πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 547 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c2ddd9a2-79d7-4f9c-9832-25c3363d3ce9
< 1.8.0
MEDIUM 6.4 The Product Catalog Simple plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's show_produ… wordfence
c2d03b83-c406-4d3f-b6be-015edcc15515
< 3.4.7
MEDIUM 6.4 The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is … wordfence
c2a97987-1a9f-4e9e-af5d-4db542eec5ae MEDIUM 6.4 The Xpert Tab plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3 d… wordfence
c2a91fe9-f642-4a61-a175-ed5bb537bf08
< 2.0.2
MEDIUM 6.4 The Surbma | Infusionsoft Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'infusions… wordfence
c2a2c069-5dc6-45e2-8ca1-842759d541c4
< 3.0.4
MEDIUM 6.4 The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is v… wordfence
c2995828-8a3e-400d-9e2b-aba8fd17cf00
< 3.5.3
MEDIUM 6.4 The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… wordfence
c2967eae-82bb-4556-a21a-c5bb6b905c62
< 2.2.0
MEDIUM 6.4 The POWR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'powr-powr-pack' shortcode i… wordfence
c291aa80-f1cd-4933-b522-73ec115a3a68
< 1.0.1
MEDIUM 6.4 The WP User Profile Avatar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
c28e740e-9337-41b5-a8e7-ca68e41eaed4
< 2.1.11
MEDIUM 6.4 The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocksy_newslet… wordfence
c27f566a-913e-498e-90bb-113692b74612
< 1.0.1
MEDIUM 6.4 The CodePen Embedded Pens Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
c2760f65-a981-42f6-b18c-fcf493bd34b6
< 1.1.1.8
MEDIUM 6.4 The plugin Codup Read Only Admin for WordPress is vulnerable to Cross-Site Scripting via the read_only_admin parameter i… wordfence
c26e2aea-835e-4462-b4e3-99d2caf3a014 MEDIUM 6.4 The Custom Content Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcod… wordfence
c24501be-8f40-4240-84e1-3eaaf1de3f25 MEDIUM 6.4 The Blockons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.15 … wordfence
c23bba83-35d2-4098-8104-8389bb2ff880
< 1.3.7
MEDIUM 6.4 The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
c23995c6-989e-48d2-ba60-b0bf7b750245
< 3.2.5
MEDIUM 6.4 The Blockspare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Cou… wordfence
c232ddc0-35e8-42e0-8fff-831c74457615
< 1.8
MEDIUM 6.4 The Wonder Video Embed WordPress plugin before 1.8 does not escape parameters of its wonderplugin_video shortcode, which… wordfence
c2324caa-f804-4f76-9d08-8951fbee4669
< 2.0.0
MEDIUM 6.4 The Weather Atlas Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shortcode-weather-atlas'… wordfence
c22f34f1-2df7-4ffc-b808-234ca9039404
< 1.47.0
MEDIUM 6.4 The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnera… wordfence
c22288e6-76f3-4c5a-bd7b-30681334bab7 MEDIUM 6.4 The TPG Get Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tpg_get_posts' sho… wordfence
c21c12b1-763e-4c01-bd41-5e2d0b34a50f
< 2.1.28
MEDIUM 6.4 The Glossary plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.27 … wordfence
c218bf5e-b28b-4512-8bc7-7662b4a06f1e
< 2.16.3
MEDIUM 6.4 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu… wordfence
c2165ca1-2c7d-42a4-a547-8adb30c24eab
< 1.5.4
MEDIUM 6.4 The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Si… wordfence
c20e0552-1ff6-43d9-be87-f6c482f1866e
< 1.5.87
MEDIUM 6.4 The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in v… wordfence
c20c674f-54b5-470f-b470-07a63501eb4d
< 1.4.17
MEDIUM 6.4 The Modern Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in ver… wordfence
c2075960-fde4-4ca9-a000-23fdd6d5de1c
< 1.4.3
MEDIUM 6.4 The Material Design Icons for Page Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl… wordfence
← Prev 544 545 546 547 548 549 550 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top