πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1398 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c6d2c4b4-8795-4252-bb43-4cfa4bc6fa06
< 10.51
MEDIUM 4.3 The FluentSnippets – The High-Performance file based Custom Code Snippets Plugin plugin for WordPress is vulnerable to… wordfence
c6c5bea1-c34d-428d-a77e-16cdd45fbc40
< 2.0.9
MEDIUM 4.3 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Sensitive Informatio… wordfence
c6c48173-ffe3-40f8-a2fa-cee66869e343
< 2.0.1
MEDIUM 4.3 The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to In… wordfence
c6c236c0-95a4-479a-a154-d267ce2c0aba MEDIUM 4.3 The Woocommerce Envato Affiliates plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
c6b7447c-c61f-40c7-a423-877dcf3e6709
< 1.40
MEDIUM 4.3 The PW WooCommerce On Sale! plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
c6ab1328-b5a0-4592-8455-0bc1874f2b3e
< 0.1.2.7
MEDIUM 4.3 The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
c69805c9-7e29-470c-b501-39b64d60367c
< 2.9.5
MEDIUM 4.3 The Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor plugin for WordPress is vulnerable to unauthorized a… wordfence
c67ee9bc-3626-4323-8b16-0fcae0db1991
< 1.3.4
MEDIUM 4.3 The Nudgify Social Proof, Sales Popup & FOMO plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… wordfence
c675f883-7e6f-43c3-a901-82ed2d2b3772
< 1.8.7
MEDIUM 4.3 The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in it… wordfence
c667be65-e6d3-40e1-aeec-384d309fde3d
< 16.26.12
MEDIUM 4.3 The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Information Exposure in a… wordfence
c6451aaa-d4ef-4903-8e30-97dfee456d93
< 1.3.4
MEDIUM 4.3 The Cron Logger plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
c63eb95c-cda6-4f88-8b23-5162663150c1 MEDIUM 4.3 The Evergreen Post Tweeter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
c63e7dbb-af56-47b9-8206-5bef96754a38
< 1.1.5
MEDIUM 4.3 The JobScout theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. Th… wordfence
c63ddc62-a4f1-4da4-a65e-4573369d6c30
< 1.0.7.5
MEDIUM 4.3 The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
c624e17f-66f8-4389-b922-b97c73b3c4a2
< 3.5.29
MEDIUM 4.3 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthor… wordfence
c61b5668-18d8-42e0-9ee3-d26ab7424350 MEDIUM 4.3 The WP Category Post List Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… wordfence
c619cb36-7216-4a23-96d2-57d8142be4af MEDIUM 4.3 The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users… wordfence
c61877f7-b037-4ddb-8f04-14c01268884b
< 4.1
MEDIUM 4.3 The Rootspersona plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
c61093b0-6004-4f20-bea5-95c891f44a13
< 1.3.0
MEDIUM 4.3 The Super Blank plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
c5fcbb61-5f22-4333-bdd9-7d843dd7e45a
< 1.8.1
MEDIUM 4.3 TablePress prior to version 1.8.1 allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vector… wordfence
c5f30190-4576-4c2b-b069-72501538733b
< 3.9.7
MEDIUM 4.3 The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the m… wordfence
c5f12e55-3608-415a-82ce-34781994111c MEDIUM 4.3 The JAMstack Deployments plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … wordfence
c5e65bba-e1eb-43b9-b3a6-7b8437692318 MEDIUM 4.3 The Anything Order by Terms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
c5decbb3-05a0-403f-918a-9b516df85778 MEDIUM 4.3 The WP Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
c5d96be2-b89a-46b0-a4f1-da44f9b54b2d
< 1.5.36
MEDIUM 4.3 The Page Builder: Live Composer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
← Prev 1395 1396 1397 1398 1399 1400 1401 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top