πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 441 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c74553c0-366e-44d7-8c4a-161a05ef02b4
< 2.2.6
MEDIUM 6.5 The Templately plugin for WordPress is vulnerable to unauthorized loss of data due to an improper capability check on th… wordfence
c726cf73-3cf8-462d-a33d-2bbba9bfc02a
< 3.3.0
MEDIUM 6.5 The The A WordPress Testimonial Plugin to Showcase Testimonial Slider, Testimonial Grid and More: Solid Testimonials plu… wordfence
c6d1f25f-9024-41e4-9665-aad0a520bbab MEDIUM 6.5 The Uptime Robot Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… wordfence
c6600f0f-2fa3-49b8-bab3-a74f69da5024 MEDIUM 6.5 The FAT Services Booking plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.6 due t… wordfence
c63079af-6a22-4692-ab81-96e166a00c38
< 3.5.3
MEDIUM 6.5 The Event Manager and Tickets Selling Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary settings re… wordfence
c6168ee5-5df3-4d79-96bb-95029f2ac54b
< 4.6.13
MEDIUM 6.5 The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in version… wordfence
c5d46fdb-b028-4298-884b-e4fe9d6bb5ca
< 8.6.11
MEDIUM 6.5 The The MapSVG plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,… wordfence
c5c9d5de-f0d0-4469-97cc-8a25740c8fde
< 3.7.2
MEDIUM 6.5 The Phone Orders for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability … wordfence
c5ba37d7-8fde-4ee3-93db-d2459da34bc4 MEDIUM 6.5 The WP Page Permalink Extension plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and i… wordfence
c59cddfb-c434-4a69-9c1c-7d58f022c1aa
< 2.8.8
MEDIUM 6.5 The Download Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.8.7.… wordfence
c59ac25a-3b97-4295-a882-6701f2a59db0 MEDIUM 6.5 The Premium SEO Pack plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.3.2 due to … wordfence
c56ec6ae-5b75-4cbb-aedd-f318fddc7bf0
< 6.5.0
MEDIUM 6.5 The Fancy Product Designer plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and … wordfence
c56e5250-7cbd-41f4-9b8c-79a644830708
< 21.3
MEDIUM 6.5 The Frontend File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check a… wordfence
c55bf5f5-20d5-4157-94d3-1a330cdc82df
< 5.0.10
MEDIUM 6.5 The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to gene… wordfence
c4feb8e8-8620-44b9-9e8d-7ea513e168ff
< 4.4.9
MEDIUM 6.5 The ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting in the Admin Dashboard in versions up to, … wordfence
c46f66ee-28cf-4c4c-aaba-aacfad37ad89 MEDIUM 6.5 The WordPress Dashboard Tweeter plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
c3f0ff27-49d7-4aa0-aa00-2853eadecddb
< 5.5
MEDIUM 6.5 The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via '… wordfence
c3ca06c0-6a7d-43ee-ac59-698e0f525e23
< 10.2.5
MEDIUM 6.5 The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions … wordfence
c3a381da-0dac-4b7f-8da8-46bb81c88f12
< 3.0.3
MEDIUM 6.5 The WCMultiShipping β€” Mondial Relay, Inpost & Chronopost for WooCommerce plugin for WordPress is vulnerable to SQL Inj… wordfence
c384d6c2-8aba-48ce-b989-66bcaa3ec4bf
< 1.2.7
MEDIUM 6.5 The Broken Link Checker plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.6 due … wordfence
c35efa26-9400-47f1-80c3-e86ca29c6b47
< 3.4.28
MEDIUM 6.5 The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields. wordfence
c35ed3ef-49bd-4f64-bb0f-2abedb7b978e
< 2.3.7
MEDIUM 6.5 The One User Avatar WordPress plugin before 2.3.7 does not check for CSRF when updating the Avatar in page where the [av… wordfence
c320e437-c1b4-4ccf-9dfd-55ba9c810534
< 1.9.7
MEDIUM 6.5 The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the … wordfence
c3190f9f-8b2f-4251-8804-f386e2c5678f
< 3.2.12
MEDIUM 6.5 The WP-Optimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.1… wordfence
c311f5f8-d781-4b89-aa6d-a1ed7c5f4c4c MEDIUM 6.5 The Ultimate Push Notifications plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.… wordfence
← Prev 438 439 440 441 442 443 444 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top