🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 549 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c146f89c-5df3-4aaf-b880-0ce6016dfb6d
< 2.2.4
MEDIUM 6.4 The Team Members – A WordPress Team Plugin with Gallery, Grid, Carousel, Slider, Table, List, and More plugin for Word… wordfence
c141af66-ebf6-4a80-8dfd-47a586342676
< 2.9.0
MEDIUM 6.4 The Auto Bulb Finder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'a… wordfence
c1403f01-6f09-4577-b906-058437b249f5 MEDIUM 6.4 The Breaking News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
c13549f8-67b7-47ef-bdf7-fcbe5e966341
< 11.9.18
MEDIUM 6.4 The PowerPress Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Podcast URLs in versions… wordfence
c12f7927-e5c3-4186-ba65-3cd4ac22c976
< 51.1.63
MEDIUM 6.4 The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
c11be4ba-1bed-4234-b475-468394b7be90
< 1.8.5.4
MEDIUM 6.4 The File Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘file_gallery_shortcode’… wordfence
c11a5f07-de89-47ec-a92e-2adc75965648 MEDIUM 6.4 The WP Popup Magic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the [wp… wordfence
c115da4f-02f1-40b6-ba47-337b279de3e0
< 1.5.17
MEDIUM 6.4 The Mortgage Calculator / Loan Calculator WordPress plugin before 1.5.17 does not escape the some of the attributes of i… wordfence
c10c447a-6743-4b84-933d-2ea1d76c7e01 MEDIUM 6.4 The Graceful Email Obfuscation plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
c10993bd-b4f3-44b6-bb0f-cb783dbcf314
< 1.1.6
MEDIUM 6.4 The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin… wordfence
c1089958-a481-47b1-9dc6-799a1a7930c8 MEDIUM 6.4 The Beauty theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tpl_featured_cat_id’ parameter … wordfence
c101b69d-02c2-4075-8de7-0988ba3c74cc
< 2.5.4
MEDIUM 6.4 The WooLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in version… wordfence
c1005616-f3b5-45fa-97f8-784429a4a168
< 4.6.1
MEDIUM 6.4 The Tournamatch plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, … wordfence
c0f899c6-cce2-4534-9b97-3783648cba09
< 1.8.6
MEDIUM 6.4 The WordPress Password Protect Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's s… wordfence
c0eef272-4e17-4bc9-aa9f-90da55795aea
< 2.1.1
MEDIUM 6.4 The Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution plugin for WordPre… wordfence
c0e7bcae-fcb9-4802-b5f5-9c07a2038baa MEDIUM 6.4 The Any News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'any-ticker' shor… wordfence
c0e58807-bccc-469f-82c3-a4bbf088a626
< 20.2.1
MEDIUM 6.4 The Yoast SEO plugin for WordPress is vulnerable to DOM-based Cross-Site Scripting via individual post SEO details in ve… wordfence
c0e2ff94-e95a-485f-a736-0cd2b45e4069
< 2.6.1
MEDIUM 6.4 The WP AdCenter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.… wordfence
c0dd70b9-6f8a-41fc-ab4f-f6cdfee8dfb8
< 2.1
MEDIUM 6.4 The Carousel, Recent Post Slider and Banner Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
c0d79ae1-e9e4-4798-aa29-519b80759be6
< 1.1.1.12
MEDIUM 6.4 The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
c0d5f034-fd8b-456a-b44a-7d82db3a16a0
< 1.7.9
MEDIUM 6.4 The Page scroll to id plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in… wordfence
c0d0c903-da4b-4be3-ac2c-35a57615ef0b MEDIUM 6.4 The AA Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
c0d06c02-fad7-4d2f-a230-03723ba828b3
< 1.0.54
MEDIUM 6.4 The aThemes Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all … wordfence
c0c78156-627c-422f-acc4-e5a707ee3946 MEDIUM 6.4 The HMH Footer Builder For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
c0bdc5d7-b8ca-4765-91bd-dd3fa475c6d9
< 1.8.8
MEDIUM 6.4 The WP Delicious plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8… wordfence
← Prev 546 547 548 549 550 551 552 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top