πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1396 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c988b505-d42a-4d23-a641-f2fc8ab9c988 MEDIUM 4.3 The Before And After plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
c9826506-2292-44a7-9564-832e54bf4fba MEDIUM 4.3 The Purchase and Expense Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
c97f7513-188b-434c-8cb1-883bed016848
< 2.0
MEDIUM 4.3 The LWS Optimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.… wordfence
c96b3d65-431b-447a-8dc5-8865d83a92b9
< 2.2.3
MEDIUM 4.3 The Printful Integration for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
c956e4c5-bf7e-4ec4-b795-74d477a61694 MEDIUM 4.3 The Amazon Scraper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
c9381244-5ab9-4927-8e18-d6030a399d7c
< 6.5.7
MEDIUM 4.3 The Easy Social Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
c9364785-1174-46d1-8671-001b755361a6 MEDIUM 4.3 The Notification Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
c923e7ca-355c-4007-9fa3-3ca27055d0f3
< 3.6.0
MEDIUM 4.3 The Stock Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
c91d1ec0-0430-4ddd-b6b1-25af0b5cea9d
< 6.2.2
MEDIUM 4.3 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthoriz… wordfence
c90fc17b-f355-4067-928f-031734a572f3
< 7.6
MEDIUM 4.3 The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to unauthorized access due to a missing… wordfence
c8f506ef-972c-403d-9167-ffdd93be8ea6
< 1.0.8
MEDIUM 4.3 The Dealia – Request a quote plugin for WordPress is vulnerable to unauthorized modification of data due to missing ca… wordfence
c8e90994-3b5c-4ae6-a27f-890a9101b440
< 1.1.3
MEDIUM 4.3 The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
c8e56c2c-b559-493f-bafa-501c5948d806
< 1.9.9.4
MEDIUM 4.3 The Contact Form by WPForms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
c8dfc1de-e17d-45c0-aab7-351150c07545
< 2.3.5
MEDIUM 4.3 The LWS Affiliation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
c8d9d19e-a080-40e9-8a71-01888393f618 MEDIUM 4.3 The GoDaddy Email Marketing plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabilit… wordfence
c8d286db-b2a7-46c4-825f-dc67dda8a63d
< 2.11.9
MEDIUM 4.3 The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecu… wordfence
c8bd5021-4895-4b0e-b517-186959f76095 MEDIUM 4.3 The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to unauthorized access due to a miss… wordfence
c8a29088-0c98-4a79-a4bf-025bcf89782b
< 5.4.13
MEDIUM 4.3 The Advanced File Manager plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 5.… wordfence
c89a8001-ab50-466c-aa51-62c0ff5f86dc
< 3.5.2
MEDIUM 4.3 The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vuln… wordfence
c886ce5a-0633-4892-9471-c1a7ee858c93
< 2.2.2
MEDIUM 4.3 The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to … wordfence
c885e9d8-7e43-4a2e-a111-b156161a58b1
< 3.1.4
MEDIUM 4.3 The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to Sensitive Information E… wordfence
c881ddce-05f8-4b56-ac72-52c9b7773db0
< 1.5.5
MEDIUM 4.3 The WP Prayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.4. … wordfence
c8798fb2-4cab-4960-9e32-fd74bb4a5091
< 5.1.5
MEDIUM 4.3 The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a miss… wordfence
c879566b-8d3b-45aa-91e5-aef1198ef994
< 2.7.23
MEDIUM 4.3 The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to unauthorized ac… wordfence
c870764c-3e2c-4be2-acff-6bcb56127fce
< 2.1.13
MEDIUM 4.3 The Property Hive plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
← Prev 1393 1394 1395 1396 1397 1398 1399 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top