🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 539 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ca5befe9-7769-4367-84cf-05aabeced67a
< 2.2.0
MEDIUM 6.4 The Clever Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CAFE Icon, CAF… wordfence
ca50e5e7-be46-40f1-9782-a72ca8ab7e9a MEDIUM 6.4 The Yet Another WebClap for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' p… wordfence
ca4f243d-0a56-4b6c-86f9-6eb435203ddc
< 11.15.14
MEDIUM 6.4 The PowerPress Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
ca4824fb-192a-499d-bf92-aa59410d8d4a
< 3.7.22
MEDIUM 6.4 Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template n… wordfence
ca47486b-0761-48b8-94a7-77175ed5a37e
< 10.14.2
MEDIUM 6.4 The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up t… wordfence
ca29158a-ca60-46c7-93a5-bcf76e7666e4
< 7.1.3
MEDIUM 6.4 The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
ca26ff73-2374-4d11-94ce-3127d4a4c13b MEDIUM 6.4 The Image Hover Effects For WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in v… wordfence
ca1aafcc-8cc1-41f1-b28c-bf5707054ce9
< 2.1.0
MEDIUM 6.4 The ShopElement plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.… wordfence
ca149cc0-b256-41cd-b64d-dd905bd72602
< 1.2.6
MEDIUM 6.4 The Flex Guten plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘thumbnailHoverEffect’ para… wordfence
c9ebcd32-90c1-419c-a67c-6fe41ee9fab1
< 1.1.4
MEDIUM 6.4 The Recently Purchased Products For Woo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vie… wordfence
c9d82a7e-abf0-4698-898d-4bbd79d36321 MEDIUM 6.4 The I Plant A Tree plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
c9bd3620-60a2-4741-b623-5147b6997575
< 1.7.8
MEDIUM 6.4 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
c98c1ce9-8213-47cb-b928-3641f821a806
< 2.1.2.1
MEDIUM 6.4 The InPost Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'admin_thumb_width' paramet… wordfence
c97fc289-1ee3-4401-a57e-b4c8d998259e MEDIUM 6.4 The Ultimate Carousel For WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
c97c338d-19b1-40fc-90c5-3e52d4cc053b MEDIUM 6.4 The MyBookTable Bookstore plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
c97c0191-1ef4-4a37-a93d-bceb2be298b4 MEDIUM 6.4 The BP Direct Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bpdm_login' shor… wordfence
c974726e-9371-40e5-8664-c12c8c06e5b9
< 1.0.2
MEDIUM 6.4 The GeoDataSource Country Region DropDown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
c96e5939-5b6d-4cf2-83eb-a7b94f032bcb
< 1.1.1
MEDIUM 6.4 The GatorMail SmartForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gatormailsm… wordfence
c96decab-0943-43c6-b8f7-9fd2e3f3b45d MEDIUM 6.4 The WP AVCL Automation Helper (formerly WPFlyLeads) plugin for WordPress is vulnerable to Server-Side Request Forgery in… wordfence
c94e321e-69d9-40c5-8242-8d090ba604d1
< 2.1.0
MEDIUM 6.4 The Master Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
c9466e5f-d8eb-4de4-a1d2-e5ef15bf1e4e
< 1.0.270
MEDIUM 6.4 The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_pos… wordfence
c9443e36-648c-4984-8b06-28e9da959e26
< 1.3.5
MEDIUM 6.4 The Gallery Styles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery Block in all versio… wordfence
c9314970-1030-4488-8147-05ba1453182c MEDIUM 6.4 The Financial Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'finance_cal… wordfence
c930c240-df79-47d0-866c-de40c219ce25 MEDIUM 6.4 The Bacon Ipsum plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4 … wordfence
c927455d-5e20-4c8c-a1cd-455c8166335c
< 11.16.11
MEDIUM 6.4 The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
← Prev 536 537 538 539 540 541 542 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top