🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 25 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cff74b3d-f056-4e9f-a62d-a3d79b4f4d56
< 3.1
CRITICAL 9.8 The Car Rental System plugin for WordPress is vulnerable to blind SQL Injection via the ‘pickuploc’ and 'dropoff' pa… wordfence
cfe5d24a-a2ed-46c1-8d9b-9bd2c63cb8b3 CRITICAL 9.8 The MoveTo plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including… wordfence
cfd32e46-a4fc-4c10-b546-9f9da75db791
< 2.3.8
CRITICAL 9.8 The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is … wordfence
cf85ddc7-cb90-4502-9936-f2c51030b4a6 CRITICAL 9.8 The Disc Golf Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.0… wordfence
cf851bed-f5d8-44e2-810d-906ba3d3c1c5
< 33.0.16
CRITICAL 9.8 The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads… wordfence
cf3df923-9426-4e5b-ba59-eda0b5c18d40
< 2.3.1
CRITICAL 9.8 The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1… wordfence
cf34eb9f-f6e9-4a7a-8459-c86f9fa3dad8
< 1.7.27
CRITICAL 9.8 The Login with phone number plugin for WordPress is vulnerable to authentication bypass in versions up to, and including… wordfence
cf24216c-7882-4359-b526-44d845de0249 CRITICAL 9.8 The EZPZ One Click Backup (ezpz-one-click-backup) plugin 12.03.10 and earlier for WordPress allows remote attackers to e… wordfence
cf159a11-9490-4f79-a62d-c279cfe26108 CRITICAL 9.8 The Ripe HD FLV plugin for WordPress is vulnerable to generic SQL Injection via the 'id' parameter in the 'config.php' f… wordfence
cef83a3e-9e8b-4c4c-9adc-cdcebefadd39 CRITICAL 9.8 The Image Gallery with Slideshow plugin for WordPress is vulnerable to generic SQL Injection via the ‘gid’ parameter… wordfence
cecffd72-4597-4308-9f21-4731269e8cf1
< 3.45
CRITICAL 9.8 A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitat… wordfence
cece751c-400d-42b4-9438-950d5aca51fc
< 3.0.4
CRITICAL 9.8 The AIT CSV import/export plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… wordfence
ce8ec66f-5efc-4354-8871-8e35ab4e51fc
< 1.6.2
CRITICAL 9.8 The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions u… wordfence
ce834ae1-e05a-4b0e-9d7f-144669437d70
< 1.7.7
CRITICAL 9.8 The Caldera Forms Pro plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on th… wordfence
ce544dd0-6e4a-4a73-bba0-db2d667e378e
< 3.1.2
CRITICAL 9.8 The Pie Register plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions before 3.1.2 d… wordfence
ce4c4395-6d1a-4d5f-885f-383e5c44c0f8
< 2.7.1
CRITICAL 9.8 The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due … wordfence
ce3ae202-1227-4247-9133-5c7284392c9f
< 2.0.0
CRITICAL 9.8 The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin fo… wordfence
ce38401f-443b-42b8-ae4e-53700f25bee7
< 1.6.11
CRITICAL 9.8 The Seofy Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.8. This … wordfence
ce332037-bfa3-42a6-a352-ba13439db62f
< 1.0.53.1
CRITICAL 9.8 The Capie theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.40. This makes… wordfence
ce119965-01a0-4cff-a0b2-e99bceb1406c
< 6.6.8
CRITICAL 9.8 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File… wordfence
ce0dcbe6-9231-45d9-9658-5d775e02cfcb
< 4.1.1
CRITICAL 9.8 The Estatik Real Estate Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc… wordfence
cdbf2658-b819-4fd3-ac89-8b90a7e3a2cf
< 7.11
CRITICAL 9.8 The Social Share, Social Login and Social Comments plugin for WordPress is vulnerable to authorization bypass due to a m… wordfence
cdb35927-b239-4243-a2d0-2e2c2cc61668
< 1.5.0
CRITICAL 9.8 The WP Fundraising Donation and Crowdfunding Platform WordPress plugin through 1.4.2 does not sanitise and escape a para… wordfence
cd8a45c9-ca48-4ea6-b34e-f05206f16155
< 1.8.90
CRITICAL 9.8 The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… wordfence
cd4f7b73-947b-4962-9880-5f279580f43c
< 3.20.0
CRITICAL 9.8 The Yith WooCommerce Gift Cards Premium plugin for WordPress is vulnerable to arbitrary file uploads due to missing file… wordfence
← Prev 22 23 24 25 26 27 28 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top