πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 353 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cf992c75-a1ae-49c3-8110-2f3b31b23f6c
< 1.1
HIGH 7.2 The Zyrex Popup plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … wordfence
cf902756-21f3-483b-a5d8-a9b4226bde22
< 1.18.11
HIGH 7.2 The Mail Mint plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pr… wordfence
cf803368-64ff-4dbe-85ae-af30e18bc833
< 2.6
HIGH 7.2 Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN development versions only, allows remote attackers… wordfence
cf3c2031-06c7-42c9-a099-a798dc0cc3d0
< 1.7.0
HIGH 7.2 The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPr… wordfence
cf346e71-9baa-473b-8a65-1f22dae8118f
< 6.0.12
HIGH 7.2 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Server-Side Requ… wordfence
cf0f5fd4-cd06-4d11-9f22-1f417b546afb
< 2.4.1
HIGH 7.2 The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜item’ pa… wordfence
cefcd612-0ba8-4225-8f23-817b7220ee7b
< 2.9.9.8
HIGH 7.2 The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Stored Cro… wordfence
cee6a100-cda5-48a6-9f9c-ea17f80c4165
< 2.3.8
HIGH 7.2 The Product Import Export for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… wordfence
cec5bfa6-96ed-4a5a-be19-63434af32c89
< 4.0.4
HIGH 7.2 Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to i… wordfence
ce6cfed1-b19c-4000-81a1-fad13dc526d3
< 12.1.1.1
HIGH 7.2 The ICS Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 12.… wordfence
ce5c048a-0dbf-448d-bfca-aff347d9466b
< 3.10.01
HIGH 7.2 The ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor plugin for WordPress is vulnerabl… wordfence
ce489717-6489-40a7-9f69-74ba841ed235 HIGH 7.2 The Kush Micro News plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… wordfence
ce330cae-c2f8-42f3-822b-ca24bf46e433
< 2.11.0
HIGH 7.2 The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up t… wordfence
ce010c6f-16bd-4178-a621-31ba6378946a HIGH 7.2 The HTTP Headers plugin for WordPress is vulnerable to External Control of File Name or Path leading to Remote Code Exec… wordfence
cdec0d79-a78a-499d-a7d0-94b65bfb84bd HIGH 7.2 The editid GET parameter of the Embed Youtube Video WordPress plugin through 1.0 is not sanitised, escaped or validated … wordfence
cde57dc8-9bfe-482c-8f04-654f4386e484
< 3.1.5
HIGH 7.2 The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL s… wordfence
cddfb3d3-89b8-4d93-8931-54de395fdb53
< 6.1.9.8
HIGH 7.2 The WP Maintenance plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.1.9.7 … wordfence
cdcdbba7-8280-457b-a511-66a486978a31
< 2.5.1
HIGH 7.2 The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 … wordfence
cdc993a4-6f65-4570-811c-13a80dbec064
< 2.0.6
HIGH 7.2 The WooCommerce Order Proposal plugin for WordPress is vulnerable to privilege escalation via order proposal in all vers… wordfence
cdb483db-56f7-4d12-9022-46c829091cc1
< 0.9.8.6
HIGH 7.2 The Custom Content Type Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and inclu… wordfence
cd97d688-d8af-4598-8faa-97eefad63808 HIGH 7.2 Cross-site scripting (XSS) vulnerability in mce_anyfont/dialog.php in the AnyFont plugin 2.2.3 and earlier for WordPress… wordfence
cd02c709-f0c0-43cc-b0b5-90b8cb1837fe
< 4.3.4
HIGH 7.2 The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cr… wordfence
ccf0d2ca-2891-45d1-8ea2-90dd435b359f
< 7.11.7
HIGH 7.2 The Avada theme for WordPress is vulnerable to SQL Injection via the 'entry' parameter in all versions up to, and includ… wordfence
cca551d0-24a7-457d-a221-ba0b68ab143e
< 4.3.3
HIGH 7.2 The Jobify theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.3.2 due … wordfence
cc987edf-5a68-4baf-947c-e623c85ec659
< 8.3.8
HIGH 7.2 Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.7, did not verify some of the uploaded fee… wordfence
← Prev 350 351 352 353 354 355 356 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top