πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 358 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c490e344-66da-4176-bd93-7e07a491bfa9
< 2.3.8
HIGH 7.2 The All in One SEO Pack plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting via unspecifie… wordfence
c4831a75-9d2b-4808-8b23-f1e9750fd905
< 2.0.12
HIGH 7.2 SQL injection vulnerability in the wpDataTables Lite Version 2.0.11 and earlier allows remote authenticated attackers to… wordfence
c48091fc-c11d-4753-9763-e1face3723fe
< 1.5.9
HIGH 7.2 The PublishPress Capabilities plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions u… wordfence
c4351ae8-7e9e-47fd-8733-2159711664af HIGH 7.2 The Pool Services WordPress Theme + RTL theme for WordPress is vulnerable to Server-Side Request Forgery in all versions… wordfence
c40bf215-81c1-423a-9d41-9a231dfc8053
< 3.2
HIGH 7.2 The Landing Page Builder plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.… wordfence
c3f3e56e-bbb6-4ceb-811d-447ed837d176
< 3.5
HIGH 7.2 Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau… wordfence
c3efbd9d-e2b5-4915-a964-29a49c7fba86
< 21.5.1
HIGH 7.2 The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the full name value in versions up to, … wordfence
c3d2425e-69e5-4efe-bbc6-0ef121e74341
< 4.3.4
HIGH 7.2 The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cr… wordfence
c3adf367-0126-4d95-b337-cc3581975113
< 3.8.20
HIGH 7.2 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
c3a993fb-cec5-4a36-9f92-3defff0ab11b
< 3.3.78
HIGH 7.2 The LiquidPoll – Polls, Surveys, NPS and Feedback Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
c389ba1a-45c5-4fba-9b99-0713fe39da42
< 2.6.0
HIGH 7.2 The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to Directory Traversal in all versi… wordfence
c3854d33-e9c5-4e35-93e3-5d4989b59413
< 2.4
HIGH 7.2 The Remoji – Post/Comment Reaction and Enhancement plugin for WordPress is vulnerable to Stored Cross-Site Scripting i… wordfence
c37bbb3b-5ef4-4604-9b0e-256dde546b4b HIGH 7.2 The T&P Gallery Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and incl… wordfence
c31de71e-254a-4ae1-a4f1-0922c26d4154
< 3.15.0.9
HIGH 7.2 The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
c318a0cf-5aaa-4442-a25e-138936d1dc90
< 1.7.11
HIGH 7.2 The ImageMagick Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including,… wordfence
c2990ed9-061e-4d35-aae0-99282a4f3737
< 1.8.176
HIGH 7.2 The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unaut… wordfence
c296743a-ec08-4cdd-b3d0-ab3de93f5bb9
< 1.0.15
HIGH 7.2 An open redirect in the Music Store – WordPress eCommerce plugin before 1.0.15 for WordPress allows attackers to redir… wordfence
c2826ac2-bb1c-4aee-ba3f-c77825fc395c
< 4.21.86
HIGH 7.2 The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to PHP Object Injection in version… wordfence
c2777158-baa4-4209-ae15-03da5adafc75 HIGH 7.2 includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues. wordfence
c2059b3f-2fbc-4dbb-b8f8-4dddb5320455
< 8.0.7
HIGH 7.2 The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable… wordfence
c154cc4b-f0b9-4c3e-8e74-9bfa6de62d2f
< 1.2.1
HIGH 7.2 The Counter Box plugin for WordPress is vulnerable to time-based blind SQL Injection via the β€˜s’ parameter in versio… wordfence
c143afd2-020f-40de-9480-bf27f1c50327 HIGH 7.2 The Easy Taxonomy Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
c12c046a-2ee4-4daa-9b2e-807d31041188
< 3.3.0
HIGH 7.2 The JobSearch WP Job Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
c12ba39f-03bc-4a45-b2f4-368f48c0a57b HIGH 7.2 The Pressference Exporter plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.3 du… wordfence
c0ca284d-1d03-46d6-94a4-7cc72e4bbf87 HIGH 7.2 The Popup4Phone plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, … wordfence
← Prev 355 356 357 358 359 360 361 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top