🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 542 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c73e53c0-3b69-4f45-b2c5-2e9b55bb8e77
< 1.2.9
MEDIUM 6.4 The Pie Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2… wordfence
c7296ef0-6cba-4aa3-acf7-621247691e81 MEDIUM 6.4 The Reftagger Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
c7243f40-5cca-475a-bb27-44fab965bb0e
< 3.10.8
MEDIUM 6.4 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Gro… wordfence
c722238a-6222-48f8-9b01-bdba56490c83
< 1.1.0
MEDIUM 6.4 The MyBrain Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'mbumap' short… wordfence
c6f96cec-ddcb-45b2-a28c-b4e7b6f5c719
< 8.3.6
MEDIUM 6.4 The WP Customer Area plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the `… wordfence
c6f8f178-47a4-4bca-b8a2-e8f148c24e1b
< 1.5.0
MEDIUM 6.4 The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerabl… wordfence
c6efb471-3f6a-4ec0-a2cd-fc1154d48ef5
< 1.1.7
MEDIUM 6.4 The Form to Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
c6e8a78b-01ad-47b2-84e6-4f6ff78c02b6
< 4.1.9
MEDIUM 6.4 The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘location_dir’ pa… wordfence
c6d5275d-43d0-41f6-96c7-e7646eac4534
< 1.31
MEDIUM 6.4 The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the style parameter in all vers… wordfence
c6c93ec9-668d-4b8d-abc4-edd04cbf9839
< 2.0.8
MEDIUM 6.4 The BNE Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in … wordfence
c6b75ae7-89d9-4dd4-85c1-c12369bd86c8
< 5.11
MEDIUM 6.4 The Library Bookshelves plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bookshelf' s… wordfence
c6ac5484-3caa-4821-990b-cd49c2c4873d
< 5.10.29
MEDIUM 6.4 The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is… wordfence
c6aa5b1d-e718-4c93-ab00-7fc343bbffba
< 2.0.0
MEDIUM 6.4 The Graphina plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.10 … wordfence
c698ba21-f578-469c-8148-7b949027ce7f MEDIUM 6.4 The Profile Widget Ninja plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
c693831f-fe60-4548-83aa-4ebd03d134ec
< 2.0.7.2
MEDIUM 6.4 The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin fo… wordfence
c691e469-3bd2-415d-8feb-9ae94aeaf339
< 1.3.10
MEDIUM 6.4 The Contact Form, Survey & Form Builder – MightyForms plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
c6848b7a-d869-41e7-9f33-01a35b6d4822 MEDIUM 6.4 The Github Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'repo' shortcode attribut… wordfence
c6840350-7ff4-4ec2-bf2b-94ce6f782537
< 3.1.73
MEDIUM 6.4 Cost Calculator Builder Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 3.1.… wordfence
c67f01c0-8b49-48e3-88da-49b39d6b0a4a
< 2.5.21
MEDIUM 6.4 The Most And Least Read Posts Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
c67c958e-1ab2-498c-b665-73e239d0029b
< 2.8.4
MEDIUM 6.4 The Out of the Block: OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's o… wordfence
c6670e56-ae81-4b1b-8274-bf355a411e92
< 2.1.2
MEDIUM 6.4 Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers… wordfence
c65b6793-42e3-40cb-a6fe-b000c879d41f
< 2025r2
MEDIUM 6.4 The Store Locator Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'storelocato… wordfence
c65a5a9a-3c2a-40a8-903b-4258f065b443 MEDIUM 6.4 The List Related Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
c64a4e84-fc39-47fa-904c-87a252fbf134 MEDIUM 6.4 The Multi-day Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
c63ff9d7-6a14-4186-8550-4e5c50855e7f
< 2.1.0
MEDIUM 6.4 The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's themify_button… wordfence
← Prev 539 540 541 542 543 544 545 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top