ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 287 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c62680b5-e9e0-497f-b957-9b223a623917
< 4.5.17
HIGH 7.5 The Small Package Quotes – UPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter… wordfence
c6070ea5-3231-4a36-b154-400c86eaf31b
< 3.0.5
HIGH 7.5 The wpForo Forum plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.4 due to insu… wordfence
c5e4e1e3-61a6-4c37-80dd-93b5cea440e3 HIGH 7.5 The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL In… wordfence
c5cc35d4-741d-4fea-974a-6ee01fbfefc6
< 5.10.5.2
HIGH 7.5 The TheGem Theme Elements (for Elementor) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, … wordfence
c5a8fd90-49dd-4a5e-88f2-cd6b338da2d6
< 1.0.6
HIGH 7.5 The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Sens… wordfence
c58a2de0-8bb3-4e48-889e-0a8f47ca2959
< 5.5.1
HIGH 7.5 The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/… wordfence
c55d3625-89cf-4d39-ad7b-59378826161d HIGH 7.5 The Apicona theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 24.1.0 via deser… wordfence
c548ea22-e40c-4174-a0de-e2d9b7602c71
< 4.1.2
HIGH 7.5 The Advanced WooCommerce Product Sales Reporting plugin for WordPress is vulnerable to SQL Injection in versions up to, … wordfence
c53997b3-5123-4483-9f56-011cc627b7da HIGH 7.5 The Felan Framework plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.3 due to i… wordfence
c51889e4-9ca2-4c3f-addb-8285579324f6
< 5.11
HIGH 7.5 Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing au… wordfence
c508c3df-c16d-4535-8f34-32fa290e4a4b HIGH 7.5 The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to Path Traversal in all ver… wordfence
c4c95f55-445a-41eb-879a-73b23f0217af
< 2.5.8
HIGH 7.5 The Revolution theme for WordPress is vulnerable to Local File Inclusion in versions up to 2.5.8. This makes it possible… wordfence
c4c3f136-fa26-4813-9e69-f94eba9e4df7
< 1.6.2
HIGH 7.5 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to… wordfence
c49811bf-19d5-450f-9f11-a5fc9e8781c8
< 2.82
HIGH 7.5 The Media Library Assistant plugin before 2.82 for Wordpress suffers from a Local File Inclusion vulnerability in mla_ga… wordfence
c481767a-dcc8-4b39-be3b-3bbce313f7ae
< 2.6
HIGH 7.5 The WP Lead Capturing Pages plugin for WordPress is vulnerable to SQL Injection in versions up to, and excluding, 2.6 du… wordfence
c4772b32-a730-44f2-b43c-f9bd5abb6541
< 2.6.0
HIGH 7.5 The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment A… wordfence
c44e7178-790c-42ab-ac87-9a678e7b38d8
< 6.2.1
HIGH 7.5 The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Directory Tr… wordfence
c432c094-fe56-4f52-ace9-f5b47e69cf99
< 1.3.1
HIGH 7.5 The Subscribe to Unlock Lite plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… wordfence
c3f37ef5-ddf5-4bd5-b6aa-121dda22fb01
< 2.11.0
HIGH 7.5 The CMB2 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.10.1 via des… wordfence
c3ea4bf9-e109-465e-890a-c2923089fb66
< 2.0.20
HIGH 7.5 The Market Exporter plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on… wordfence
c3cc20d7-bdb7-4591-a9ff-4e17e9b3ad9c HIGH 7.5 The Dør - Modern Architecture and Interior Design Theme theme for WordPress is vulnerable to Local File Inclusion in ve… wordfence
c3afcac7-9900-463d-9cb9-f00c10ea47cf
< 6.6.9
HIGH 7.5 The Gtbabel plugin for WordPress is vulnerable to cookie stealing in all versions up to, and including, 6.6.8. This is d… wordfence
c34bc6b9-7c70-4ccc-b265-2919e39a3bcb HIGH 7.5 The Single Property theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.8 via … wordfence
c33ba940-14cf-4df7-bf41-cdac3890c0be
< 1.0.3
HIGH 7.5 The Pixel WordPress Form BuilderPlugin & Autoresponder plugin for WordPress is vulnerable to SQL Injection in versions u… wordfence
c3002e85-3f3d-478a-b5cc-d8204d27ca6b
< 1.1.36
HIGH 7.5 The Fana theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.35. This makes … wordfence
← Prev 284 285 286 287 288 289 290 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top