🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 415 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c884af7a-cd66-4f38-887d-a782ffb32219
< 2.0.9.1
HIGH 7.1 The AffiliateWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filter_from’ parameter… wordfence
c77295f3-0a37-4fa8-a375-b4bd3dc55945
< 1.1.48
HIGH 7.1 The Contact Form Email plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cal’ parameter … wordfence
c7641d52-e930-4143-9180-2903d018da91
< 2.6.4
HIGH 7.1 The Index Now plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6… wordfence
c6aaabe9-4f55-4c01-b350-573e6a944353
< 2.8.9
HIGH 7.1 The ShopLentor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
c5f23c14-e9ed-474c-9acc-2d6d43201572 HIGH 7.1 Cross-site scripting (XSS) vulnerability in includes/getTipo.php in the ToolPage plugin 1.6.1 and earlier for WordPress … wordfence
c39c1b72-e3e0-44fb-8fb8-602cb0aa61e3
< 3.1.9
HIGH 7.1 The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to,… wordfence
c38b6cce-ea8b-48f3-a995-173047d1caf8
< 1.5.2
HIGH 7.1 Cross-site scripting (XSS) vulnerability in the Polylang plugin before 1.5.2 for WordPress allows remote attackers to in… wordfence
c3678b4d-0cd0-4873-8cf3-90c557931f4c
< 5.9.8.5
HIGH 7.1 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due … wordfence
c237c4bc-b971-4d76-97a1-155ef7a3e5df HIGH 7.1 The Easy Blocks pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
c1532e12-b786-4b87-ae19-951297c47a6c
< 2.26.6
HIGH 7.1 The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_block… wordfence
bf0f549d-1d88-415a-81f3-b50f977e2c17
< 8.2.4
HIGH 7.1 Cross-site request forgery (CSRF) vulnerability in the All in One Webmaster plugin before 8.2.4 for WordPress allows rem… wordfence
bb5f73c3-f40b-45d5-9947-c1a514d230f7
< 2.4.45
HIGH 7.1 The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… wordfence
b948574a-0aab-4596-83e6-04be21f78bc1 HIGH 7.1 Several YITHEMES plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the c… wordfence
b8d63789-16b3-443b-8dcb-67b1e5e25d20
< 1.3.21
HIGH 7.1 The Cloudflare plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 1.3.… wordfence
b722bf4e-1e04-4d80-b359-7d43596751a8 HIGH 7.1 The Flashlight theme plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.8.4 … wordfence
b6de66ee-08f6-47f6-b6d1-edbf7bea70d8
< 2.1
HIGH 7.1 Cross-site scripting (XSS) vulnerability in the Custom Banners plugin before 2.1 for WordPress allows remote attackers t… wordfence
b647a6c5-3710-43ec-bf31-87b5a26d54b3
< 5.5.7
HIGH 7.1 The Formidable Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
b46b5299-2c14-4eb7-872c-f43518e1d31d HIGH 7.1 Cross-site scripting (XSS) vulnerability in process.php in the Malware Finder plugin 1.1 and earlier for WordPress allow… wordfence
b4503e2c-0d0d-45de-a597-baace44a98a7
< 5.6.18
HIGH 7.1 The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cro… wordfence
b0d8499a-a630-4c2b-9381-78ac83da119d
< 3.2.13
HIGH 7.1 The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
b0b2bdb3-713c-47c6-8907-ac0f86038dc2
< 3.10.4
HIGH 7.1 The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is… wordfence
b05ece19-ba0d-456e-bdab-86abe9a13e70
< 5.2.0
HIGH 7.1 The Newsletter Meenews plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 5.1.… wordfence
af1796b7-64b4-4198-9ba4-8a77a0f1cf02 HIGH 7.1 Cross-site scripting (XSS) vulnerability in oleggo-twitter/twitter_login_form.php in the Oleggo LiveStream plugin 0.2.6 … wordfence
aed2ec57-2475-4e77-8219-399cf769ba5a
< 3.1.2.6
HIGH 7.1 The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘quiz’ parameter in versi… wordfence
ae1e198b-0c0d-47aa-8a56-ec4e790c8022
< 4.16.12
HIGH 7.1 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
← Prev 412 413 414 415 416 417 418 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top