🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 27 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cadb77be-1b57-4c05-8fb2-cc5916a215a4 CRITICAL 9.8 The My Geo Posts Free plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2 v… wordfence
ca868ec4-9d28-4edd-b31c-a8546f9ced9e CRITICAL 9.8 The FAT Event Lite plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1. Thi… wordfence
ca3775db-0722-4090-924e-81e38d5dce97 CRITICAL 9.8 The Extensions by HocWP Team plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin… wordfence
ca2b6f6e-4cc0-40ae-8969-c82c5a231f41
< 5.1.94
CRITICAL 9.8 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Local File I… wordfence
ca1d5275-3398-47a7-889b-4050ebe635ee
< 2.1.7
CRITICAL 9.8 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
ca02cd21-e278-478e-80e8-18ff51f6ed10
< 1.6.7
CRITICAL 9.8 The Car Dealer theme for WordPress is vulnerable to PHP Object Injection in versions up to, and excluding, 1.6.7 via des… wordfence
c9fb3480-f83a-4cf1-873e-4a938805666b CRITICAL 9.8 The AJAX Random Posts plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.3.3… wordfence
c9f4760c-a794-43e0-80a3-88b3f41810f5
< 1.2.0
CRITICAL 9.8 A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 1.2.0 for WordP… wordfence
c9cd43f5-c3d0-4eb2-9c18-1af2edca37ff CRITICAL 9.8 The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the reg… wordfence
c9a5f8ca-7efc-401b-8a93-07fbe7204dce
< 3.1
CRITICAL 9.8 The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path vali… wordfence
c97b31bc-75d6-40af-bf4a-714ea69d2c28 CRITICAL 9.8 The Easy Career Openings plugin for WordPress is vulnerable to SQL Injection via the ‘jobid’ parameter in versions u… wordfence
c978a252-1f77-4c8d-b51a-04ed3493ee34 CRITICAL 9.8 The Dynamic Font Replacement DFR4WP EN plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ para… wordfence
c96507cf-3c2d-4516-92f5-d08384aa6b1a
< 2.8.1
CRITICAL 9.8 The WORDPRESS VIDEO GALLERY Plugin for WordPress is vulnerable to SQL Injection via the ‘vid' parameter in versions up… wordfence
c959fac5-d881-403d-85e0-edf4cb1be02e CRITICAL 9.8 Multiple plugins and/or themes for WordPress are vulnerable to Privilege Escalation in various versions. This is due to … wordfence
c8e634ef-b496-40cd-ab20-32f68c0be7ee
< 4.2
CRITICAL 9.8 The ARPrice plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.1.3 via deser… wordfence
c8de9ce3-c96a-4fe5-a1f9-8019ca13cc11
< 1.4.6
CRITICAL 9.8 The Sigma Forms Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
c89b4177-2e8b-4124-9517-6a1ff6830308
< 4.5.1
CRITICAL 9.8 The couponxl theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.5.0. This… wordfence
c880470f-3f81-47a2-b450-7074410e9f43
< 1.0.5
CRITICAL 9.8 The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.… wordfence
c814924a-bdcd-4b73-905b-a469f4d37ddf
< 2.731
CRITICAL 9.8 The Post Pay Counter plugin before 2.731 for WordPress has PHP Object Injection via deserialization of untrusted input v… wordfence
c7e3a8ee-9950-4da4-8450-8b5902b3b876
< 1.0.94
CRITICAL 9.8 The User Verification plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when gen… wordfence
c7a97aeb-f34c-4997-864b-132bb5ed28e7
< 2.3.9
CRITICAL 9.8 The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL stateme… wordfence
c7a6eff3-a592-4476-aff4-c133bb4e5870
< 1.1.23
CRITICAL 9.8 WordPress WP GPX Maps Plugin before 1.1.23 allows remote attackers to execute arbitrary PHP code via improper file uploa… wordfence
c77619cd-8d14-42b9-a536-cf39c50e714a
< 0.5.4
CRITICAL 9.8 The Front End Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation vi… wordfence
c764e742-1135-43aa-a190-3b7ec6767f1c CRITICAL 9.8 The LogisticsHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … wordfence
c764811f-e9dc-4c3d-b696-5792e70ff0b6 CRITICAL 9.8 The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stockt… wordfence
← Prev 24 25 26 27 28 29 30 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top