πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 823 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c7429367-f9f4-4859-9537-0f543e32870a
< 4.0.5
MEDIUM 6.1 The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to Reflected Cros… wordfence
c73e6889-78f1-4118-ba76-4cd696d24800 MEDIUM 6.1 The Backup by 10Web – Backup and Restore Plugin WordPress plugin through 1.0.20 does not sanitise or escape the tab pa… wordfence
c738e051-ad1c-4115-94d3-127dd5dff935 MEDIUM 6.1 The Your Journey theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions… wordfence
c7370cbc-f681-49d7-9330-762443202529
< 1.1.53
MEDIUM 6.1 The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' par… wordfence
c72daa83-afda-4999-b856-aba4d4118228 MEDIUM 6.1 The Kikx Simple Post Author Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up t… wordfence
c726d6a4-5178-428e-8915-3f8408900e2f MEDIUM 6.1 The Wp EMember plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 10… wordfence
c7164c43-9a16-4021-a365-b1908a17140e MEDIUM 6.1 The Advanced Options Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, … wordfence
c7088e84-a138-452b-bc4d-8ca9427ca8ae
< 0.6
MEDIUM 6.1 The embed-comment-images plugin before 0.6 for WordPress has XSS. wordfence
c7035903-d598-4db3-ba77-6e836229c5de
< 1.9.3
MEDIUM 6.1 The Simple User Listing plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜as’ parameter … wordfence
c6fd7da8-d203-4076-8c7d-b8532d9d0bed
< 2.1.3
MEDIUM 6.1 The ELEX WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
c6f7da0b-cc2c-43e5-8ae9-ef7d6d6f0ae9
< 2.5.1.9
MEDIUM 6.1 There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re… wordfence
c6c370f5-087b-4e75-a726-b79bf792441b
< 4.4.12
MEDIUM 6.1 The Simple File List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' and 'subtab' par… wordfence
c6bc8753-9b63-41ee-8269-89883969983b
< 1.4
MEDIUM 6.1 The visualslider Sldier plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … wordfence
c6b95cc2-c40b-40db-abd2-d66978cf55d1
< 1.5.6
MEDIUM 6.1 The Salem Theme plugin for WordPress is vulnerable to DOM-based Cross-Site Scripting in versions up to, and including, 1… wordfence
c6b43a4f-ef44-46cf-89ce-5747ac5f47cd MEDIUM 6.1 The PayPal Responder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
c6b3e014-fb08-41e9-a667-b70f96602134
< 3.2
MEDIUM 6.1 Multiple cross-site scripting (XSS) vulnerabilities in userperspan.php in the Count Per Day module before 3.2 for WordPr… wordfence
c6996e6b-e421-438a-ad21-f7ddbd29742f MEDIUM 6.1 The WP-Click-Tracker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
c67b310c-4a27-427d-9f99-fab56f3f6580 MEDIUM 6.1 The Add Categories Post Footer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
c66f1633-5563-4deb-b315-79b4b9e17a95
< 1.3.5
MEDIUM 6.1 The WPZOOM Addons for Elementor – Starter Templates & Widgets plugin for WordPress is vulnerable to Reflected Cross-Si… wordfence
c664b4e5-8f9f-4cbd-86a6-74901fa47223 MEDIUM 6.1 The Test Email plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
c65b48a4-5278-4648-9785-091d1acfaab3 MEDIUM 6.1 The Handmade Framework plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
c64e1b35-46f4-4d90-a4c9-79bf512471de MEDIUM 6.1 The Ultimate Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and incl… wordfence
c63d5ccb-8798-4894-8bac-83bebe353cd0 MEDIUM 6.1 The Don't Break The Code plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
c62e8fc2-fad5-4fcc-b0e8-e434b21b65d1
< 2.12.16
MEDIUM 6.1 The Fast eBay Listings plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.12.15… wordfence
c621e57e-8483-4dde-9c83-cc4522f92c1c MEDIUM 6.1 The Simple Quotation WordPress plugin through 1.3.2 does not have CSRF check when creating or editing a quote and does n… wordfence
← Prev 820 821 822 823 824 825 826 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top