🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 31 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c4039a27-0100-49c5-8dce-cf015a08ef04
< 1.1.9
CRITICAL 9.8 The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the c… — wordfence
c3f50771-f889-4de9-9d43-a736c4c24efc
< 1.2.3
CRITICAL 9.8 SQL injection vulnerability in the Landing Pages plugin before 1.2.3 for WordPress allows remote attackers to execute ar… — wordfence
c3f13f7a-95ed-4f90-8c65-7a4318a8b542
< 1.5.4
CRITICAL 9.8 The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to arbitrary file uploads due to mi… — wordfence
c3d42b22-cf8f-4726-9188-4c7baf8e5200
< 1.9.9.1
CRITICAL 9.8 The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to Privilege Escalat… — wordfence
c3b6c3ab-529d-44f2-b901-ea720cbc3fbc
< 2.1.57
CRITICAL 9.8 The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name. — wordfence
c31906da-f2fd-40ac-86e0-3f1ed0409d0c
< 3.9.6
CRITICAL 9.8 The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulne… — wordfence
c317fe6a-b691-40bb-a646-a06a8337da31
< 3.0.0
CRITICAL 9.8 The Axact Author List Widget plugin for WordPress is vulnerable to generic SQL Injection via the ‘listItem’ paramete… — wordfence
c309e32f-9b1a-453f-873c-cc9bd18bc115
< 2.3.2
CRITICAL 9.8 The WP Job Portal plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.1. Th… — wordfence
c2c2385e-0d1e-435a-9b82-972964084148
< 1.1
CRITICAL 9.8 The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3. This is due t… — wordfence
c2c0ab2d-1ba9-4a0a-b1fa-bacebe1034eb CRITICAL 9.8 The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validatio… — wordfence
c2b79193-f8fc-4ea2-8973-fe292cfb926b
< 3.7.9.3
CRITICAL 9.8 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … — wordfence
c2b2bb9a-2a32-4591-a149-bfb487c48890 CRITICAL 9.8 The Woostagram Connect plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including… — wordfence
c2a6c3b7-eaef-41c8-9126-df8e8e1dd3e7
< 1.4.19
CRITICAL 9.8 The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Privilege Escalation in all versions … — wordfence
c28e2aba-73eb-43f9-bae9-a78a67e6207c
< 1.0.33
CRITICAL 9.8 The Product Designer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.… — wordfence
c274a9b2-c95e-4898-afa4-d6e2f6006f91 CRITICAL 9.8 The Premium Gallery Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… — wordfence
c2553c88-3bef-4a9f-8339-f6667aa5fb93
< 5.2.0.1
CRITICAL 9.8 The QA Assistants – Driven by data plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, … — wordfence
c2475643-a0b4-444a-a2c6-a5c45e90e1dd CRITICAL 9.8 The UltimateAI plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.8.3. This… — wordfence
c244eb33-acaf-460b-ae1d-6688b21cc60f CRITICAL 9.8 The SV100 Companion plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e… — wordfence
c23c3b24-893f-4589-8fab-bd54259bd105
< 0.8.4.9
CRITICAL 9.8 The WP Fastest Cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppoll… — wordfence
c211e0c0-3086-43d2-853c-489f9c42b0ab
< 6.4
CRITICAL 9.8 The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu… — wordfence
c1fe4f60-d93b-4071-90ae-ac863c17fe19
< 6.1
CRITICAL 9.8 The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all … — wordfence
c1f64b77-5c8b-44f3-b1a8-6aa9f13624b7
< 9.0.2.16
CRITICAL 9.8 The WooCommerce Amazon Affiliates plugin for WordPress is vulnerable to Arbitrary File Upload due to missing file type v… — wordfence
c1e563e1-5381-4353-aa09-b09971b830c8
< 3.0.2
CRITICAL 9.8 The Easy Digital Downloads plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, … — wordfence
c1d8ae51-5f5e-466d-9994-32c898f01f53
< 0.3
CRITICAL 9.8 SQL injection vulnerability in adclick.php in the AdServe 0.2 plugin for WordPress allows remote attackers to execute ar… — wordfence
c1d359ef-a6f1-451e-a76b-e8f7a54b4eac
< 2.1.20
CRITICAL 9.8 The Easy Invoice – Invoice Generator, PDF Quotes & Payments plugin for WordPress is vulnerable to Remote Code Executio… — wordfence
← Prev 28 29 30 31 32 33 34 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top