ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 544 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c57bffc8-1ee5-4380-a78f-f4fc8c606861 MEDIUM 6.4 The Scylla lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the … wordfence
c57b9a78-53f4-40bb-ae6a-c5242b41329f
< 0.0.8
MEDIUM 6.4 The ConvertForce Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gutenberg block… wordfence
c557fc55-3c0d-43ff-8575-32f669299b39
< 2.2.1
MEDIUM 6.4 The User IP and Location plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes i… wordfence
c5451e21-2782-4d2b-8c2b-be12102e20c4
< 1.2.3
MEDIUM 6.4 The Card Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via title tags in vers… wordfence
c530f5d2-eed3-433b-bf96-656593ad6ce2 MEDIUM 6.4 The Responsive video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's video settings f… wordfence
c52de26a-d52c-4b2e-8e51-731115d29bd0 MEDIUM 6.4 The RevInsite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `token` parameter in all version… wordfence
c52cdb58-c97a-43a6-a3ff-be084ceee085
< 6.1
MEDIUM 6.4 The Geo Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'geotargetlygeoconten… wordfence
c52cadb2-703f-4aad-85f2-aec1dd4befdc
< 2.0.5
MEDIUM 6.4 The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerabl… wordfence
c5293c0f-90b0-41df-a623-90297d998c41 MEDIUM 6.4 The 診断ジェãƒãƒ¬ãƒ¼ã‚¿ä½œæˆãƒ—ラグイン (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cro… wordfence
c5277e25-d923-4553-9371-192d4cf4389a MEDIUM 6.4 The Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's nd_cost_calculato… wordfence
c50c8eb5-5f7c-4294-86fa-a5998db0675c
< 2.5.7
MEDIUM 6.4 The Pz-LinkCard plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, … wordfence
c506fd52-ec10-48bd-a221-713d6c5951ce
< 2.0
MEDIUM 6.4 The Ultimate Classified Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
c4edf78c-cd17-42dd-90dc-10946e79d57b
< 1.2.3
MEDIUM 6.4 The Liveticker (by stklcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livetic… wordfence
c4e1ce97-c390-4b87-b68d-bbce93d4665f
< 2.1.4
MEDIUM 6.4 The Biagiotti Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, a… wordfence
c4db394c-415a-40c5-ae0e-2dfe503867d4
< 2.5.5
MEDIUM 6.4 The Search Atlas SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
c4d8ec65-cebe-48fe-875b-a62f2af2bfd8
< 3.4.1
MEDIUM 6.4 The Theme Switcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.… wordfence
c4d5d58f-913a-4a26-8b2a-bfdd08033993 MEDIUM 6.4 The Opal Estate Pro – Property Management and Submission plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
c4d46c87-5c30-4251-941e-a5e52b5d0c9f MEDIUM 6.4 The Simple Map No Api plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in… wordfence
c4d2e763-0dd6-4e1c-af37-036fffff84d7 MEDIUM 6.4 The Custom HTML Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
c4a46d4c-3f03-4d41-8382-b43a02b59cb2 MEDIUM 6.4 The Point Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'point_maker' shortco… wordfence
c4a20569-c1ad-49d2-b5dd-87b97ff95cc0
< 5.2.0
MEDIUM 6.4 The Highlight and Share – Social Text and Image Sharing plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
c4a051e3-4489-4124-abf6-905b7ff7fd3c
< 1.4.2
MEDIUM 6.4 The Freesia Empire theme for WordPress is vulnerable to Stored Cross-Site Scripting via post author display names in all… wordfence
c498bd08-e5ad-460f-ac25-f18ee7d0f35b MEDIUM 6.4 The DesignThemes Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
c495d7f6-6d4a-4b1a-90f9-5273e7773d7a
< 5.0.2
MEDIUM 6.4 The Advanced Custom Fields: Font Awesome Field plugin for WordPress is vulnerable to Cross-Site Scripting in all version… wordfence
c4886822-3a05-45b3-ad1d-4d4a4f921817
< 2.4.15
MEDIUM 6.4 The Serial Codes Generator and Validator with WooCommerce Support plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
← Prev 541 542 543 544 545 546 547 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top