πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 819 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cb112c12-2587-46de-a688-d0f04e1ec431
< 2.8.1
MEDIUM 6.1 The WP Google Analytics Events – No-Code Custom Event Tracking for Google Analytics plugin for WordPress is vulnerable… wordfence
cb072bfa-991a-4839-996d-fdc803427076
< 2.8.1
MEDIUM 6.1 Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to redirect us… wordfence
cb028377-d62d-4172-9253-6870c985736f MEDIUM 6.1 The OWL Carousel Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … wordfence
cae72c7e-9bc8-40a7-b125-c9e8c86b14bf
< 1.1.3
MEDIUM 6.1 The Advance Search WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the wpas_id parameter found in t… wordfence
cae45f7d-0ffe-41c4-9d1c-3211d6f86e5c
< 0.5.4
MEDIUM 6.1 The Stop Comment Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
cae1f5c7-ae91-4f45-8b4f-b2be89d36437
< 0.6
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Video Lead Form plugin for WordPress allows remote attackers to inject a… wordfence
cae1e984-95b2-4b76-b6b3-563dc3104a72
< 1.3.5
MEDIUM 6.1 The Woo Custom Checkout Field plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versi… wordfence
cad7731a-1f81-4055-9b49-15b35edd3fcf
< 1.2.0
MEDIUM 6.1 The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to limited file uploads due to a misconfig… wordfence
cad5274f-0d73-425d-bdfb-478c77d55d6c
< 2.9.97
MEDIUM 6.1 The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includi… wordfence
cad4300f-02f9-4c9f-9bb3-1c9da8b78ac9
< 2.0.11
MEDIUM 6.1 The WP Simple Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad… wordfence
cace29fd-95d0-48ea-8dfa-6fd12dd9ccbf
< 3.2.44
MEDIUM 6.1 The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attr… wordfence
cac4482e-bdf8-434a-ad22-ca2eeec15906
< 3.6.5
MEDIUM 6.1 The NiceJob plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.4… wordfence
cabf7aae-0673-4358-a2df-0ca22c8432b5
< 3.1.25
MEDIUM 6.1 The Ditty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via unescaped URLs in versions up to, and… wordfence
caae093e-58e8-48b1-8665-2a5f49e98c58
< 1.1.6
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in admin/OptionsPostsList.php in the TheCartPress plugin for WordPress before 1… wordfence
caa23ec8-547b-425e-94bd-297d12702256
< 2.41
MEDIUM 6.1 The Ravpage plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.40 … wordfence
caa09e12-60f9-4ef4-85f7-dadb6833e077
< 4.1.12
MEDIUM 6.1 The theplus_more_post AJAX action of The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.12 did not p… wordfence
ca8c676a-144c-4809-b8f6-50cb9e1390b5
< 1.0.4
MEDIUM 6.1 The Easy Digital Downloads (EDD) Invoices extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9… wordfence
ca77c769-a5e4-406f-954b-00bd767909ec MEDIUM 6.1 The Onlywire Multi Autosubmitter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
ca62b54e-dde6-440f-bed9-db320179269e
< 5.1.7
MEDIUM 6.1 The Photo Gallery by Ays plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
ca32fd93-cab3-431b-91c3-9ed244f9d1f1
< 2.3.7
MEDIUM 6.1 The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg()… wordfence
ca2d687f-0358-4642-849b-100bf40cbbf1
< 1.1.3
MEDIUM 6.1 The MediaView plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜id' parameter in all versi… wordfence
ca203777-84ea-47ab-bafc-f2cc8f778fcd
< 4.1.6.6
MEDIUM 6.1 The LearnPress – WordPress LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of … wordfence
ca11e840-04bd-4731-bfa9-3bf8ed98e155
< 2.1
MEDIUM 6.1 The Image Gallery – Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via … wordfence
ca0e51b2-640a-4bd1-b667-74107b7dcc6f
< 1.33.10
MEDIUM 6.1 The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in al… wordfence
ca09ce0d-3989-420d-9457-f0acd709cc6b
< 2.3.8
MEDIUM 6.1 The Stagtools plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'popup' parameter in versions… wordfence
← Prev 816 817 818 819 820 821 822 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top