πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 545 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c4884ba9-4448-43b0-93d3-110b719845ea
< 1.8.5
MEDIUM 6.4 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
c47e9220-d7d7-4a66-b555-8fa837d45d59 MEDIUM 6.4 The eVision Responsive Column Layout Shortcodes for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi… wordfence
c4770184-1b96-490c-b506-f648ab3ed764
< 2.0.8
MEDIUM 6.4 The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Count… wordfence
c46d71fb-ccf1-4cbe-8088-edb7fba225e9
< 1.6.5
MEDIUM 6.4 The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vul… wordfence
c4624846-3399-458b-8287-77553f43cd37
< 4.4.4
MEDIUM 6.4 The Maximum Products per User for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… wordfence
c4555cd1-5ae5-42b3-938f-ffce5ba4fe56
< 11.14.0
MEDIUM 6.4 The The7 β€” Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
c4528b63-8d8e-44a4-a71f-2ad1636ac93c
< 1.3.4
MEDIUM 6.4 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
c44c1a50-e282-4a5b-8b7f-1021c9d6f58e MEDIUM 6.4 The Monkee-Boy Essentials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all … wordfence
c44b7ded-e67d-4185-92de-78a82f409333
< 10.14.8
MEDIUM 6.4 The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
c4498d0a-32f2-4747-88bd-0f85312b4653
< 3.0.9.1
MEDIUM 6.4 The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shor… wordfence
c446f429-1981-4d6d-a5ec-a5837428d212
< 7.9.1
MEDIUM 6.4 The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's social i… wordfence
c43e292b-8344-4842-bed1-32e7f8cb992b
< 2.9.14
MEDIUM 6.4 An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stor… wordfence
c4285590-9c2f-4189-8b47-09378d8a2432
< 1.12.33
MEDIUM 6.4 The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜id’ parameter in all version… wordfence
c4250395-3709-47cd-86d4-e6a1fec10298
< 2.2.3
MEDIUM 6.4 The The Ultimate Video Player For WordPress – by Presto Player plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
c41b0370-2881-4053-98b1-9c70251a3b63
< 4.1.2
MEDIUM 6.4 The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the p… wordfence
c4067e03-427c-4b03-a250-0354572ae361
< 2.6.2
MEDIUM 6.4 The myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin plugin for WordPress is vulnerable to Store… wordfence
c3f07ebf-5e8b-42ea-853e-9b28784b14a5
< 2.0.28
MEDIUM 6.4 The Beds24 Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
c3ecf638-dfc4-4e9d-bca8-cd008227e934
< 1.2.2
MEDIUM 6.4 The User Avatar – Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcod… wordfence
c3ecda09-ecee-4e97-ae6f-92d52b0589e5
< 4.7.31
MEDIUM 6.4 WordPress Core is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.8.2 due to insuffici… wordfence
c3ec4978-0d51-4ca1-b0cf-81aaa4d43f7b
< 3.5.2
MEDIUM 6.4 The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable… wordfence
c3e47d14-4c00-4b10-9e4d-7f1d7946a2b4
< 1.3.95
MEDIUM 6.4 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versio… wordfence
c3d62ac3-7980-4817-ab22-e5d0a6a10d84 MEDIUM 6.4 The Hide It plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hideit' shortcode in all… wordfence
c3d40868-267f-4875-81ea-09e18010670a
< 1.5.1
MEDIUM 6.4 The Esteem theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.0 due … wordfence
c3d2c9a4-32f7-484f-86ce-a33ef1174b28
< 2.88.5
MEDIUM 6.4 The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mappress' shortco… wordfence
c3d0f9e9-29f5-4d74-814b-bad0fc535e1c
< 2.8.8
MEDIUM 6.4 The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.7… wordfence
← Prev 542 543 544 545 546 547 548 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top