πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,403
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 12, 2026
Last Updated

39,403 vulnerabilities found (page 30 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c2c0ab2d-1ba9-4a0a-b1fa-bacebe1034eb CRITICAL 9.8 The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validatio… wordfence
c2b79193-f8fc-4ea2-8973-fe292cfb926b
< 3.7.9.3
CRITICAL 9.8 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … wordfence
c2b2bb9a-2a32-4591-a149-bfb487c48890 CRITICAL 9.8 The Woostagram Connect plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including… wordfence
c2a6c3b7-eaef-41c8-9126-df8e8e1dd3e7
< 1.4.19
CRITICAL 9.8 The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Privilege Escalation in all versions … wordfence
c28e2aba-73eb-43f9-bae9-a78a67e6207c
< 1.0.33
CRITICAL 9.8 The Product Designer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.… wordfence
c274a9b2-c95e-4898-afa4-d6e2f6006f91 CRITICAL 9.8 The Premium Gallery Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… wordfence
c2475643-a0b4-444a-a2c6-a5c45e90e1dd CRITICAL 9.8 The UltimateAI plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.8.3. This… wordfence
c244eb33-acaf-460b-ae1d-6688b21cc60f CRITICAL 9.8 The SV100 Companion plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e… wordfence
c23c3b24-893f-4589-8fab-bd54259bd105
< 0.8.4.9
CRITICAL 9.8 The WP Fastest Cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppoll… wordfence
c211e0c0-3086-43d2-853c-489f9c42b0ab
< 6.4
CRITICAL 9.8 The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu… wordfence
c1fe4f60-d93b-4071-90ae-ac863c17fe19
< 6.1
CRITICAL 9.8 The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all … wordfence
c1f64b77-5c8b-44f3-b1a8-6aa9f13624b7
< 9.0.2.16
CRITICAL 9.8 The WooCommerce Amazon Affiliates plugin for WordPress is vulnerable to Arbitrary File Upload due to missing file type v… wordfence
c1e563e1-5381-4353-aa09-b09971b830c8
< 3.0.2
CRITICAL 9.8 The Easy Digital Downloads plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, … wordfence
c1d8ae51-5f5e-466d-9994-32c898f01f53
< 0.3
CRITICAL 9.8 SQL injection vulnerability in adclick.php in the AdServe 0.2 plugin for WordPress allows remote attackers to execute ar… wordfence
c1d359ef-a6f1-451e-a76b-e8f7a54b4eac
< 2.1.20
CRITICAL 9.8 The Easy Invoice – Invoice Generator, PDF Quotes & Payments plugin for WordPress is vulnerable to Remote Code Executio… wordfence
c1d354fc-8137-44fa-980a-215dbeb7d15c
< 1.7.7
CRITICAL 9.8 SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL … wordfence
c1d02646-271a-4079-8a47-00b4029e9c1f
< 9.3.3
CRITICAL 9.8 The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and param… wordfence
c1bb3ab9-afbb-40e7-967a-45f737777dcf
< 2.11.2
CRITICAL 9.8 The Ajax Load More plugin for WordPress is vulnerable to Local File Inclusion in versions before 2.11.2 via the 'repeate… wordfence
c1b93229-55ef-4216-8d48-35e8b6506c19
< 3.9.7
CRITICAL 9.8 The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to PHP Object Injection in all versions… wordfence
c1804afe-55a1-428f-ae5d-99d68f61d33b
< 3.1
CRITICAL 9.8 Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin before 3.1 for WordPress allows remote … wordfence
c16fab08-6b2c-433a-9105-fc15f5c52575
< 1.4.4
CRITICAL 9.8 The Platform theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalatio… wordfence
c16b6a15-9f15-44a6-8663-201f64af81cc
< 1.0.1
CRITICAL 9.8 SQL injection vulnerability in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to execute arbitrary SQL … wordfence
c148372b-e0d2-4164-b7e7-91921720adcf
< 2.57
CRITICAL 9.8 The olimometer plugin before 2.57 for WordPress has SQL injection via olimometer_id parameter. wordfence
c1280ceb-9ce8-47fc-8fd3-6af80015dea9
< 1.41
CRITICAL 9.8 The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to … wordfence
c1184b8d-259f-4713-a61d-9ca9985d55ab
< 5.3.9
CRITICAL 9.8 The Tourmaster plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.3.8. This … wordfence
← Prev 27 28 29 30 31 32 33 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top