πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 546 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c3b1ff70-7e37-4f74-bd72-ecda81d13d83
< 3.3.6
MEDIUM 6.4 The Gutentor - Gutenberg Blocks - Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-S… wordfence
c394c9bc-21f6-45ea-8eda-8ee22a9b87ba
< 2.1.1
MEDIUM 6.4 The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cro… wordfence
c3915c2f-400d-433d-bbc8-4d88258123dc
< 2.0.1
MEDIUM 6.4 The WooCommerce Pre-Orders plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
c38ee04a-52db-478b-8e4d-790e7beadd28 MEDIUM 6.4 The Kona Gallery Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
c3851607-73e7-44ae-8d5b-e8b7460851ea
< 6.9.10
MEDIUM 6.4 The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' … wordfence
c36bc98b-2e31-4a6b-a529-6d7849db4b3e
< 2.0.23
MEDIUM 6.4 The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
c366e14c-fa0e-4099-99d7-00f75874e1a2 MEDIUM 6.4 The WM Zoom plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 due … wordfence
c35652d0-c527-4b5c-bccb-daa6fb970434 MEDIUM 6.4 The Simple Social Share Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
c33f8b0d-97d9-4d00-bd31-444ee2afbfe6 MEDIUM 6.4 The Tempera theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.2 due… wordfence
c33d972f-921b-4b93-a20d-f3f7f6cbd3d4
< 1.4.0
MEDIUM 6.4 The Attesa Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versi… wordfence
c33b51bb-d368-4056-97f2-03543c4e9f8c
< 1.3.3
MEDIUM 6.4 The WordPress Meta Data and Taxonomies Filter (MDTF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting i… wordfence
c32a71d6-d61c-4f6f-9d35-70140235af7c
< 1.1.2
MEDIUM 6.4 The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_simple_folio_item_client_na… wordfence
c329767e-7699-4860-9782-4a27ec1d3596 MEDIUM 6.4 The Video Expander plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
c31c0a10-0617-4bf7-a098-45df2d460a61 MEDIUM 6.4 The Add Featured Image Custom Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
c3189e11-94f3-4af6-8ea5-92325d33d6a3 MEDIUM 6.4 The Translate This gTranslate Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
c31732fa-eb35-4932-bee6-08955a14b010
< 3.4.1.1
MEDIUM 6.4 The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'watu-basic-chart' shor… wordfence
c3122ac8-5f53-4e78-8d59-c9f9a78c12a2
< 1.4.18
MEDIUM 6.4 The Xpro Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
c3122921-6bea-49e7-b1d7-77a291928497
< 2.3.0
MEDIUM 6.4 The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typewr… wordfence
c30b3958-8a61-4460-a072-eac1010c07b3 MEDIUM 6.4 The Wibar | Wine and Vineyard WooCommerce WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
c300c485-e5ab-48b3-99e8-0def5668ef4a
< 3.4.3
MEDIUM 6.4 The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-… wordfence
c2fe3724-f71c-4548-9410-838c0337f887
< 1.9.2
MEDIUM 6.4 Cross-site scripting (XSS) vulnerability in the BuddyPress plugin before 1.9.2 for WordPress allows remote authenticated… wordfence
c2fd9be1-5918-4f6e-9cc5-ce4bfdd1286a
< 1.3.0
MEDIUM 6.4 The WPMozo Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
c2f10cc4-82a8-4668-b1e5-a08a0f79b59c
< 1.6.0
MEDIUM 6.4 The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before… wordfence
c2e64541-019a-4de8-aaaa-d4055be659c7 MEDIUM 6.4 The Video.js HLS Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
c2e552b8-84ad-436d-b029-f7dd4534f7d5
< 1.0.33
MEDIUM 6.4 The Checkout for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'checkout_for… wordfence
← Prev 543 544 545 546 547 548 549 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top