πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1400 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c4e13ff2-410e-4a65-8b9c-660629eefd5b
< 2.4.7
MEDIUM 4.3 The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… wordfence
c4e0ba71-74dc-414a-9c4e-ad07448e2f18
< 2.7.2.4
MEDIUM 4.3 The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
c4dfd5af-0af0-469c-81ed-52867609550c
< 2.1.20
MEDIUM 4.3 The Total theme for WordPress is vulnerable to Plugin Activation due to insufficient capability and nonce checks on the … wordfence
c4dc736a-6c34-489f-a73a-c7030c60b97f
< 3.8.5
MEDIUM 4.3 The The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary sho… wordfence
c4b01e7d-1c6d-4252-95a4-13f4e486b643
< 3.9.13
MEDIUM 4.3 The Tutor LMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
c49eb49c-4fe3-4b62-9395-ac7ec08dc9ef MEDIUM 4.3 The Direct Payments WP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a … wordfence
c49b3841-370b-42ed-9545-e69c2544642d
< 1.1.7
MEDIUM 4.3 The Marker.io plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.6. … wordfence
c4921cf5-8d09-4278-bf37-02a5f2779fa9
< 2.0.5
MEDIUM 4.3 The Barcode Generator for WooCommerce – Show barcodes on products, orders, invoices and other pages plugin for WordPre… wordfence
c47e170f-f51e-400a-97f3-4da034c193a9 MEDIUM 4.3 The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
c47dbe5d-2507-4946-9ec4-6dd69890277f
< 3.7.3
MEDIUM 4.3 The Porto Theme - Functionality plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
c478a421-8dc1-46cb-ada8-ceb107f22a53
< 2.0.5
MEDIUM 4.3 The vulnerability allows Subscriber+ level users to create brands in WordPress Perfect Brands for WooCommerce plugin (ve… wordfence
c47601b4-bf16-4f59-b5f3-584a8eac7c67
< 3.4.8
MEDIUM 4.3 The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Insecure Direct Object Reference in all … wordfence
c4740494-625f-49ff-967e-07f791ec3f1f
< 2.0
MEDIUM 4.3 The Custom Category/Post Type Post order plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
c47386ee-25c8-4a77-92e8-5a82afc9c826
< 3.5.2
MEDIUM 4.3 The wp-mpdf plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.1. Th… wordfence
c46c47d8-e0cc-45fb-9771-bffcf8131426 MEDIUM 4.3 The Clearbit Reveal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
c463a1d4-14c8-460a-ad83-6f3b38f1e4e8 MEDIUM 4.3 The Remove Post Type Slug plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
c45b6163-7ebf-4f18-afd6-735d02d9170d
< 1.3.3
MEDIUM 4.3 The Joli FAQ SEO – WordPress FAQ Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… wordfence
c4470c03-64fc-46d9-b224-de5a3149c3d5
< 2.1
MEDIUM 4.3 The Add to Cart Text Changer and Customize Button, Add Custom Icon plugin for WordPress is vulnerable to Cross-Site Requ… wordfence
c43f4c91-329d-46b9-b2c8-f35e5baa38d7 MEDIUM 4.3 The Estatebud – Properties & Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… wordfence
c43c8c01-3f8a-4ae4-8113-d410850e721d
< 2.2.4
MEDIUM 4.3 Cross-Site Request Forgery (CSRF) vulnerability in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress. wordfence
c42f56a2-b9f9-40ef-86ad-fea6cf2e29f8
< 1.1.4
MEDIUM 4.3 The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to … wordfence
c40e0582-b471-415a-aedc-10e3f44d2ce8 MEDIUM 4.3 The Upcoming Events Lists plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, … wordfence
c3efae8f-ca89-4d8c-a177-6793994b3ea0
< 3.11.6
MEDIUM 4.3 The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorizati… wordfence
c3dfb0b7-5d9f-492b-9a1a-d4445d39c00c
< 1.3.987
MEDIUM 4.3 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up t… wordfence
c3c80120-c0b2-4bf7-87ec-1277106171c5 MEDIUM 4.3 The WP Performance Pack plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
← Prev 1397 1398 1399 1400 1401 1402 1403 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top