πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1395 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cac05073-0ac9-45be-9fd0-e812d9fd2437 MEDIUM 4.3 The Post Type Converter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
cabb5976-375a-4f67-8ffd-6dd56d48b81d MEDIUM 4.3 The Thim Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3… wordfence
cab9eb4f-6ce6-473a-8248-85e7208c366e
< 5.26.4
MEDIUM 4.3 The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability… wordfence
cab22e97-ee7f-4be2-9381-ba16b67456b9
< 0.0.8
MEDIUM 4.3 The Currency Switcher for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… wordfence
cab1d5a0-66e0-4017-8563-f8e582a6f964
< 1.7.5
MEDIUM 4.3 The Product Import Export for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to, … wordfence
caa73e10-fc2d-4a51-a2fb-6f13817e7c74
< 3.4.2
MEDIUM 4.3 The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Cross-Site Request … wordfence
ca8f4f6b-756b-4511-9e48-e41a872a9dad
< 3.3.2
MEDIUM 4.3 The Contextual Related Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
ca7e7419-5e1f-42f3-8dad-78d536b36888
< 5.6.4
MEDIUM 4.3 The JoomSport plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … wordfence
ca7dfdea-b9c6-4108-8d18-1f952180cd3d
< 3.0.6
MEDIUM 4.3 The JobSearch WP Job Board plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,… wordfence
ca74b5b1-e4dd-4ca9-8716-b9d0f5adcc0d
< 2.9.5.6
MEDIUM 4.3 The WPComplete plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
ca66c98c-66cb-4573-ae27-bec8a5541583 MEDIUM 4.3 The BCM Duplicate Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
ca55a7a0-da31-4d3f-845b-80f89ffbadf5
< 3.3.9
MEDIUM 4.3 The CoSchedule plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.8.… wordfence
ca4dead2-c6da-4613-8ce6-13699a7495a1
< 1.1.5
MEDIUM 4.3 The Superb Social Media Share Buttons and Follow Buttons plugin for WordPress is vulnerable to unauthorized modification… wordfence
ca4cf299-9dee-4ebf-83f3-4c3471bd9fb0
< 3.1.14
MEDIUM 4.3 The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
ca497ffa-6306-46dc-895f-94f1d5236e28
< 2.35.0
MEDIUM 4.3 The YITH Essential Kit for WooCommerce #1 plugin for WordPress is vulnerable to unauthorized modification of data due to… wordfence
ca423309-d8bd-46a4-9e88-9534d9c60b4a
< 2.12.29
MEDIUM 4.3 The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to in… wordfence
ca1c1b43-def2-4f9f-b5c7-075ca188f6e7
< 3.5
MEDIUM 4.3 The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to Cross-Site Request Forger… wordfence
ca13db03-74ee-4fdf-96ea-28219f9324e5
< 2.1.3
MEDIUM 4.3 The ELEX WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to Cross-Site Request Forgery in v… wordfence
ca04a041-6614-420b-a7c5-65128202d713
< 2.3.16
MEDIUM 4.3 The Accordion – AI FAQ, Accordion, Tabs, Image Accordion, Product FAQ, FAQ Builder, FAQ Grid plugin for WordPress is v… wordfence
c9f71433-7b86-46c7-b91e-bc59679f0351
< 1.2.4
MEDIUM 4.3 The Counter Box – WordPress plugin for countdown, timer, counter plugin for WordPress is vulnerable to Cross-Site Req… wordfence
c9e45ae8-e5b5-460b-80f8-de562ae7c56a
< 1.2.2
MEDIUM 4.3 The SALERT plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on … wordfence
c9d2431d-32ea-4f2d-9fce-bd44dc6680ba
< 1.14.0.4
MEDIUM 4.3 The FunnelKit Payment Gateway for Stripe WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in… wordfence
c9c907ea-3ab4-4674-8945-ade4f6ff2679
< 2.0.7
MEDIUM 4.3 The Depicter Slider – Responsive Image Slider, Video Slider & Post Slider plugin for WordPress is vulnerable to Cross-… wordfence
c9b4b8cc-fa30-454d-b86a-55133f2ca993
< 3.1.4
MEDIUM 4.3 The JS Help Desk plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 3.1.3. This… wordfence
c99b8a94-c35b-43a1-bb14-2ca97be421cc
< 2.3.5
MEDIUM 4.3 The aDirectory – WordPress Directory Listing Plugin plugin for WordPress is vulnerable to unauthorized loss of data du… wordfence
← Prev 1392 1393 1394 1395 1396 1397 1398 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top