🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 28 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cb2e9370-f50e-4792-99f6-4678e0256a56
< 3.0.61
CRITICAL 9.8 The Gallery Bank – WordPress Photo Gallery Plugin for WordPress is vulnerable to arbitrary file uploads due to missing… — wordfence
cb1626ae-cf58-4377-ab4f-58e4536825fe CRITICAL 9.8 The Foodbakery Sticky Cart plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, … — wordfence
cb102a58-2fc0-4441-8f51-a6109e323878
< 1.1
CRITICAL 9.8 Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow re… — wordfence
cb03eb79-27c9-4a9d-b690-71946e11f39f
< 5.4.4
CRITICAL 9.8 The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, … — wordfence
cae6e8b9-a8a9-41d3-83e8-d833515a0244
< 3.2
CRITICAL 9.8 The Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics plugin for WordPress is vulnerable to PHP O… — wordfence
cadd47e9-1d5b-4f04-8421-7707dad53ea6
< 0.91
CRITICAL 9.8 The Google Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.90 via d… — wordfence
cadb77be-1b57-4c05-8fb2-cc5916a215a4 CRITICAL 9.8 The My Geo Posts Free plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2 v… — wordfence
caa1a42a-6bb2-42c8-aae7-fb1c895573a8
< 5.0.4
CRITICAL 9.8 The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions… — wordfence
ca868ec4-9d28-4edd-b31c-a8546f9ced9e CRITICAL 9.8 The FAT Event Lite plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1. Thi… — wordfence
ca3775db-0722-4090-924e-81e38d5dce97 CRITICAL 9.8 The Extensions by HocWP Team plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin… — wordfence
ca2b6f6e-4cc0-40ae-8969-c82c5a231f41
< 5.1.94
CRITICAL 9.8 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Local File I… — wordfence
ca1d5275-3398-47a7-889b-4050ebe635ee
< 2.1.7
CRITICAL 9.8 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … — wordfence
ca02cd21-e278-478e-80e8-18ff51f6ed10
< 1.6.7
CRITICAL 9.8 The Car Dealer theme for WordPress is vulnerable to PHP Object Injection in versions up to, and excluding, 1.6.7 via des… — wordfence
c9fb3480-f83a-4cf1-873e-4a938805666b CRITICAL 9.8 The AJAX Random Posts plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.3.3… — wordfence
c9f4760c-a794-43e0-80a3-88b3f41810f5
< 1.2.0
CRITICAL 9.8 A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 1.2.0 for WordP… — wordfence
c9cd43f5-c3d0-4eb2-9c18-1af2edca37ff CRITICAL 9.8 The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the reg… — wordfence
c9a5f8ca-7efc-401b-8a93-07fbe7204dce
< 3.1
CRITICAL 9.8 The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path vali… — wordfence
c97b31bc-75d6-40af-bf4a-714ea69d2c28 CRITICAL 9.8 The Easy Career Openings plugin for WordPress is vulnerable to SQL Injection via the ‘jobid’ parameter in versions u… — wordfence
c978a252-1f77-4c8d-b51a-04ed3493ee34 CRITICAL 9.8 The Dynamic Font Replacement DFR4WP EN plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ para… — wordfence
c96507cf-3c2d-4516-92f5-d08384aa6b1a
< 2.8.1
CRITICAL 9.8 The WORDPRESS VIDEO GALLERY Plugin for WordPress is vulnerable to SQL Injection via the ‘vid' parameter in versions up… — wordfence
c959fac5-d881-403d-85e0-edf4cb1be02e CRITICAL 9.8 Multiple plugins and/or themes for WordPress are vulnerable to Privilege Escalation in various versions. This is due to … — wordfence
c8e634ef-b496-40cd-ab20-32f68c0be7ee
< 4.2
CRITICAL 9.8 The ARPrice plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.1.3 via deser… — wordfence
c8de9ce3-c96a-4fe5-a1f9-8019ca13cc11
< 1.4.6
CRITICAL 9.8 The Sigma Forms Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … — wordfence
c89b4177-2e8b-4124-9517-6a1ff6830308
< 4.5.1
CRITICAL 9.8 The couponxl theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.5.0. This… — wordfence
c880470f-3f81-47a2-b450-7074410e9f43
< 1.0.5
CRITICAL 9.8 The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.… — wordfence
← Prev 25 26 27 28 29 30 31 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top