🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 820 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ca05783d-7516-469e-b8a0-c23035db43b7
< 1.4.16
MEDIUM 6.1 The PixTypes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4.… wordfence
ca036121-072c-4944-84e9-3b8b69f3e17c
< 1.1.0
MEDIUM 6.1 2Checkout Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). wordfence
c9e50b6a-0b64-4cc8-91a0-509fb8d0bf42
< 1.5.3
MEDIUM 6.1 The Miti theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 1.5.3 due to insufficient… wordfence
c9e3702b-8a3a-467d-aba8-2d617ee5c419
< 0.1.6
MEDIUM 6.1 The Listings for Buildium plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
c9de2fe9-c1d7-4898-806d-68628061a98d MEDIUM 6.1 The Convert Post Types plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
c9db93e9-bcd8-48d7-aa68-b92532bab1e6
< 1.6.29
MEDIUM 6.1 The Riode | Multi-Purpose WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up… wordfence
c9ce2107-18bd-4331-bd8e-578f56fdebf7
< 5.2.2
MEDIUM 6.1 The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirec… wordfence
c9c1039e-759f-420a-87a7-6a106640ff60
< 0.2.7
MEDIUM 6.1 The Unlimited Page Sidebars plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
c9a717ff-8bab-4ead-8323-35bd2fdee12d MEDIUM 6.1 The Universal Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
c9a3d3c3-278b-46c7-87d0-53528d616951
< 1.4.6
MEDIUM 6.1 The Postmatic plugin before 1.4.6 for WordPress has XSS. wordfence
c9983364-9b52-4acc-91d4-b352c6d24d52
< 1.2.17
MEDIUM 6.1 The wordpress vertical image slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘sear… wordfence
c98cd47b-075a-44c4-8755-02f474f9ca42 MEDIUM 6.1 The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.9.1… wordfence
c9799ebf-1810-4c34-8262-2559de61c1c8 MEDIUM 6.1 An issue was discovered in the Vanguard plugin 2.1 for WordPress. XSS can occur via the mails/new title field, a product… wordfence
c95e5e27-58e5-42ea-841a-f49fdedc3796
< 2.0.4
MEDIUM 6.1 The Payment Gateway for Telcell plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including… wordfence
c950ac0a-80fb-4f95-ba20-afb8ba6b137f
< 0.9
MEDIUM 6.1 The Mantenimiento web plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
c942fd74-7a2d-43ec-9806-cdfe21a83149
< 1.20
MEDIUM 6.1 The quotes-and-tips plugin before 1.20 for WordPress has XSS. wordfence
c92e166d-2ede-4280-a875-d30c0cf6f467
< 1.22
MEDIUM 6.1 The Video Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
c92e15a8-6b0c-43bf-813d-b2484cb9ef8e
< 3.2.33
MEDIUM 6.1 The Front End Users plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
c9295b82-27c1-4f35-b40c-1ac40ebe5d5e
< 2.5
MEDIUM 6.1 The Interactive World Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search (s) param… wordfence
c9291a17-7add-4cc2-ab44-9b640940c6b7 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in res/fake_twitter/frame.php in the "verwei.se - WordPress - Twitter" (verweis… wordfence
c924b317-97ec-43b8-9bf3-ed7618743de7
< 1.2.2
MEDIUM 6.1 The PKT1 Centro de envios plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'success' and 'er… wordfence
c921d8fd-07f6-4d17-89b7-0e8e3dc1e2f8 MEDIUM 6.1 The Laika Pedigree Tree plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… wordfence
c91f1e35-88ad-46e9-8d30-d4bddde92975 MEDIUM 6.1 The flexoslider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1… wordfence
c915b30b-a15d-4ac7-abb6-f6d81a6e2ee7 MEDIUM 6.1 The wpCAS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.07 du… wordfence
c90dadc9-0109-4ebd-8135-3efd26682ad9
< 1.8.0
MEDIUM 6.1 The Action Network plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all … wordfence
← Prev 817 818 819 820 821 822 823 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top