🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 356 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cae74177-7bfc-4fe2-9d45-0bc567a17909
< 2.5
HIGH 7.2 The White Label CMS plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.4 via… wordfence
cae284dd-34e0-4dc5-a954-b37935f3cfbc
< 1.8
HIGH 7.2 The Awin Data Feed WordPress plugin through 1.6 does not sanitise and escape a header when processing request to generat… wordfence
cabdc9db-2d1c-4390-a4b7-65648ef9f16a HIGH 7.2 The SIS Handball plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in versions … wordfence
caa5b9aa-e98c-48fc-9e63-0a1380465918
< 5.0.1
HIGH 7.2 The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin… wordfence
caa39613-aaf3-4e47-8866-8fda1f7fc15b
< 3.2.12
HIGH 7.2 The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to SQL Injection via the '$email_add… wordfence
ca97a718-7508-4bc0-8f8e-7849eb9a0dc0
< 3.3
HIGH 7.2 The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cro… wordfence
ca91e41d-b728-4eb0-86d5-043813d8c2c1
< 4.5.13
HIGH 7.2 The WP Meta SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Referer’ header in all ve… wordfence
ca73de6d-2d47-4d7c-a917-0f99fed8c27d
< 2.1.0
HIGH 7.2 The SVG Sanitizer library is vulnerable to XSS Bypass in versions up to, and including, 0.15.4. This may allow an attack… wordfence
ca6c0527-5a1c-4bf3-af71-8e40381f0c1c
< 4.15
HIGH 7.2 The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.14… wordfence
ca616ae6-59d3-4037-b538-d371f007a037 HIGH 7.2 The Frontend Registration – Contact Form 7 plugin for WordPress is vulnerable to privilege escalation in versions up t… wordfence
ca1fd2f3-7f3a-4227-b013-95e4ec59fce4
< 1.0.8
HIGH 7.2 The PostmagThemes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and includ… wordfence
c9fe3574-f338-474c-af78-f843501d422c
< 1.2.4
HIGH 7.2 The Site Mailer – SMTP Replacement, Email API Deliverability & Email Log plugin for WordPress is vulnerable to Stored … wordfence
c9c1ddaf-4bf2-4937-b7bf-a09162db043e
< 5.4.11
HIGH 7.2 The WP EasyCart plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in versio… wordfence
c9a989db-683c-492c-8c26-abef0fecf00e
< 9.1.2
HIGH 7.2 The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection. wordfence
c92776c4-643c-40f2-ac28-5df5d6bf7fcd
< 2.37
HIGH 7.2 The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to arbitrary file … wordfence
c91a14d3-bc41-4490-888c-486ad2994095
< 1.7.1057
HIGH 7.2 The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter … wordfence
c8f42f17-bce2-421e-9031-bfa0f8c26b2a HIGH 7.2 The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inc… wordfence
c8bc1653-8fee-468a-bb6d-f24959846ee5
< 2.8.4
HIGH 7.2 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… wordfence
c88f9c43-6772-4406-b1f0-2d20f970f1c2
< 7.1.0
HIGH 7.2 The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 7.0.0-7.0.16 d… wordfence
c8416840-c022-40a1-bcd3-17b34df11d95
< 4.5.4
HIGH 7.2 The ProfilePress plugin for WordPress is vulnerable to Cross-Site Scripting via $data['name'] parameter in versions up t… wordfence
c80e6f0b-ccca-4755-b64e-cfcebc5cc1fe
< 1.4.0
HIGH 7.2 The WP Sticky Button plugin for WordPress is vulnerable to stored cross-site scripting in versions up to, and including,… wordfence
c7f10f62-98cf-4629-9a48-59a42490276d
< 2.1.1
HIGH 7.2 The Catch Themes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and includi… wordfence
c7f098b9-eca3-41c7-9c74-0f4b3f75c915
< 8.14.1
HIGH 7.2 The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFi… wordfence
c7b1216e-b174-4598-bd7b-27a34d251d8a
< 15.0.6
HIGH 7.2 The Simple Link Directory Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
c7ab6715-78ac-4030-9147-73c472c6b2e0
< 1.1.0
HIGH 7.2 The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPr… wordfence
← Prev 353 354 355 356 357 358 359 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top