🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 30 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c5c17dea-7b61-4e73-ac61-3fe536c22962
< 2.1.66
CRITICAL 9.8 The WooCommerce Products Vendor plugin for WordPress is vulnerable to blind SQL Injection via the ‘s_postcode’ param… — wordfence
c5bd11c6-2f55-4eee-834a-c4e405482b9c
< 5.7.24
CRITICAL 9.8 The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin… — wordfence
c5bc757d-2495-4be2-bccd-d4090e66ced4 CRITICAL 9.8 The Fresh Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.… — wordfence
c5ada976-03b8-4219-9ae3-9060fb7b9de5
< 1.7
CRITICAL 9.8 The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to … — wordfence
c5a5c209-0ccd-4fa9-b22d-05bb22247441
< 2.1.6
CRITICAL 9.8 The OneLogin SAML-SSO plugin for WordPress is vulnerable to authentication bypass due to insufficient user validation in… — wordfence
c58d5a57-6b87-4a39-b995-c86fbc779565
< 3.2.11
CRITICAL 9.8 A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful explo… — wordfence
c5757abd-33dc-4751-bc55-afd944ff2341
< 1.3.0
CRITICAL 9.8 The Duplicator – WordPress Migration & Backup Plugin plugin for WordPress is vulnerable to Remote Code Execution in al… — wordfence
c5519d4e-84b5-4901-b55c-a0a919f4b6c9
< 1.0.6.1
CRITICAL 9.8 The Active Products Tables for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up… — wordfence
c54d503f-9de5-496f-bd6d-2e417a5c1b67 CRITICAL 9.8 The Picturesurf Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… — wordfence
c542b535-f75c-4f63-a3d8-7f80139ac97e
< 1.0.3
CRITICAL 9.8 The FrieChat - WordPress Chat Plugin for WordPress is vulnerable to generic SQL Injection via the ‘time’ parameter i… — wordfence
c52a8b78-39bd-473b-ad78-377c31453f4e
< 1.4.3
CRITICAL 9.8 The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the di… — wordfence
c52435f3-cc1c-4d3a-a664-a07e60fad6ae
< 4.4.3
CRITICAL 9.8 The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Local… — wordfence
c508cb73-53e6-4ebe-b3d0-285908b722c9
< 0.9.2
CRITICAL 9.8 The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 thr… — wordfence
c5007dd0-a62c-4ad8-8f8b-eb3f4387c370
< 1.0.12
CRITICAL 9.8 The AI Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actual… — wordfence
c4ea7512-34f4-4f58-8564-74a79c84d9d8
< 1.5.7
CRITICAL 9.8 The Sogrid plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.6. This make… — wordfence
c4d99e64-1daf-4349-9702-341f05a65c21
< 1.4.14
CRITICAL 9.8 CVE-2019-1010209: GoUrl.io GoURL Wordpress Plugin 1.4.13 and earlier is affected by: CWE-434. The impact is: unauthentic… — wordfence
c4c530fa-eaf4-4721-bfb6-9fc06d7f343c
< 3.16.2
CRITICAL 9.8 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in al… — wordfence
c493191e-b2ec-4e5e-ac41-0cff24635a25
< 3.1.7
CRITICAL 9.8 The PlainInventory plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.1.6 vi… — wordfence
c4679fa7-be6b-4f50-8cdf-ff9822794f19
< 6.0.2.7
CRITICAL 9.8 The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to … — wordfence
c466c0ff-d84b-4536-bea7-ada2a80aad15
< 2.2.0
CRITICAL 9.8 The WordPress Share Buttons Plugin – AddThis for WordPress is vulnerable to code injection in versions up to, and incl… — wordfence
c458e018-5901-4917-9847-35f07646e068
< 4.4.6
CRITICAL 9.8 The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5.… — wordfence
c44b9eb6-96a8-4e19-b4c1-72a69b9f159f CRITICAL 9.8 Multiple SQL injection vulnerabilities in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allow remote atta… — wordfence
c42428c6-5d9d-4679-91fe-8ec6f3a3bf9e
< 4.1.8
CRITICAL 9.8 The Gift Vouchers plugin before 4.1.8 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/adm… — wordfence
c42203bc-3f69-44d2-b165-abb55937f65b CRITICAL 9.8 SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary… — wordfence
c4073c20-e5ca-4978-86a4-7715ba2921bb
< 2.5.5
CRITICAL 9.8 The Axeptio plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.5.4. This mak… — wordfence
← Prev 27 28 29 30 31 32 33 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top