πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 134 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c6b395b1-c6fb-4ab9-b446-cba9e32ca65d
< 2.0.11
HIGH 8.8 The Accessibility Suite by Online ADA plugin for WordPress is vulnerable to generic SQL Injection via several parameters… wordfence
c6ae2633-caf6-4319-ba81-e71a673c89ee
< 3.7.10
HIGH 8.8 SQL injection vulnerability in the wp_untrash_post_comments function in wp-includes/post.php in WordPress before 4.2.4 a… wordfence
c681d1ac-a5d0-43f2-a1e4-0684cd56a3b8
< 4.0.11
HIGH 8.8 The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress … wordfence
c66d0fb4-e2df-4bdb-8ccb-18a96173a55d
< 16.8
HIGH 8.8 The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p… wordfence
c648aace-93d9-46c9-bf10-80286c81422c
< 4.4.3
HIGH 8.8 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Local File Inclusi… wordfence
c647beda-cf73-4372-975f-a8c8ed05217f
< 2.7.1
HIGH 8.8 The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data … wordfence
c5f3e34d-07fb-4e49-a4e2-f8e92301b35e HIGH 8.8 The FreeMind WP Browser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
c5eb9b1f-39d5-4c5d-8fb3-71d4bbe5f43a
< 2.8.22
HIGH 8.8 The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … wordfence
c5e26a56-bba0-4204-bcb7-c5ec123a9b2d
< 0.6.6
HIGH 8.8 The Link Whisper Free plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.6.5 due to… wordfence
c5d6e18b-00d0-4f02-b56b-692170c08d99
< 6.0.1
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allow… wordfence
c5b2e22c-3811-4bf8-a8da-2ca9c38333dc
< 1.0.10
HIGH 8.8 The Realty Workstation WordPress plugin through 1.0.9 does not sanitise and escape the trans_edit parameter before using… wordfence
c5a0b8fe-d284-4780-84b5-2e97fa96c99a
< 3.3.1
HIGH 8.8 The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to… wordfence
c59a365c-7fed-431b-8c28-a3b04f9828fe
< 2.3.5
HIGH 8.8 The Striking theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.3.4. This… wordfence
c4fe6dcc-93c8-4956-85ae-a1125bc84509 HIGH 8.8 The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… wordfence
c4f19302-70a5-4132-b841-fba1dd86a0d3
< 1.3
HIGH 8.8 The SEO Change Monitor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2 due to … wordfence
c4cd477c-29c5-4715-bffb-55754858f9fc
< 4.3.7
HIGH 8.8 The WpEvently plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.3.6 via des… wordfence
c4aa2813-6920-4886-b6d2-78fbcd00bdf7
< 1.2.10
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in Social Sharing Plugin versions prior to 1.2.10 allows remote attacker… wordfence
c4a70eec-ee14-4bef-8d23-5954b1f1baf5
< 3.2.1
HIGH 8.8 The Cache Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.… wordfence
c453aaf6-767d-4929-bbb3-3c0b78b0507a
< 1.8.1
HIGH 8.8 The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all vers… wordfence
c43c060b-7a18-49ee-a753-ae1ed2f7e04d HIGH 8.8 The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in version… wordfence
c3dd6240-bb39-49a3-b012-773a831d2034
< 7.6.5
HIGH 8.8 The Themify Builder plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.6.3. … wordfence
c3da10da-8de3-4547-abe4-202002728c80
< 7.2.1
HIGH 8.8 BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2… wordfence
c3b42bd3-f7d3-43d1-bdd8-4389fd82e1e9
< 2.0.7
HIGH 8.8 wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric… wordfence
c3a647b6-ed9e-402d-9424-2937f7aa8960
< 1.8.1
HIGH 8.8 The BoomBox Theme Extensions plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu… wordfence
c3938bbb-dc3d-4550-a05d-0cde970e38f8 HIGH 8.8 The Category and Product Woocommerce Tabs plugin for WordPress is vulnerable to Local File Inclusion in all versions up … wordfence
← Prev 131 132 133 134 135 136 137 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top