πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 355 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cdec0d79-a78a-499d-a7d0-94b65bfb84bd HIGH 7.2 The editid GET parameter of the Embed Youtube Video WordPress plugin through 1.0 is not sanitised, escaped or validated … wordfence
cde57dc8-9bfe-482c-8f04-654f4386e484
< 3.1.5
HIGH 7.2 The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL s… wordfence
cddfb3d3-89b8-4d93-8931-54de395fdb53
< 6.1.9.8
HIGH 7.2 The WP Maintenance plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.1.9.7 … wordfence
cdcdbba7-8280-457b-a511-66a486978a31
< 2.5.1
HIGH 7.2 The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 … wordfence
cdc993a4-6f65-4570-811c-13a80dbec064
< 2.0.6
HIGH 7.2 The WooCommerce Order Proposal plugin for WordPress is vulnerable to privilege escalation via order proposal in all vers… wordfence
cdb483db-56f7-4d12-9022-46c829091cc1
< 0.9.8.6
HIGH 7.2 The Custom Content Type Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and inclu… wordfence
cda83985-aa36-40ac-80ee-6963fcd77702
< 8.12
HIGH 7.2 The Visitors Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
cd97d688-d8af-4598-8faa-97eefad63808 HIGH 7.2 Cross-site scripting (XSS) vulnerability in mce_anyfont/dialog.php in the AnyFont plugin 2.2.3 and earlier for WordPress… wordfence
cd02c709-f0c0-43cc-b0b5-90b8cb1837fe
< 4.3.4
HIGH 7.2 The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cr… wordfence
ccf0d2ca-2891-45d1-8ea2-90dd435b359f
< 7.11.7
HIGH 7.2 The Avada theme for WordPress is vulnerable to SQL Injection via the 'entry' parameter in all versions up to, and includ… wordfence
cca551d0-24a7-457d-a221-ba0b68ab143e
< 4.3.3
HIGH 7.2 The Jobify theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.3.2 due … wordfence
cc987edf-5a68-4baf-947c-e623c85ec659
< 8.3.8
HIGH 7.2 Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.7, did not verify some of the uploaded fee… wordfence
cc8e2042-93aa-454a-97b7-283d8a22bf46
< 1.0.34
HIGH 7.2 Multiple cross-site scripting (XSS) vulnerabilities in the Mingle Forum plugin before 1.0.34 for WordPress allow remote … wordfence
cc7075a6-5609-42ab-a4cb-9d33686c7de0
< 1.6.4
HIGH 7.2 The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to… wordfence
cc49db10-988d-42bd-a9cf-9a86f4c79568
< 1.4.0
HIGH 7.2 The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.… wordfence
cc174fc6-b72a-49ed-9aed-7a935a239295
< 7.0.1
HIGH 7.2 The WPJAM Basic plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, … wordfence
cbf8a398-334b-4b89-8a39-b8f0032fefc7
< 1.0.9.2
HIGH 7.2 The Transposh WordPress Translation plugin for WordPress is vulnerable to remote code execution in versions up to, and i… wordfence
cbdfef0e-aadd-456b-84f6-ecd626400cbe
< 2.0
HIGH 7.2 The Videopack (formerly Video Embed & Thumbnail Generator) plugin for WordPress is vulnerable to remote code execution i… wordfence
cbd42fc4-ab4a-4053-b765-18272eacd2bc
< 3.7.4.1
HIGH 7.2 The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… wordfence
cbc3210d-224e-4ed2-ada7-dc17deb17584
< 2.3.5
HIGH 7.2 The Debug Log Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the auto-refresh debug log i… wordfence
cb9ca8e0-741c-4763-b677-61f16e5a3b50
< 1.2.1
HIGH 7.2 The Event Monster plugin for WordPress is vulnerable to SQL Injection via the β€˜id’ parameter in versions up to, and… wordfence
cb8c80fc-3b51-4003-b221-6f02e74bead0
< 1.7.2
HIGH 7.2 The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging feature … wordfence
cb73e92b-b807-4406-b378-cef6cff9eb82 HIGH 7.2 The Estatik Mortgage Calculator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up … wordfence
cb713c9c-adb4-410c-a92f-d4d5b002d626
< 5.12
HIGH 7.2 The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Sid… wordfence
cb02878a-2c85-4dcb-bdc0-e65addf9fb9c
< 1.14.15
HIGH 7.2 The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting in all versions up to, and including,… wordfence
← Prev 352 353 354 355 356 357 358 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top