πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1397 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c85a2d47-cabe-4c0b-b329-af93163d3771
< 7.0.07
MEDIUM 4.3 The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Two-Factor Authentication … wordfence
c857fb50-f3f1-4574-ada9-9492fe09a9c3
< 8.6.7
MEDIUM 4.3 The Directorist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
c83f48dd-9070-412d-b911-98581a81e29a
< 3.2.19
MEDIUM 4.3 The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… wordfence
c82f3864-13af-4ff6-824a-4c799a98f3f6
< 1.6.10.0
MEDIUM 4.3 The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to I… wordfence
c820003b-8f30-4557-a282-e3ad7e403062
< 2.25.2
MEDIUM 4.3 The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.1. Th… wordfence
c80833c3-8ffc-41a1-8d11-dafa962191fd
< 12.4.5
MEDIUM 4.3 The Product Feed PRO for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
c8065d25-2ded-4021-a53d-204242db0915
< 1.0.2
MEDIUM 4.3 Several Addify plugins for WordPress are vulnerable to Cross-Site Request Forgery in various versions. This is due to mi… wordfence
c7fe06c1-fe51-42b5-9c56-cb9e6513f4af
< 2.0.6
MEDIUM 4.3 The Cross-Site Request Forgery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
c7f5aece-dff2-40d9-bab7-9e2a795fab5b
< 2.1.9
MEDIUM 4.3 The Publitio plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the update_s… wordfence
c7db2ec4-67cd-4ebb-8fbb-a1dc9def2f9a
< 1.5
MEDIUM 4.3 The Theme Changer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
c7c89fce-afef-4b5a-92c3-41bcfb382978
< 4.2.5
MEDIUM 4.3 The WooCommerce Builder & Gutenberg WooCommerce Blocks – WowStore plugin for WordPress is vulnerable to unauthorized a… wordfence
c7b3aa68-e8db-4fac-8c94-b1398bec3263 MEDIUM 4.3 The External image replace plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
c7ab5a00-ce1c-4d74-9192-c9834e2d702d
< 6.9
MEDIUM 4.3 The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to unauthorized access of data due to a miss… wordfence
c7907277-ee09-4a4e-a65c-13f18be65473 MEDIUM 4.3 The Admin Notes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
c78b07c1-c31e-4e98-b33d-eb364ec11851
< 1.5.3
MEDIUM 4.3 The YayExtra – WooCommerce Extra Product Options plugin for WordPress is vulnerable to unauthorized access due to a mi… wordfence
c785b7a0-5091-4d89-87d3-cd7d9984553e
< 3.5.16
MEDIUM 4.3 The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulner… wordfence
c77d94ae-528d-4525-b16d-96529bee08c0
< 10.24
MEDIUM 4.3 The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to… wordfence
c761f19e-3263-4fa5-90c0-d661f160ed3a
< 1.2.1
MEDIUM 4.3 The Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to … wordfence
c75e0013-2b4c-4172-8a6b-7e1072d36089
< 2.3.4
MEDIUM 4.3 The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to… wordfence
c74bf337-9b8b-4461-897a-b49b0077580d
< 5.0.2
MEDIUM 4.3 The Contact Form 7 Dynamic Text Extension plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u… wordfence
c743fcc4-650f-416f-9b3e-3f206ca8d3bd
< 4.9.3
MEDIUM 4.3 The ShopEngine plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.9.2.… wordfence
c727ab41-c091-4fff-8abe-f52a904cd9f0 MEDIUM 4.3 The Animated Pixel Marquee Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery via the 'marquee' pa… wordfence
c720fffe-c089-450a-ac5f-1138c1c223d9
< 5.6.1
MEDIUM 4.3 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site R… wordfence
c6e2710f-f51a-487d-a4bb-a19f614ff254
< 5.38.2
MEDIUM 4.3 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mi… wordfence
c6d8533c-43d9-4bd6-a72e-dda8660e474e
< 4.8.5
MEDIUM 4.3 The Contact Form, Drag and Drop Form Builder Plugin – Live Forms plugin for WordPress is vulnerable to unauthorized ac… wordfence
← Prev 1394 1395 1396 1397 1398 1399 1400 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top