ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 541 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c85c13ed-6981-4062-8aca-800721b28b88
< 2.8.1
MEDIUM 6.4 The WxSync plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.0 due… wordfence
c8452e54-7a81-4921-b531-8cb3b0953dab
< 2.5.0
MEDIUM 6.4 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
c8177f27-19e1-4272-91ee-55d980b7128e MEDIUM 6.4 The Infomaniak Connect for OpenID plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'endpoint_lo… wordfence
c80d845b-117e-4f60-8978-4aa9806d8c9d
< 2.14.4
MEDIUM 6.4 The Paid Member Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
c7ffd34b-c1b5-4031-937d-c509f9979116 MEDIUM 6.4 The Administrator Z plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
c7f7b6b1-61d6-4911-ad1f-16a14c16618d
< 2.0.8
MEDIUM 6.4 The uTubeVideo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in … wordfence
c7f5ac78-5195-4b59-abc7-f41e487f9361
< 0.1.11
MEDIUM 6.4 The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's taeggie-feed shortco… wordfence
c7e1028e-e04b-46c4-b574-889d9fc1069d
< 3.21.6
MEDIUM 6.4 The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored C… wordfence
c7d3edf5-245f-42f2-9add-e87de6839ed1
< 3.0
MEDIUM 6.4 The CITS Support svg, webp Media and TTF,OTF File Upload plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
c7d04f7d-d114-4104-a7cb-298c148e2b6d
< 2.0.10
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in wp-includes/general-template.php in WordPress before 20070309 allows remote … wordfence
c7cdf109-a9ce-4b1e-ac4d-07c5eee550cf
< 1.4.5
MEDIUM 6.4 The Block for Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode … wordfence
c7c8380b-02ae-49d2-8c64-debe7f73ee35
< 2.1.18
MEDIUM 6.4 The Author Avatars List/Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortco… wordfence
c7bcd458-71bf-4961-a7ce-3f88593f6f5e
< 4.1
MEDIUM 6.4 The iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘onload’ attribute found in the… wordfence
c7aaff3e-0c81-4fe7-b162-569c517f6c49
< 1.1.37
MEDIUM 6.4 The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
c7aa1f57-44c2-45ec-87a3-483f8dc9a957
< 7.5.19.728
MEDIUM 6.4 Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versi… wordfence
c7a943e2-f121-4f3c-b7e9-81a2158fa93f
< 1.5.3.5
MEDIUM 6.4 The Landing Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
c7a2be64-18e5-4e79-a5a2-3bf3cf949a67
< 7.5.880
MEDIUM 6.4 The Lead capture, gated content & newsletter opt-ins plugin for WordPress is vulnerable to Stored Cross-Site Scripting i… wordfence
c78acf9d-89bf-4c8f-b333-31a330701614
< 3.13
MEDIUM 6.4 The sola-support-tickets plugin before 3.13 for WordPress has incorrect access control for /wp-admin with resultant XSS. wordfence
c77ef86e-ea5b-46fc-a3d7-d11a20f3f871
< 4.4.3
MEDIUM 6.4 The EAN for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in… wordfence
c7780eea-230b-41ad-addd-92791e5ab432
< 2.0.0
MEDIUM 6.4 The Blur Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.0 … wordfence
c763a8d8-c31a-4c9f-8f0e-814cda91b860
< 2.24
MEDIUM 6.4 A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an appl… wordfence
c7528928-e677-4a2d-8ee1-78166d0c34df
< 3.4.7
MEDIUM 6.4 The Catch Base theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.6 … wordfence
c745b86b-8ab7-4e04-8888-65e43d568410
< 3.3.61
MEDIUM 6.4 The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
c7457ce7-8471-415d-8e34-4505aa34fd61
< 3.2.46
MEDIUM 6.4 The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to DOM-based Sto… wordfence
c74209e2-52cc-4ea1-967f-65fb9031e9a0
< 0.5.72
MEDIUM 6.4 The Co-marquage service-public.fr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sho… wordfence
← Prev 538 539 540 541 542 543 544 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top