πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 285 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cee0fbbb-64eb-4022-8220-dfcc5c37aa40 HIGH 7.5 The WP JobHunt plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi… wordfence
ce047db1-b701-4903-9244-68b3ecaad78f
< 2.4.9
HIGH 7.5 common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not con… wordfence
ce032abe-ee9d-4be1-ac97-5fa95d598e85
< 2.6
HIGH 7.5 The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2… wordfence
cdcae7fe-1cc1-4168-8b4b-fcee5bf91be2
< 2.5.5
HIGH 7.5 The Booking and Rental Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includi… wordfence
cdbbccc5-07e5-48fb-8242-cd100a76eb9f
< 3.2.0
HIGH 7.5 The Amely theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.4 due to insufficient… wordfence
cdac6080-5e23-488d-8b3c-de0c6c92e344
< 3.2
HIGH 7.5 The Service Finder - Provider and Business Listing theme for WordPress is vulnerable to Path Traversal in versions up to… wordfence
cd9eb6e5-5566-4a11-bcca-26c166a5b4c5 HIGH 7.5 The Download Counter plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.4… wordfence
ccf7ecf9-4e73-437d-98c2-be9ff3f1cdb6 HIGH 7.5 The CHATLIVE plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.1 due to insuffic… wordfence
ccced656-0907-48d2-a8ab-32ac86c1e6c9 HIGH 7.5 The Easy Guide plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.0 due to insuff… wordfence
ccb24a6d-5df4-4b56-b63a-353ad41e7f1c
< 1.0.11
HIGH 7.5 The Antideo Email Validator plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.10… wordfence
cc42ac65-969a-476d-993e-7d8bc2b4fa96
< 2.2
HIGH 7.5 The Method Theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.1. This is d… wordfence
cc3cf6c5-643e-49ca-b09c-bd7cfec328ee
< 1.13.19
HIGH 7.5 The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'map_post_type' parameter in all v… wordfence
cbe2be48-cad8-4679-beb8-c4c80c045d37 HIGH 7.5 The Nuss - Hotel Booking WordPress theme for WordPress is vulnerable to Local File Inclusion in versions up to, and incl… wordfence
cbd8d37d-50f7-4480-acef-cdec33c9f07f
< 0.2.4
HIGH 7.5 The WP Attachment Export WordPress plugin before 0.2.4 does not have proper access controls, allowing unauthenticated us… wordfence
cbb7bdcf-9f93-4c86-a4b3-ad5aaf7521b0
< 1.0.8
HIGH 7.5 The ShipEngine Shipping Quotes plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all ve… wordfence
cb981b48-a31a-4ebb-96c9-c6d31e2dfe02
< 1.5.0
HIGH 7.5 The Visionary Core plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.9 vi… wordfence
cb8eea53-64d1-4375-9364-292b96080f68
< 4.2
HIGH 7.5 Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote att… wordfence
cb855743-1d08-4e21-a23c-a4ffba615f57
< 2.0.7
HIGH 7.5 The NextGen Gallery plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.0 via the '… wordfence
cacf2e32-12cf-41a9-a57f-1135c165494c
< 1.2.36
HIGH 7.5 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the … wordfence
caa66246-7ffa-4944-ae3a-9c872300b7d4
< 3.7.28
HIGH 7.5 In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler … wordfence
ca878f27-f837-412b-8d63-9decb40dc8a5
< 1.4.3
HIGH 7.5 The Simple Video Directory plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.4… wordfence
ca72924f-23fc-42ef-9556-8fb9f5e88add HIGH 7.5 Absolute path traversal vulnerability in Cross-RSS (wp-cross-rss) plugin 1.7 for WordPress allows remote attackers to re… wordfence
ca4e2fa0-9b18-4318-b588-33d5bc3c5ab9
< 1.7.5
HIGH 7.5 The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions u… wordfence
ca41c951-318f-47a7-9a30-c1d4eea1b1b5
< 5.9.0
HIGH 7.5 The PGS Core plugin for WordPress is vulnerable to SQL Injection via the 'event' parameter in the 'save_header_builder' … wordfence
ca263c58-addd-4cd6-b55b-82b7023849e1
< 0.9.106
HIGH 7.5 The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in all v… wordfence
← Prev 282 283 284 285 286 287 288 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top