🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 231 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cb7f78b8-670f-4a23-9498-6fa570833642
< 5.6.4
HIGH 8.1 The WP Activity Log plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.6.3.1… wordfence
cab89b56-d989-40c4-83be-2de3b1a91382
< 1.5
HIGH 8.1 The Zoya theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4 via deserializa… wordfence
ca6f87ee-2a2f-44fc-af3c-f8ecb420cd04 HIGH 8.1 The MultiOffice theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2. This ma… wordfence
ca5fbb95-1b03-4bb9-850a-586b19a374ef
< 3.0.0
HIGH 8.1 The PoloPag – Pix Automático para Woocommerce plugin for WordPress is vulnerable to Local File Inclusion in versions … wordfence
ca57c103-094b-4e1f-8875-75f883ff10a7 HIGH 8.1 The XLSXviewer plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in… wordfence
ca4398d3-1299-4456-9cf8-1674b2fe79d4
< 2.0.2
HIGH 8.1 The Event List plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.2. This … wordfence
ca380ae0-6ca5-4f48-a275-a9d21bfaa4d3 HIGH 8.1 The Alright theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.1. This make… wordfence
ca37d453-9f9a-46b2-a17f-65a16e3e2ed1
< 2.288
HIGH 8.1 The CMS Commander plugin for WordPress is vulnerable to authorization bypass due to the use of an insufficiently unique … wordfence
c9dd2d46-2994-4ea3-9b2a-6aa3444b1b38 HIGH 8.1 The CloudMe | Cloud Storage & File-Sharing WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in … wordfence
c9d00ee8-b9df-4044-a5e2-320391d6c9b1
< 3.2.8
HIGH 8.1 The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missin… wordfence
c967f087-89c4-4798-9758-fcbe25a44f4f
< 4.15
HIGH 8.1 The Newsletters plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.14 via de… wordfence
c962553f-ad49-43da-a29c-eb0823a34247 HIGH 8.1 The Vapester theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.10. This ma… wordfence
c9221f21-9a0c-4ee0-962b-e185b4d9df1a
< 1.9.7
HIGH 8.1 The Medizin - Medical WooCommerce Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to … wordfence
c8b3d614-a943-488a-aeb3-c874e72d2733 HIGH 8.1 The Bajaar - Highly Customizable WooCommerce WordPress theme for WordPress is vulnerable to Local File Inclusion in vers… wordfence
c883c5ab-7bff-48c8-9842-bf51f016981a HIGH 8.1 The MaxShop theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.6.20. This mak… wordfence
c866b3b7-50cf-41a5-bdc2-60384b15df79
< 2.8.0
HIGH 8.1 Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized us… wordfence
c80ac8db-a748-46f4-baef-6c6ff87efb0d HIGH 8.1 The Modernee theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.0. This mak… wordfence
c7b897f5-f988-4515-83bc-456f041d7e2e
< 3.14.6
HIGH 8.1 The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3… wordfence
c77c00c7-a4f6-4ad6-9f1f-4bd941fd6e09 HIGH 8.1 The Foodie theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.14. This makes … wordfence
c7430c99-2696-4b13-8f90-9cb86d52357b HIGH 8.1 The PartyMaker theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.15. This … wordfence
c729f826-3073-4e77-a663-1a1d3ab229e7
< 1.3.9
HIGH 8.1 The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to Local File Inclusion in versions up t… wordfence
c729d5d4-9629-46f1-b90f-f7b4771e50e1
< 3.4.2
HIGH 8.1 The Ghost Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.4.1. This m… wordfence
c6fb55fd-04ee-4f1a-b651-17a82e771d62
< 12.10.4
HIGH 8.1 The Novalnet Payment Gateway for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up t… wordfence
c6e82b46-0b10-45fe-949e-dd94dd8656c0 HIGH 8.1 The GMAce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This… wordfence
c6c52f1a-2203-4abe-b777-064bd6fd1714
< 1.0.2
HIGH 8.1 The Bravis User plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.1.… wordfence
← Prev 228 229 230 231 232 233 234 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top