🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 822 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c80fdf06-48ce-4778-9123-9c531538195d MEDIUM 6.1 The Ps Ads Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including… wordfence
c80e2a84-fa77-49a8-b197-c258aba58537
< 2.29.1
MEDIUM 6.1 The Image Source Control plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
c80d994e-997f-457b-b6f9-3589815dc86e
< 4.3.3
MEDIUM 6.1 The wp-database-backup plugin before 4.3.3 for WordPress has XSS. wordfence
c80b1d1b-9650-4481-a9aa-09269cbbabde MEDIUM 6.1 The Category of Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
c801dfe6-a39f-4212-9cd7-71ef921c43ef
< 1.9.2
MEDIUM 6.1 The Content Audit plugin for WordPress is vulnerable to Cross-Site Request Forgery via the content_audit_save_bulk_edit … wordfence
c7fef895-95d3-4106-94f1-52f8044c3b62 MEDIUM 6.1 The fgallery_plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘album’ parameter in … wordfence
c7d688af-649c-4858-9c63-b12933d78bc2 MEDIUM 6.1 The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to Reflected … wordfence
c7d667af-d15f-4fe0-91af-36a3ed314760 MEDIUM 6.1 Reflected XSS in wordpress plugin photoxhibit v2.1.8 via 'gid' parameter wordfence
c7c36911-4afe-4ac7-9a76-7365bb86f81c
< 4.0.6
MEDIUM 6.1 The Advanced Contact Us Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
c7bfc7bf-19bb-43aa-95fc-7f4558699f41
< 0.6.1
MEDIUM 6.1 The WP Print Friendly plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘add_query_arg’ f… wordfence
c7bf3d06-2378-4c2c-9d7e-c1de703043a8 MEDIUM 6.1 The Lockets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 0… wordfence
c7ba4218-5b60-4e72-b98d-7c95c9fc3d59
< 4.4.2
MEDIUM 6.1 The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to St… wordfence
c7b5e028-d4ea-4f6d-aee1-0e9661853d43 MEDIUM 6.1 The Event Espresso – Custom Email Template Shortcode plugin for WordPress is vulnerable to Reflected Cross-Site Script… wordfence
c7adf1fc-5123-49f8-92e5-b187b74f0e35
< 1.2.6
MEDIUM 6.1 The Easy Voice Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in… wordfence
c7a92dc0-f3bd-4133-b7c1-137eb7799d7f MEDIUM 6.1 The Mitm Bug Tracker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
c79d781e-4c11-43e9-8c5f-aa89e8fbf635
< 1.5.52
MEDIUM 6.1 The Query Wrangler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in … wordfence
c79a9fad-3f4a-47f5-b911-c9f22a08f0aa MEDIUM 6.1 The "Visit Site" Link enhanced – WordPress PlugIn plugin for WordPress is vulnerable to Cross-Site Request Forgery in … wordfence
c799a373-3c0e-4b77-9e51-0e6bd2ab4b7f
< 4.0
MEDIUM 6.1 The Car Repair Services & Auto Mechanic WordPress theme before 4.0 did not properly sanitise its serviceestimatekey sear… wordfence
c793d7ad-987f-4b44-92aa-d0fdd66aa537
< 4.3.7
MEDIUM 6.1 The Members List Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in versio… wordfence
c793bf75-5e44-4511-9005-4175f349cef4
< 1.3.3
MEDIUM 6.1 ajax.functions.php in the MailUp plugin before 1.3.3 for WordPress does not properly restrict access to unspecified Ajax… wordfence
c78a0325-5bbf-4550-8477-94247f085e40
< 1.3.9.3
MEDIUM 6.1 The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited upload of files … wordfence
c77f6fff-8456-4979-90c3-52078ee12264 MEDIUM 6.1 Multiple cross-site request forgery (CSRF) vulnerabilities in the Acobot Live Chat & Contact Form plugin 2.0 for WordPre… wordfence
c774891a-c18a-4ef9-9ed0-9fcb95d371cb MEDIUM 6.1 The Simple Post Series plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
c7621d0f-3a69-4aea-a652-3143e256902e MEDIUM 6.1 The JustRows free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'slug' parameter in all v… wordfence
c748c2a3-4df1-4bcb-a6d3-9644da623f1c MEDIUM 6.1 The WP Map Route Planner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
← Prev 819 820 821 822 823 824 825 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top