🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 29 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c54d503f-9de5-496f-bd6d-2e417a5c1b67 CRITICAL 9.8 The Picturesurf Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… wordfence
c542b535-f75c-4f63-a3d8-7f80139ac97e
< 1.0.3
CRITICAL 9.8 The FrieChat - WordPress Chat Plugin for WordPress is vulnerable to generic SQL Injection via the ‘time’ parameter i… wordfence
c52a8b78-39bd-473b-ad78-377c31453f4e
< 1.4.3
CRITICAL 9.8 The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the di… wordfence
c52435f3-cc1c-4d3a-a664-a07e60fad6ae
< 4.4.3
CRITICAL 9.8 The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Local… wordfence
c508cb73-53e6-4ebe-b3d0-285908b722c9
< 0.9.2
CRITICAL 9.8 The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 thr… wordfence
c5007dd0-a62c-4ad8-8f8b-eb3f4387c370
< 1.0.12
CRITICAL 9.8 The AI Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actual… wordfence
c4ea7512-34f4-4f58-8564-74a79c84d9d8
< 1.5.7
CRITICAL 9.8 The Sogrid plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.6. This make… wordfence
c4d99e64-1daf-4349-9702-341f05a65c21
< 1.4.14
CRITICAL 9.8 CVE-2019-1010209: GoUrl.io GoURL Wordpress Plugin 1.4.13 and earlier is affected by: CWE-434. The impact is: unauthentic… wordfence
c4c530fa-eaf4-4721-bfb6-9fc06d7f343c
< 3.16.2
CRITICAL 9.8 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in al… wordfence
c493191e-b2ec-4e5e-ac41-0cff24635a25
< 3.1.7
CRITICAL 9.8 The PlainInventory plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.1.6 vi… wordfence
c4679fa7-be6b-4f50-8cdf-ff9822794f19
< 6.0.2.7
CRITICAL 9.8 The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to … wordfence
c466c0ff-d84b-4536-bea7-ada2a80aad15
< 2.2.0
CRITICAL 9.8 The WordPress Share Buttons Plugin – AddThis for WordPress is vulnerable to code injection in versions up to, and incl… wordfence
c44b9eb6-96a8-4e19-b4c1-72a69b9f159f CRITICAL 9.8 Multiple SQL injection vulnerabilities in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allow remote atta… wordfence
c42428c6-5d9d-4679-91fe-8ec6f3a3bf9e
< 4.1.8
CRITICAL 9.8 The Gift Vouchers plugin before 4.1.8 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/adm… wordfence
c42203bc-3f69-44d2-b165-abb55937f65b CRITICAL 9.8 SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary… wordfence
c4073c20-e5ca-4978-86a4-7715ba2921bb
< 2.5.5
CRITICAL 9.8 The Axeptio plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.5.4. This mak… wordfence
c4039a27-0100-49c5-8dce-cf015a08ef04
< 1.1.9
CRITICAL 9.8 The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the c… wordfence
c3f50771-f889-4de9-9d43-a736c4c24efc
< 1.2.3
CRITICAL 9.8 SQL injection vulnerability in the Landing Pages plugin before 1.2.3 for WordPress allows remote attackers to execute ar… wordfence
c3f13f7a-95ed-4f90-8c65-7a4318a8b542
< 1.5.4
CRITICAL 9.8 The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to arbitrary file uploads due to mi… wordfence
c3d42b22-cf8f-4726-9188-4c7baf8e5200
< 1.9.9.1
CRITICAL 9.8 The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to Privilege Escalat… wordfence
c3b6c3ab-529d-44f2-b901-ea720cbc3fbc
< 2.1.57
CRITICAL 9.8 The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name. wordfence
c31906da-f2fd-40ac-86e0-3f1ed0409d0c
< 3.9.6
CRITICAL 9.8 The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulne… wordfence
c317fe6a-b691-40bb-a646-a06a8337da31
< 3.0.0
CRITICAL 9.8 The Axact Author List Widget plugin for WordPress is vulnerable to generic SQL Injection via the ‘listItem’ paramete… wordfence
c309e32f-9b1a-453f-873c-cc9bd18bc115
< 2.3.2
CRITICAL 9.8 The WP Job Portal plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.1. Th… wordfence
c2c2385e-0d1e-435a-9b82-972964084148
< 1.1
CRITICAL 9.8 The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3. This is due t… wordfence
← Prev 26 27 28 29 30 31 32 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top