ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 357 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c7a7df90-a542-48cf-a58e-bcbddc978df2
< 1.8.0
HIGH 7.2 The PeproDev CF7 Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission in versi… wordfence
c79587d8-56a9-4c1c-99dc-bc66194ffe52
< 2.70
HIGH 7.2 The WP-UserOnline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp-useronline.php file in ve… wordfence
c77db815-e401-4410-b6ec-e6668dd988ab
< 3.0
HIGH 7.2 The WPide plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 2.6. This makes… wordfence
c77b357e-4bcd-45e2-9a84-7d299fcfdd88
< 7.5.2
HIGH 7.2 The wpDataTables (Premium) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
c7723579-33ca-4007-a6fa-31b15f3e70a1
< 3.7.2
HIGH 7.2 The Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, an… wordfence
c73d4b78-72aa-409a-a787-898179773b82
< 1.0.229
HIGH 7.2 The Colibri Page Builder for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to,… wordfence
c7349e5f-fd45-44bf-9f9e-c0d109069232
< 2.5.0
HIGH 7.2 The Chatbot for WordPress by Collect.chat âš¡ï¸ plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… wordfence
c6f6662f-1013-4de1-9091-1ac330260eed
< 3.0.8
HIGH 7.2 The Footnotes Made Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all ver… wordfence
c6a6fa09-f7bd-4ed0-8fdc-3f927b33af02
< 1.5
HIGH 7.2 The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id… wordfence
c6716a5d-48ed-4735-b765-a7606ea401d0
< 1.5.3
HIGH 7.2 The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cont… wordfence
c660f356-46af-4d34-af82-ab2a0b74dded HIGH 7.2 The Downloable by American Osteopathic Association plugin for WordPress is vulnerable to Server-Side Request Forgery in … wordfence
c65a4ac6-0438-40d0-b0b4-32366fac477c
< 8.3.8
HIGH 7.2 The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cro… wordfence
c5fcfa21-b3f7-4241-a931-9708ced4f811
< 2.6.1
HIGH 7.2 The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versio… wordfence
c5ce2d08-6e01-4a7c-a2d5-ba98639107a8
< 1.15.6
HIGH 7.2 The MultiParcels Shipping For WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘s… wordfence
c5bfa818-65e4-4b36-8b61-6f47b42eb6c5
< 3.7.5
HIGH 7.2 Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordPress before 3.9.x before 3.9.3 and 4.x b… wordfence
c57bd721-2888-47d1-97a4-7c7603396f2b
< 1.12.0
HIGH 7.2 The Smart Popup by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
c5697616-4e19-45a3-b860-623af66469bc
< 1.55.0.2
HIGH 7.2 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored C… wordfence
c5549f6a-f7ac-4586-a3ff-43abeaedd4a0
< 1.1.0
HIGH 7.2 The WOLF - WordPress Posts Bulk Editor and Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
c548b70a-8566-4aaf-a3a2-fce6c19e6a0c
< 2.36
HIGH 7.2 The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Infor… wordfence
c548a6dc-7c6d-4837-9417-dabb3fc8f0f6
< 1.0.25
HIGH 7.2 Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting in various versions due to in… wordfence
c53c322a-b197-4ece-ae4a-a3a86a009e4d
< 1.6.0
HIGH 7.2 The Make Connector plugin for WordPress is vulnerable to arbitrary file uploads due to misconfigured file type validatio… wordfence
c4f22ca7-0e7c-438a-8e63-cf3723d087f4
< 3.7.6
HIGH 7.2 The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' param… wordfence
c4dd681d-90cb-44dc-adf0-d7e269d15a60
< 4.9.9
HIGH 7.2 The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
c495ac39-c99b-423d-a601-d0bfcc514ebe
< 2.4.2
HIGH 7.2 The Product Import Export for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… wordfence
c49389b5-bf5a-49b8-8d20-404195b50308 HIGH 7.2 The Notification Bar for WordPress plugin is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in vers… wordfence
← Prev 354 355 356 357 358 359 360 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top