ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 136 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c13f370b-c9f6-4e58-b6a7-6aa03a0ed5cd HIGH 8.8 The Open Close WooCommerce Store plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inclu… wordfence
c1197d19-e49f-4d44-8efe-ef8d7e91bce0 HIGH 8.8 The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not … wordfence
c10a5583-5273-4b94-8e2e-e3d24ea941b0
< 2.1.4.6
HIGH 8.8 The InPost Gallery plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.4.5.… wordfence
c0eae97c-d7e5-4dde-a323-d90a20826341
< 5.6.1
HIGH 8.8 The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF. wordfence
c0d68506-ee5c-4b01-a0d2-caf2482106e0
< 1.2.3
HIGH 8.8 The wp-rollback plugin before 1.2.3 for WordPress has CSRF. wordfence
c0ce3a76-5e16-4772-a802-9e5ce1345f95 HIGH 8.8 The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF. wordfence
c0c74d48-6cfc-4899-bd2c-4a80b1f6e05f HIGH 8.8 The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3… wordfence
c0a2a379-bd33-4c7d-8b79-e48a2df7e281
< 1.3.6
HIGH 8.8 The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the order… wordfence
c09f9f61-c25f-49dc-a97c-8e145e1141b6
< 2.3.15
HIGH 8.8 The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and i… wordfence
c07ea205-5a05-43f5-993e-c6e30f660ac8
< 2.2.41
HIGH 8.8 The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation v… wordfence
c062d60b-eda8-4039-8655-64f32e70839a
< 3.1.5
HIGH 8.8 Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection… wordfence
c042b347-2884-436d-abd3-6931548f18d6
< 2.2
HIGH 8.8 The Shopper Approved Reviews plugin for WordPress is vulnerable to unauthorized modification of data that can lead to pr… wordfence
c03e74c5-ad32-4651-a55a-cc8d89b8a991 HIGH 8.8 The Hillter theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.7 via deseri… wordfence
c0363732-0a67-4a58-9b54-6315328c70ec HIGH 8.8 The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allow… wordfence
c01bce24-3563-40bd-83c5-8d54bd622151
< 1.0.1
HIGH 8.8 The "Ultimate WordPress Auction Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions bef… wordfence
c000a424-4060-4dcc-bae3-fa8cfc00ddda
< 1.4.4
HIGH 8.8 The Per page add to head WordPress plugin before 1.4.4 is lacking any CSRF check when saving its settings, which could a… wordfence
bff9866e-3967-426e-9b8d-17b317aac7a3
< 1.9.9.5.2
HIGH 8.8 The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versio… wordfence
bff3a160-5238-4478-ab11-3300cac51cf2
< 2.20.7
HIGH 8.8 The ArtPlacer Widget plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions up to, and i… wordfence
bfeb5a08-4aad-421b-9e50-68dd84adc396
< 3.7.59
HIGH 8.8 The Challan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.58. T… wordfence
bfc62289-9ac0-4aeb-96ac-010af6f437a6
< 1.9.9.5.2
HIGH 8.8 The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versio… wordfence
bfc04273-0d72-4b18-bcb5-eb1530aefcc0
< 2.12
HIGH 8.8 The WordPress User Registration Forms by Formidable Forms plugin for WordPress is vulnerable to arbitrary user password … wordfence
bfb53b61-f476-4b92-b87a-de10e18428a3
< 1.1.4
HIGH 8.8 The GoDaddy Email Marketing plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.1.4. T… wordfence
bf893b1e-9fcf-4a3a-862e-4f050617acc6
< 2.9
HIGH 8.8 Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plu… wordfence
bf50922a-58a6-4ca4-80b7-cafb37b87216 HIGH 8.8 The Horizontal scrolling announcement plugin for WordPress is vulnerable to SQL Injection via the plugin's [horizontal-s… wordfence
bf152269-73e1-473f-8d97-ce94e9b885d0 HIGH 8.8 The 'Videospirecore Theme Plugin' plugin for WordPress is vulnerable to privilege escalation via account takeover in all… wordfence
← Prev 133 134 135 136 137 138 139 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top