πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1402 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c2e98359-6b38-4132-9699-a0180813bff3
< 7.0.4
MEDIUM 4.3 The WPC Frequently Bought Together for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a mi… wordfence
c2e92646-bb71-4cf1-b826-e749693b0c0c
< 3.1.2.1
MEDIUM 4.3 The RestroPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.2… wordfence
c2e0a227-670d-40d8-ba82-6602ab57bc4a
< 1.46
MEDIUM 4.3 The We’re Open! plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4… wordfence
c2d1151b-e1c7-4b34-bdf4-285b845ea6d3 MEDIUM 4.3 The Twitch TV Embed Suite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
c2cb2475-2064-4212-89fe-402622736b78 MEDIUM 4.3 The WP MultiTasking – WP Utilities plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up… wordfence
c2b92091-e615-484f-b402-2e793eed214d MEDIUM 4.3 The Get Post Content Shortcode plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up… wordfence
c2af263f-960b-4807-bc85-d136136fa30f MEDIUM 4.3 The Popover Windows plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
c2a1b1a4-df72-4666-b116-882af4cd5796
< 5.9.4.3
MEDIUM 4.3 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object R… wordfence
c28bc239-c77b-4a64-a0bf-edde7d61e268 MEDIUM 4.3 The WP-Syntax plugin for WordPress is vulnerable to Regex Denial of Service in all versions up to, and including, 1.2. T… wordfence
c272d8af-6ebd-44b2-bff2-fa94de2046c4
< 2.0.8
MEDIUM 4.3 The pCloud WP Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
c265590c-be4f-4191-8368-7d366d182dc0
< 3.3
MEDIUM 4.3 The WP Airbnb Review Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
c25ce375-0cdd-4e3e-adfc-3f8bc12a318d MEDIUM 4.3 The Typekit plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
c24cf4de-1392-43a8-85a5-8c66c00c44d7
< 1.4.1
MEDIUM 4.3 The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
c24c57e5-2b42-40db-816a-f1327d1ac09b
< 2.1.5
MEDIUM 4.3 The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capa… wordfence
c2487a5e-f038-414b-bc88-ed2c7f2c624c
< 5.11.2
MEDIUM 4.3 The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a … wordfence
c248606f-2d79-46c1-8975-e111b9118ceb
< 3.1.2
MEDIUM 4.3 A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when pub… wordfence
c23e9810-40ea-43e2-9292-f05f300a7ddf
< 1.3.60
MEDIUM 4.3 The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_mega_menu_… wordfence
c23c08c2-5baa-47a9-a060-b6019d3cdc83 MEDIUM 4.3 The PawFriends - Pet Shop and Veterinary WordPress theme for WordPress is vulnerable to Cross-Site Request Forgery in ve… wordfence
c21f5461-9c1e-48ec-b15f-6a9be1e27b43 MEDIUM 4.3 The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Cross-Site… wordfence
c2138634-c149-4fd1-a33d-351bbf633ea3
< 1.2.12
MEDIUM 4.3 The AnyWhere Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, … wordfence
c2136e1c-5f69-434d-bdc7-72a144da744b
< 4.2.1
MEDIUM 4.3 The Essential Blocks for Gutenberg plugin for WordPress is vulnerable to unauthorized access to AJAX actions due to a mi… wordfence
c20c1fb1-8803-4f84-bdbb-6f03edd907cf
< 7.7.5
MEDIUM 4.3 The The Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… wordfence
c1d157ea-ea5b-46f1-9833-07816c812f85
< 6.4.1
MEDIUM 4.3 The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forg… wordfence
c1cec0b1-b77c-4d21-a3d2-c79fd3250bb0
< 1.2.5
MEDIUM 4.3 The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.4… wordfence
c1a9e2d8-f823-4612-846c-0de72b618b66
< 2.4.1
MEDIUM 4.3 The JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is vulnerable to Cross-Sit… wordfence
← Prev 1399 1400 1401 1402 1403 1404 1405 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top