πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 135 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c38a5e59-3233-4b37-bd6f-baf5dc9f9a01
< 3.7.27
HIGH 8.8 WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/… wordfence
c3871a1e-513a-4bc4-a90d-a46cb56780d7
< 2.3.12
HIGH 8.8 The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inc… wordfence
c32ba2a0-a9a7-4f17-8169-912cecc40b7b
< 1.8.4
HIGH 8.8 The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation i… wordfence
c3248327-6e10-420e-83cf-a23296eb2e6f
< 3.3.6
HIGH 8.8 The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missin… wordfence
c30f2322-14b1-476a-bbaf-99a14bc9e017
< 9.7
HIGH 8.8 The Stockholm theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.6. This … wordfence
c30801d1-9335-4bba-b344-f0ff57cecf84
< 7.0.8
HIGH 8.8 The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPre… wordfence
c2fcf51d-ed21-4438-9179-07a56ed97251
< 10.4.1
HIGH 8.8 The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,… wordfence
c2a30bb9-501b-44bd-8121-c137bb1c3ae5
< 1.5
HIGH 8.8 The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php. wordfence
c2663150-61f9-49e3-9219-fbe89cc6b03c
< 3.2.8
HIGH 8.8 The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
c248f11c-f381-4335-b6f7-bb18bbf1f7b0
< 4.3.2
HIGH 8.8 The WP-Invoice – Web Invoice and Billing plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
c2421108-d4b0-480e-a020-95712cdfae8e
< 3.6.3
HIGH 8.8 The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due t… wordfence
c237cfa7-1b55-4cca-91de-0fde3d598329 HIGH 8.8 The WP Remote Thumbnail plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… wordfence
c232b39c-7144-4d3a-9770-883986ca8b29
< 4.1.0
HIGH 8.8 The WooCommerce plugin for WordPress is vulnerable to arbitrary product meta data creation/overwriting due to a lack o… wordfence
c22c2c17-c9c5-46eb-877a-a49ccf1a74ef HIGH 8.8 The Rename Media Files plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including,… wordfence
c2151c87-0df3-477a-a1b2-7d2e5bc44eb5 HIGH 8.8 The Minterpress plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escal… wordfence
c1d9ee9f-d8d0-4a9d-b414-bc79c4255b4e
< 2.3.2
HIGH 8.8 The Events Shortcodes & Templates For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the pl… wordfence
c1d2b6bd-a75a-4a07-b2f0-8ec206d41211
< 3.1.7
HIGH 8.8 The SupportCandy plugin for WordPress is vulnerable to SQL injection via the 'id' parameter used in the /wp-json/support… wordfence
c19b0da5-db46-4a27-86a6-445dd9a3350d
< 4.2.3
HIGH 8.8 The KBucket: Your Curated Content in WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missi… wordfence
c190c2d7-961b-4643-a7fe-6d4a22b0d5d7
< 1.0.69
HIGH 8.8 The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action… wordfence
c187ed25-6ba7-4a58-97df-5fea723d485a
< 0.9.5
HIGH 8.8 The W3 Total Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in v… wordfence
c170a228-4abd-4ee6-ba37-bdcde1cb7fc5
< 4.7.1
HIGH 8.8 The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to a missing file type validati… wordfence
c1690fe3-f03f-4640-9948-2109d73a841c
< 8.0.0
HIGH 8.8 The WP Support Plus Responsive Ticket System plugin for WordPress is vulnerable to generic SQL Injection via the "$_POST… wordfence
c16543db-2f8c-4266-9fb2-fc429f5647b6 HIGH 8.8 The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logg… wordfence
c1621cd2-78d3-4429-862a-b425f5436f38
< 3.9.001
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows re… wordfence
c15eda1f-dc9f-4601-a337-ad3e66baf3b2
< 1.3.7.1
HIGH 8.8 The WooCommerce Currency Switcher plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and incl… wordfence
← Prev 132 133 134 135 136 137 138 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top