πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 821 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c904391e-efa1-4fba-b6a5-b9b38822e194 MEDIUM 6.1 The Flaming Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
c8fb459b-39c1-4bbe-b176-93b25822be2e MEDIUM 6.1 The ZooEffect plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1… wordfence
c8faa8bb-0ebe-4671-87cf-98edbebe913e MEDIUM 6.1 The 2TypoFR WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the text function found in the ~/vendor… wordfence
c8f008c6-42c6-40c3-9058-d8812ec40bef
< 9.7.5
MEDIUM 6.1 The Quick Event Manager WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to… wordfence
c8edba5b-9bce-4a93-86a6-bb6dcb30fa60
< 1.8
MEDIUM 6.1 The WP Job Manager – Company Profiles plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'co… wordfence
c8e768a4-09ac-4772-9e5d-b9f63bac208c
< 2.3.1
MEDIUM 6.1 The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-syste… wordfence
c8d87951-4c9b-45b8-be73-17c7b9bdbcd9 MEDIUM 6.1 The Style Tweaker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
c8cef103-8b8d-4e9b-9cd2-6e998dcb68dd MEDIUM 6.1 The Page Link Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
c8c8f6d4-817b-4ff7-8362-5d699237d6ce
< 1.2.71
MEDIUM 6.1 The Question Answer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
c8c89eea-f6b0-4771-ab7d-05e266324d58
< 4.3.1
MEDIUM 6.1 The SULly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.3. Th… wordfence
c8b80ad3-7a52-463b-abbd-544c4d5c6090
< 4.1
MEDIUM 6.1 The Chat2 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0. Th… wordfence
c8a8be59-d4c1-4cce-b474-8d885b4d89c6
< 2.92.4
MEDIUM 6.1 The CommentLuv plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_ajax_nonce' parameter in v… wordfence
c8a49064-ad48-410e-9b32-f94109830ccf
< 1.3.2.1
MEDIUM 6.1 The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dnf' parameter on the 'ch… wordfence
c8a2e3ea-8da8-4e86-9720-3149ddb13bbe MEDIUM 6.1 The addWeather plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.… wordfence
c89e2f15-20e9-442a-8a05-025a6f95c351 MEDIUM 6.1 The HyperComments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ… wordfence
c89d541f-d34e-46f9-a7cd-aeb00b2e8ad0
< 3.1.4
MEDIUM 6.1 A cross-site scripting (XSS) vulnerability in the AlgolPlus Advanced Order Export For WooCommerce plugin 3.1.3 for WordP… wordfence
c8958931-36be-47b7-9262-3061cff9be22 MEDIUM 6.1 The Amerisale-Re plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'edit' parameter in the 'n… wordfence
c892e5da-bab2-4689-bad0-4b4789015113
< 2.0.6
MEDIUM 6.1 Authenticated Reflected Cross-Site Scripting (XSS) vulnerability in WordPress uListing plugin (versions <= 2.0.5). Vulne… wordfence
c874c643-ceb6-4646-adfa-6cd7393bb4f5
< 12.3.17
MEDIUM 6.1 The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
c8661bd7-65b7-4277-81a0-fd410ae0ee1b
< 3.6.2
MEDIUM 6.1 The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting du… wordfence
c856e06d-34f7-42e9-a72c-3d4e9207e07e MEDIUM 6.1 The Alink Tap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3… wordfence
c8313827-f3ce-451d-869a-99684f58daff
< 2.0.2
MEDIUM 6.1 Multiple "unannounced" cross-site scripting (XSS) vulnerabilities in WordPress before 2.0.2 allow remote attackers to in… wordfence
c820ff17-718d-4e3a-9a46-7d5a4a573f78
< 2.28
MEDIUM 6.1 The Multilevel Referral Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scri… wordfence
c81f9926-736b-42f1-a0f5-f9b434ffcce1 MEDIUM 6.1 The Admin Amplify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
c81b2dca-d830-4901-8b16-5feb7cd1a4d5
< 1.4.0
MEDIUM 6.1 The Themify Post Type Builder Search Addon WordPress plugin before 1.4.0 does not properly escape the current page URL b… wordfence
← Prev 818 819 820 821 822 823 824 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top