πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 548 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c205041a-01c9-44cd-8270-dafae2a78cbf
< 1.6.0
MEDIUM 6.4 The Post Carousel Slider for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
c1fda48e-cd19-469e-8a73-fd933752d03c
< 2.3
MEDIUM 6.4 The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' … wordfence
c1faea72-1863-4055-897c-352c8174a715 MEDIUM 6.4 The Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… wordfence
c1f71ffb-f09c-40f6-b65e-af30ce155466 MEDIUM 6.4 The CSS3 Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode i… wordfence
c1f56477-a397-4c91-95a8-e0bd9ffc4961
< 1.5.1
MEDIUM 6.4 The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
c1f55b51-cc93-4f45-9666-03740e147277
< 1.1.2
MEDIUM 6.4 The ConvertCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and '… wordfence
c1f10e67-d301-46ba-b92e-432819cb9606
< 9.86.0.0
MEDIUM 6.4 The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shor… wordfence
c1e648f7-c2ea-40b2-9ff8-7402c13f3703 MEDIUM 6.4 The Structured Content (JSON-LD) #wpsc plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
c1cae64e-caed-43c0-9a75-9aa4234946a0
< 1.0.92.1
MEDIUM 6.4 The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl… wordfence
c1c89ce7-82d8-42e9-9608-cc77cb9c41d6
< 1.27.6
MEDIUM 6.4 The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Stored Cross… wordfence
c1ba314e-0c7a-408a-9565-89989b22de44
< 3.1.43
MEDIUM 6.4 The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
c1ae1535-e5fb-4d1d-9349-59f4adaca328
< 1.6.0
MEDIUM 6.4 The Responsive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
c1a8a9dd-21f0-4bec-93ba-53ab8ef6d1ab
< 1.0.2
MEDIUM 6.4 The Sticky Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
c192425a-1e2d-4f7d-bd88-3a594d70a461
< 3.5.1.11
MEDIUM 6.4 The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3… wordfence
c1871009-8bf1-47a6-9fef-9ab2798b057c
< 4.9.10
MEDIUM 6.4 The Easy Accept Payments for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's s… wordfence
c17c344b-c891-4086-98c8-cea5673173d7 MEDIUM 6.4 The More Featured Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mfi_image' parameter… wordfence
c179cb56-6d18-4e04-8539-3834a286e302 MEDIUM 6.4 The Devnex Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
c1710f84-e3c1-4fbc-841e-c7c9ccf3a2e5
< 3.6.0
MEDIUM 6.4 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
c170ab8e-e578-49af-80c3-82ff21057262 MEDIUM 6.4 The JS Job Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
c16cd71e-a09e-4d34-99be-b632a3e64253 MEDIUM 6.4 The WP Calendar plugin for WordPress is vulnerable to Cross-Site Scripting via an unknown parameter in versions up to, a… wordfence
c16230cb-e53f-4e2a-a555-1dfdda825c45 MEDIUM 6.4 The Category Featured Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
c15f171f-e9e0-42dc-9701-e14e6c42af78
< 1.2.11
MEDIUM 6.4 The Astra Bulk Edit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
c14e6411-20de-4cfe-96b5-20e71718610e
< 1.5.1
MEDIUM 6.4 The RomethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
c14b1d49-efea-4c09-9448-533223c6d2e8
< 4.2
MEDIUM 6.4 The Export All URLs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
c14783d3-68de-49c6-9c54-eb7fc4a7bf94
< 5.6
MEDIUM 6.4 The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cro… wordfence
← Prev 545 546 547 548 549 550 551 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top