πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 286 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ca21320a-ee26-47e9-bbf8-cfbb45d7a882 HIGH 7.5 The About Me plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the functio… wordfence
ca155a52-4ee8-45dd-a74c-7155ea5bc0c1
< 2.4.3
HIGH 7.5 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection in versi… wordfence
c9cccff7-29c0-4275-b689-a3f29bc25e57
< 2.1.5
HIGH 7.5 The AnalyticsWP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.2 due to insuf… wordfence
c9438574-11ce-4535-ae64-89b42517c6c2
< 2.5.3
HIGH 7.5 The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in… wordfence
c9279c42-2a59-4228-983a-332179f8d845 HIGH 7.5 The Struktur Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.5.1. Th… wordfence
c9276757-1f73-44bf-9640-ea749ede5f16
< 3.1.2
HIGH 7.5 The Traveler Code plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.1 due to ins… wordfence
c8b497b4-947c-4011-92c3-a3e265b80845 HIGH 7.5 The Freshio theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.2. This make… wordfence
c89d9bfd-f14e-4299-ab25-a6856c1af95c
< 3.14.0
HIGH 7.5 The Profile Builder Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and excluding, 3.14.0 due… wordfence
c8815e53-f96b-44b2-8dae-9fcc481b6e0c
< 2.8.163
HIGH 7.5 The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable t… wordfence
c80e9dc6-6a0a-4bdf-bcc4-52df9cc4c405
< 9.7.3
HIGH 7.5 The XStore theme for WordPress is vulnerable to SQL Injection in versions up to 9.7.3 due to insufficient escaping on th… wordfence
c7fdd481-57f0-4fa8-8434-868ef6341fd2
< 2.0.7
HIGH 7.5 The Medilink-Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to 2.0.7. This makes it poss… wordfence
c7f4f726-7e53-4397-8d8b-7a574326adc6
< 4.2.3
HIGH 7.5 The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and… wordfence
c7cd6e44-bd78-4eb8-bab8-09e2af583222
< 1.3.1
HIGH 7.5 The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Arbitrary File Read i… wordfence
c7909b75-8087-4d38-8325-c619bf84d997
< 3.2.5
HIGH 7.5 The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and… wordfence
c7697346-842c-4d34-83be-42f8607fb14d
< 2.7.8.4
HIGH 7.5 The Participants Database plugin for WordPress is vulnerable to SQL Injection in versions up to 2.7.8.4 due to insuffici… wordfence
c74784de-b9cc-4d50-b6be-dc5bb22d1daa
< 1.5.5
HIGH 7.5 The AI Copilot – Content Generator plugin for WordPress is vulnerable to SQL Injection in versions up to, and includin… wordfence
c73dbc40-ba54-4836-9bb1-a35f95d5a077
< 2.2
HIGH 7.5 The WordPress Job Board and Recruitment Plugin – JobWP plugin for WordPress is vulnerable to Sensitive Information Exp… wordfence
c72099cc-e70a-4afe-92c0-8f9f8c1e91b7 HIGH 7.5 The LT Unleashed plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.1 … wordfence
c70ed02e-1183-475b-a110-4a2d8dbe610e HIGH 7.5 The Nitro by WooRockets theme for WordPress is vulnerable to Arbitrary Plugin Installation in versions up to, and includ… wordfence
c70baf59-e3c8-461d-9fb3-8c2a71173140 HIGH 7.5 The 404 SEO Redirection plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to… wordfence
c708698f-a38a-4213-a022-817b380e64df
< 4.23.88
HIGH 7.5 The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to PHP Object Injection in version… wordfence
c6c846c8-df8a-4a95-834e-a9443b6a86b5 HIGH 7.5 The ArielBrailovsky-ViralAd plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the printResul… wordfence
c6a49422-ac78-4fad-a69a-55c0569ec8b5 HIGH 7.5 The Kitchor theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.3. This make… wordfence
c699c99d-cf6b-4c14-aaaf-c5270b8763c1
< 6.6.8.8
HIGH 7.5 The Quiz Maker plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.6.8.7 due to insu… wordfence
c6571ebd-1b28-4670-ad87-3919577f01ad HIGH 7.5 The Biolife theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.2.3. This make… wordfence
← Prev 283 284 285 286 287 288 289 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top