πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 288 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c2fc8741-9d53-473b-b396-5a47b3d0eacc HIGH 7.5 The WordPress & WooCommerce Scraper Plugin, Import Data from Any WebSite. plugin for WordPress is vulnerable to Director… wordfence
c2b9c6ab-28b4-49c7-9dc2-32bca81300f8
< 5.7.8
HIGH 7.5 The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection… wordfence
c2a3076b-f5dc-4d93-b0a5-7121ba4e529a
< 6.16.3
HIGH 7.5 The The Events Calendar plugin for WordPress is vulnerable to SQL Injection in versions up to 6.15.12-6.16.2 due to insu… wordfence
c25fc6ff-1928-4690-bf1e-a5e87425c6f0 HIGH 7.5 The Varnish/Nginx Proxy Caching plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up … wordfence
c2346543-c05a-4c69-9b1d-3d33c860c385
< 2.4.9
HIGH 7.5 The Small Package Quotes – Unishippers Edition plugin for WordPress is vulnerable to SQL Injection in versions up to, … wordfence
c22e5765-54bd-4677-947c-8a7c48bdf65b
< 2.6.1
HIGH 7.5 The BMLT Meeting Map plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.… wordfence
c22b9505-6341-4db8-9d21-23796caf63d3
< 0.99
HIGH 7.5 Multiple directory traversal vulnerabilities in resize.php in the PictPress 0.91 and earlier plugin for WordPress allow … wordfence
c1e9e536-b13d-495a-a43b-4ad3803a879c
< 5.7.0
HIGH 7.5 The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to SQL Injec… wordfence
c1836b1e-6c37-4a07-ac29-687d2eebd3ec
< 3.4.5
HIGH 7.5 The ConvertPlus plugin before 3.4.5 for WordPress has an unintended account creation (with the none role) via a request … wordfence
c120871a-8f56-42ea-b5ab-44d0f8233e66 HIGH 7.5 The tPlayer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.1.6 due to insuffi… wordfence
c0fff84c-afe9-446e-96f8-17c4d383978e HIGH 7.5 The SetSail - Travel Agency WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versions up to,… wordfence
c0ed0cfc-9360-42e3-bd96-1d439ee2a8d4 HIGH 7.5 The Saasplate Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.8 due to in… wordfence
c0377d27-0439-46d3-a02c-a693b1ed0bfd
< 2.5
HIGH 7.5 The Persuasion Theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.4. This … wordfence
c022c434-6a77-4ef8-8665-127f54f743cd
< 5.5.7
HIGH 7.5 The μ›Œλ“œν”„λ ˆμŠ€ 결제 μ‹¬ν”ŒνŽ˜μ΄ – 우컀머슀 결제 ν”ŒλŸ¬κ·ΈμΈ plugin for WordPress is vulnerable to SQL I… wordfence
bfe10de1-1c1f-437b-8851-7024fce753be HIGH 7.5 The WP-Mon plugin for WordPress is vulnerable to Arbitrary File Download via the 'download.php' file in versions up to, … wordfence
bf6fc554-8e15-4a9e-ba12-354200ba5351 HIGH 7.5 The Multi CryptoCurrency Payments plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … wordfence
bf658b2c-9c98-47af-abfc-9689cdbfcda3
< 1.1.3
HIGH 7.5 The ThemeMakers Goodnex Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sens… wordfence
bf1ffbbb-6a08-4be1-837e-7c6be3b2ac74
< 3.1.0
HIGH 7.5 The BuddyBoss Platform plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.5 due t… wordfence
befc411f-8c50-44a2-b1af-10a507230df9 HIGH 7.5 The Infility Global plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.14.49 due to… wordfence
be9a0345-fb78-4cde-8d20-002e97825c4e
< 4.3.1
HIGH 7.5 The ekommart theme for WordPress is vulnerable to Local File Inclusion in versions up to 4.3.1. This makes it possible f… wordfence
be61e0ab-bcd9-4e8d-b6b6-ab1663f064a4
< 2.3.16
HIGH 7.5 The Besa theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.15. This makes … wordfence
be4743d5-e4ca-4579-84e2-5eb3ef0e274d
< 4.0.4
HIGH 7.5 The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary Function Call in versions up to and including 4.0.3… wordfence
be1d9d2b-cbdf-4d62-85fe-2616eaf02848
< 1.36.0
HIGH 7.5 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthor… wordfence
bdfabd43-0ffa-4c25-aa72-0572e7007a01
< 2.8.5
HIGH 7.5 The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file read due to missing restrictions to proper f… wordfence
bde90d33-b36f-4ca9-87c2-f0dab723ed06 HIGH 7.5 The About Rentals plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when savi… wordfence
← Prev 285 286 287 288 289 290 291 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top