πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 540 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c923d1d6-04c6-4ea2-a69e-041fea1e280a
< 3.7.6
MEDIUM 6.4 The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
c91a4d4d-5bfa-42fd-80b4-7a75ee79db19
< 2.0.12
MEDIUM 6.4 The GZSEO plugin for WordPress is vulnerable to authorization bypass leading to Stored Cross-Site Scripting in all versi… wordfence
c9141ad3-86cf-47ae-be99-d78f0337f2ca
< 6.5.2
MEDIUM 6.4 The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulner… wordfence
c90f9935-0cdf-4699-bf1c-89e287d8ede0
< 5.2.6
MEDIUM 6.4 The WP Flow Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.2… wordfence
c8f45054-e6a4-403b-94eb-2dd2a4840c22
< 1.4.1
MEDIUM 6.4 The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in … wordfence
c8e231a9-4527-41b1-adf6-4eab6bf39801 MEDIUM 6.4 The Elizaibots plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.2… wordfence
c8e1bc48-98ff-48f0-b3b3-4032dc3ac3f1
< 1.0.14
MEDIUM 6.4 The Calendar.online / Kalender.digital plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
c8db80ef-5863-41dd-b33f-850984a72ee6
< 5.9.22
MEDIUM 6.4 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… wordfence
c8d7448a-b8a6-4b0b-92df-a15272fc56bf
< 3.20.3
MEDIUM 6.4 The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
c8d06b5d-43b8-4dae-abe9-abe07a63528e
< 1.4.1
MEDIUM 6.4 The Shortcode for Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortc… wordfence
c8c60701-37f0-4404-b965-9136ac456e38
< 1.7.0
MEDIUM 6.4 The Structured Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_fs_local_bu… wordfence
c8c530e2-ce42-40f3-82ab-1df9089a5407
< 6.11.5
MEDIUM 6.4 The Ecwid Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) … wordfence
c8bd975a-38ac-4014-a4c5-d022e58afc54 MEDIUM 6.4 The BeBetter Social Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
c8a93aab-4845-46ed-8adc-d06b2ee8ee9e MEDIUM 6.4 The Login Logout Register Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'llrml… wordfence
c8a4e9b8-9794-48b7-8c53-cfad37ed530c
< 1.0.20
MEDIUM 6.4 The ConvertBox Auto Embed WordPress plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜… wordfence
c8a27ec5-019b-4aa5-8317-1c832af3b7ca
< 1.8.2
MEDIUM 6.4 The Hot Random Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute in versi… wordfence
c89934b1-5e3c-4bf2-8d36-17c4268ccd4e
< 2.0.66
MEDIUM 6.4 The Contests by Rewards Fuel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'RF_CONT… wordfence
c896da97-3100-43a8-a5e0-44b61c4431fd
< 1.11
MEDIUM 6.4 The Juicer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions … wordfence
c88d378a-6c58-4670-b0b6-0e0d51c39bd1 MEDIUM 6.4 The Zenost Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' and 'target' para… wordfence
c88c6ad8-d4bd-4785-a6e7-e5034c58158b
< 1.7.0
MEDIUM 6.4 The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cro… wordfence
c886daf1-6e1e-4100-bd40-241588de0410 MEDIUM 6.4 The Simpul Events by Esotech plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
c87e7f50-f14a-4751-abcb-3a5bdd214889
< 4.2.1
MEDIUM 6.4 The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the … wordfence
c87a80ad-27bf-404d-8adf-9acc91354515
< 8.14.1
MEDIUM 6.4 The Google Analytics by Monster Insights plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
c877ac24-a6da-4e61-a669-a0224c9e3bb5
< 2.5.2
MEDIUM 6.4 The Fancy Elementor Flipbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Fancy Elementor Fl… wordfence
c8647c44-4879-4895-bd07-19f7d62a7326
< 1.7
MEDIUM 6.4 The Weaver Show Posts Plugin for WordPress is vulnerable to stored Cross-Site Scripting due to insufficient escaping of … wordfence
← Prev 537 538 539 540 541 542 543 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top