🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,758
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 26, 2026
Last Updated

41,758 vulnerabilities found (page 32 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c1d354fc-8137-44fa-980a-215dbeb7d15c
< 1.7.7
CRITICAL 9.8 SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL … — wordfence
c1d02646-271a-4079-8a47-00b4029e9c1f
< 9.3.3
CRITICAL 9.8 The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and param… — wordfence
c1bb3ab9-afbb-40e7-967a-45f737777dcf
< 2.11.2
CRITICAL 9.8 The Ajax Load More plugin for WordPress is vulnerable to Local File Inclusion in versions before 2.11.2 via the 'repeate… — wordfence
c1b93229-55ef-4216-8d48-35e8b6506c19
< 3.9.7
CRITICAL 9.8 The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to PHP Object Injection in all versions… — wordfence
c1804afe-55a1-428f-ae5d-99d68f61d33b
< 3.1
CRITICAL 9.8 Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin before 3.1 for WordPress allows remote … — wordfence
c16fab08-6b2c-433a-9105-fc15f5c52575
< 1.4.4
CRITICAL 9.8 The Platform theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalatio… — wordfence
c16b6a15-9f15-44a6-8663-201f64af81cc
< 1.0.1
CRITICAL 9.8 SQL injection vulnerability in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to execute arbitrary SQL … — wordfence
c148372b-e0d2-4164-b7e7-91921720adcf
< 2.57
CRITICAL 9.8 The olimometer plugin before 2.57 for WordPress has SQL injection via olimometer_id parameter. — wordfence
c1280ceb-9ce8-47fc-8fd3-6af80015dea9
< 1.41
CRITICAL 9.8 The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to … — wordfence
c1233f6c-102e-42a7-9c73-9dec712743d6 CRITICAL 9.8 The Social Login & Sharing buttons with Analytics By SoClever plugin for WordPress is vulnerable to Authentication Bypas… — wordfence
c1184b8d-259f-4713-a61d-9ca9985d55ab
< 5.3.9
CRITICAL 9.8 The Tourmaster plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.3.8. This … — wordfence
c1001b2b-395a-44ee-827e-6e57f7a50218
< 1.4.2
CRITICAL 9.8 The WPCasa plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.4.1. This is due… — wordfence
c0e9726f-45cc-4759-909d-3de2ae9b2334
< 0.1.0.83
CRITICAL 9.8 The InstaWP Connect plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.1.0.8… — wordfence
c0b50597-18c1-4cbc-aebb-348f4d786ad9
< 3.1.2
CRITICAL 9.8 The Leopard - WordPress Offload Media plugin for WordPress is vulnerable to unauthorized modification of data that can l… — wordfence
c0a617fc-da3d-4828-b027-44093dd11769 CRITICAL 9.8 The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leadi… — wordfence
c099f401-4b05-4532-8e31-af1b1dea7eca
< 5.4.7
CRITICAL 9.8 The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and i… — wordfence
c0856920-5463-4dd3-a4fd-e56901a89b83
< 2.1.5
CRITICAL 9.8 The Import XML and RSS Feeds for WordPress is vulnerable to remote code execution in versions up to, and including, 2.1.… — wordfence
c080df50-1113-484b-80ed-09515982c585
< 6.0.10
CRITICAL 9.8 The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. Thi… — wordfence
c035ac71-54f9-471b-93f3-6bd6a5b86ab2
< 2.8
CRITICAL 9.8 SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin b… — wordfence
bfe92082-4944-43dc-b06c-3c3d22e93213
< 1.3.1
CRITICAL 9.8 The FluentCommunity plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.15 … — wordfence
bfe1d122-610a-47c1-944d-bf7352e9ff38
< 3.1.0
CRITICAL 9.8 The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads. — wordfence
bfd93c33-4672-4914-b052-7bea283ef60c
< 7.0.1
CRITICAL 9.8 An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthe… — wordfence
bfd3926e-cdb6-44a6-bada-cb83458ca172
< 8.0.07
CRITICAL 9.8 The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution d… — wordfence
bfd1e244-27c2-4c3e-9d82-a7ffefd4eab6
< 1.5.2
CRITICAL 9.8 The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using… — wordfence
bfc4863a-1b8c-4b13-9df1-18f221b40b26
< 3.17.6
CRITICAL 9.8 The Flatsome theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.17.5 via dese… — wordfence
← Prev 29 30 31 32 33 34 35 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top