6.2
HIGH 8.8 The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-ad… wordfence
c8b1015f-6825-4813-b5db-71f1c1e88310
< 1.3.6.6
HIGH 8.8 The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forge… wordfence
c8af0c5c-3d7b-416d-9d10-6867fcf909a5 HIGH 8.8 The WHMPress - WHMCS Client Area plugin for WordPress is vulnerable to unauthorized modification of data that can lead t… wordfence
c8ae0a47-cba5-468e-8d25-7b7176373b9c
< 3.6.1
HIGH 8.8 The ElementsKit Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6… wordfence
c8a1127c-308d-4347-bd42-2071b906e247 HIGH 8.8 The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could… wordfence
c873d838-58e8-4f69-bccb-6d1de8d91877
< 2.1
HIGH 8.8 The Login as User or Customer Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
c8440240-f652-4372-9ed8-f3eb3b8336e0
< 4.0.7
HIGH 8.8 The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions s… wordfence
c829894f-05b8-4c65-9f3a-3a5d6e212cde
< 7.3.11
HIGH 8.8 The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
c7caf1f4-a8dd-4016-91eb-2adbeed5290a
< 1.8.1
HIGH 8.8 The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the w… wordfence
c7bb055d-dd43-4c40-be30-325ecb6d7731 HIGH 8.8 The Amplus theme for WordPress is vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce va… wordfence
c7b540b9-cdf1-40ea-b693-c237e76c0958 HIGH 8.8 Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a reques… wordfence
c77fce42-92e9-43bc-ab3b-599e036ed648
< 3.4.1
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to h… wordfence
c72a6459-f5a7-4b3d-ac70-c685fb90f903
< 2.0.2
HIGH 8.8 The Charety - Charity & Donation WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to miss… wordfence
c7296fdb-d5d6-4d4f-ac80-b9d5452191b4
< 16.01
HIGH 8.8 The WP Symposium Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 16.01. This is … wordfence
c7266ce6-2853-4c5d-9e36-8c5b7418b072
< 1.3.28
HIGH 8.8 The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in versions less than, … wordfence
c6efb57a-9638-44d1-a8d1-8eeadcc81ecc
< 4.2.3
HIGH 8.8 The Analytify – Google Analytics Dashboard For WordPress plugin for WordPress is vulnerable to Cross-Site Request Forg… wordfence
c6ea48b4-b4ef-40e2-ade9-8bf44147e8c7
< 3.4.13
HIGH 8.8 The Post Grid Master plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.4.12… wordfence
← Prev 130 131 132 133 134 135 136 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top