ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 28 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c754d957-26a8-4fef-a487-96d566c2dc36
< 6.6.8
CRITICAL 9.8 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary … wordfence
c74ce3e8-cab9-4cc6-a1ad-1e51f7268474
< 2.17.1
CRITICAL 9.8 The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all ve… wordfence
c7476f2c-c32f-4ff7-ad32-70cf68387342
< 2.76
CRITICAL 9.8 The Disqus Comment System plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, … wordfence
c741350a-e083-499c-992d-727f46ca57f9
< 1.1.2
CRITICAL 9.8 The simple-login-log plugin before 1.1.2 for WordPress has SQL injection via the 'order' parameter in the get_results fu… wordfence
c726d8f0-7f2a-414b-9d73-a053921074d9
< 3.9.1
CRITICAL 9.8 The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This… wordfence
c7214f90-a205-4d7e-94c8-ee07515ebbf1
< 1.4.7
CRITICAL 9.8 The Material Dashboard plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, … wordfence
c6f68bfd-36c3-45f5-a50b-6803b5967e52 CRITICAL 9.8 The Download from files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… wordfence
c6ef0c41-e498-4de6-a86a-d23f65a7a824
< 1.0.9
CRITICAL 9.8 controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users… wordfence
c6ee9437-a12a-476b-9a4b-8da8d9fbfeb3
< 5.2.13
CRITICAL 9.8 The Fluent Forms Pro in version 6.2.7 and the Ninja Tables Pro in version 5.2.13 plugins for WordPress are vulnerable to… wordfence
c6a0811e-f02b-49d1-915e-cf7ac4b5e1f5 CRITICAL 9.8 The Power Zoomer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via th… wordfence
c6a02da1-b005-4fa9-9657-1c5f019f3858
< 2.0.8
CRITICAL 9.8 The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the '*_ordering' parameter in all versions … wordfence
c6998185-0f9b-48ab-9dca-05adf5ae603a CRITICAL 9.8 The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerabl… wordfence
c691d129-35db-4de8-a28e-5e77347e2280
< 1.15.20
CRITICAL 9.8 The Form Maker by 10Web plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valid… wordfence
c66d88a1-0936-40c4-adcf-ad79b9c57a80
< 4.4.3
CRITICAL 9.8 Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to exec… wordfence
c63048ad-3d37-402e-8e61-415d2d6caa69 CRITICAL 9.8 The Form Lightbox plugin for WordPress is vulnerable to arbitrary option updates due to a missing capability check in th… wordfence
c62d8146-e4b1-4c86-9d8a-c3a9bbfb0763
< 1.1.60
CRITICAL 9.8 The Profile Builder – User Profile & User Registration Forms Plugin for WordPress is vulnerable to authentication bypa… wordfence
c5fee6e4-b985-4190-953b-133bc90e47da
< 1.6
CRITICAL 9.8 The Freshmail plugin for WordPress is vulnerable to Multiple SQL Injections via the 'include/wp_ajax_fm_form.php' and 'i… wordfence
c5c17dea-7b61-4e73-ac61-3fe536c22962
< 2.1.66
CRITICAL 9.8 The WooCommerce Products Vendor plugin for WordPress is vulnerable to blind SQL Injection via the ‘s_postcode’ param… wordfence
c5bd11c6-2f55-4eee-834a-c4e405482b9c
< 5.7.24
CRITICAL 9.8 The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin… wordfence
c5bc757d-2495-4be2-bccd-d4090e66ced4 CRITICAL 9.8 The Fresh Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.… wordfence
c5ada976-03b8-4219-9ae3-9060fb7b9de5
< 1.7
CRITICAL 9.8 The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to … wordfence
c5a5c209-0ccd-4fa9-b22d-05bb22247441
< 2.1.6
CRITICAL 9.8 The OneLogin SAML-SSO plugin for WordPress is vulnerable to authentication bypass due to insufficient user validation in… wordfence
c58d5a57-6b87-4a39-b995-c86fbc779565
< 3.2.11
CRITICAL 9.8 A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful explo… wordfence
c5757abd-33dc-4751-bc55-afd944ff2341
< 1.3.0
CRITICAL 9.8 The Duplicator – WordPress Migration & Backup Plugin plugin for WordPress is vulnerable to Remote Code Execution in al… wordfence
c5519d4e-84b5-4901-b55c-a0a919f4b6c9
< 1.0.6.1
CRITICAL 9.8 The Active Products Tables for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up… wordfence
← Prev 25 26 27 28 29 30 31 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top