πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 31, 2026
Last Updated

40,407 vulnerabilities found (page 1403 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c1a4d8a3-5553-4b1c-b0f8-d6a372de3692
< 1.5.1.6
MEDIUM 4.3 The Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages plugin for WordPress … wordfence
c1a0200f-9861-4eca-adbf-d458eb6b4e63
< 3.1.2
MEDIUM 4.3 The Canto plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 3.1.1. This is due… wordfence
c19b24ef-cf49-4a5c-a187-0f09ac53c337
< 2.0.1
MEDIUM 4.3 The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in vers… wordfence
c195c772-dd88-4e35-bd95-ca2d8bb6ddb5 MEDIUM 4.3 The ts-tree plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… wordfence
c191da68-d531-4c01-a364-2621c822dc80
< 3.4.1
MEDIUM 4.3 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to HTML Injection in all versi… wordfence
c189bdcb-3b72-4e25-8444-6852444b89f7
< 1.5.2
MEDIUM 4.3 The Sync Post With Other Site plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
c189a778-0338-408c-bcca-a0ac76d8eb44
< 2.5.1
MEDIUM 4.3 The AutomatorWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.0… wordfence
c1870c6e-23b6-4f3b-adba-72633d62dfd0
< 1.9.8
MEDIUM 4.3 The SiteAlert (Formerly WP Health) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
c186d5eb-abc2-47bd-9d3c-2b2f24d2f87e MEDIUM 4.3 The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
c17ef8db-98ea-47b0-8d7f-b2b3f01bf6ec
< 3.4.0
MEDIUM 4.3 The Inline Related Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
c17d7fba-7b98-4a7a-a35e-78f16be81aca
< 3.9.3
MEDIUM 4.3 The Sliced Invoices plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the s… wordfence
c174887b-e24d-4100-97da-8e0923ebafe5 MEDIUM 4.3 The jQuery Hover Footnotes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
c16e1fdc-63b3-4af0-8327-23175191f4ee
< 5.4
MEDIUM 4.3 The Just Writing Statistics plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
c16b299e-a300-4d02-9ffe-52166d3791f4
< 1.4.4
MEDIUM 4.3 The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access due… wordfence
c1520cce-4ed7-4815-9023-4a994200601a
< 4.5.2
MEDIUM 4.3 The Sensei LMS plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.5.1. This… wordfence
c1466b0c-0476-48f7-8817-f2951a8fe78b MEDIUM 4.3 The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missi… wordfence
c132cfc1-03b3-4616-9a66-871e88c857cb
< 2.0.1
MEDIUM 4.3 The WP To Do plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.… wordfence
c12c7f08-5132-4209-ae4e-fb67bf885e57
< 2.15.0
MEDIUM 4.3 The Tourfic plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… wordfence
c12094bd-aa23-4f9b-92e1-d1d4284fb2a0
< 1.4.4
MEDIUM 4.3 The Elementor Addons, Widgets and Enhancements – Stax plugin for WordPress is vulnerable to Cross-Site Request Forgery… wordfence
c0ef3ae7-b3c0-4f54-a95d-9f8cf9497d8f
< 2.4.5
MEDIUM 4.3 The Homey theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th… wordfence
c0ed65f8-a2af-476e-a3f5-51f7b01724f2
< 4.9.6
MEDIUM 4.3 The WpStream – Live Streaming, Video on Demand, Pay Per View plugin for WordPress is vulnerable to unauthorized access… wordfence
c0d8ac01-ac73-47ea-839b-edc820436f27
< 3.11.19
MEDIUM 4.3 The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient user v… wordfence
c0c8d882-32e7-4aa5-8428-f3ce7924ab54 MEDIUM 4.3 The Table Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … wordfence
c0c44335-5d05-48cb-a3a2-574d65f02866
< 3.0.9
MEDIUM 4.3 The Newspack Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … wordfence
c0c13b83-6885-46db-bf33-0b2b63ff06db
< 1.9.4
MEDIUM 4.3 The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Cross-Site Request Forgery in versio… wordfence
← Prev 1400 1401 1402 1403 1404 1405 1406 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top