🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 824 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c60979fc-d2d2-4995-87fd-077ea6569a51 MEDIUM 6.1 The WPEX Replace DB Urls plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… wordfence
c5ffe80a-edd3-4369-a5bc-ce7c9b259416 MEDIUM 6.1 The Redirect wordpress to welcome or landing page plugin for WordPress is vulnerable to Cross-Site Request Forgery in al… wordfence
c5fe6884-4a31-4341-b30f-354b447f5313 MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for Jigoshop (swipe-hq-checkout-for-ji… wordfence
c5fd2255-7f02-4de8-b904-a753580123b9 MEDIUM 6.1 The FastBook – Responsive Appointment Booking and Scheduling System plugin for WordPress is vulnerable to Cross-Site R… wordfence
c5fa2f02-4a81-4d49-b473-7447cd371244 MEDIUM 6.1 Reflected XSS in wordpress plugin recipes-writer v1.0.4 wordfence
c5ed7387-34e2-4cf0-926b-e5c2ef4222cd MEDIUM 6.1 The Amber plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.4… wordfence
c5e66244-2b86-491b-9eca-19e42e7f2da8
< 1.4.6.1
MEDIUM 6.1 The Category Order and Taxonomy Terms Order plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to… wordfence
c5e011d3-bd0f-46cb-9fb1-af06bcb7e307
< 2.0.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in advancedtext.php in Advanced Text Widget plugin before 2.0.2 for WordPress a… wordfence
c5d8a452-1f80-4bd8-bf63-086139a67189 MEDIUM 6.1 The Stop Registration Spam plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and i… wordfence
c5d17538-30ff-423c-bd61-d85a3f5aba74
< 2.13.5
MEDIUM 6.1 The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST paramete… wordfence
c5c96063-a6ac-4325-9f44-a6f8344e00ef MEDIUM 6.1 The Woocommerce Social Media Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… wordfence
c5bf1c8c-97b0-412c-aa26-88fd7bbe7c8c
< 2.5.0
MEDIUM 6.1 The Soundslides plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2… wordfence
c5b9e53e-d2d3-40a0-adba-f489343c6ee6
< 2.8.10
MEDIUM 6.1 The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'X-Forwarded-For' head… wordfence
c5ab6a1f-181c-4bc2-bcc3-e19f94fc5e46
< 4.0.3
MEDIUM 6.1 The Google Photos Gallery with Shortcodes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all ve… wordfence
c5ab685c-1e58-43f3-a984-52afcfaa5aca
< 4.8.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in photocrati-gallery/ecomm-sizes.php in the Photocrati theme for WordPress all… wordfence
c5aa0006-435d-4874-8d71-659d5d72e702
< 1.4.29
MEDIUM 6.1 The 10Web Social Photo Feed WordPress plugin before 1.4.29 was affected by a reflected Cross-Site Scripting (XSS) vulner… wordfence
c5a26a49-f113-4aca-acc0-4b0c9955e13c
< 3.15.0.6
MEDIUM 6.1 The FunnelKit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.1… wordfence
c5a263d5-df39-412e-b40a-e06e23168b7e
< 4.2.0
MEDIUM 6.1 The WC Marketplace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including… wordfence
c5820352-a271-43c6-950d-815402241362
< 6.0.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the Blubrry PowerPress Podcasting plugin before 6.0.1 for WordPress allows r… wordfence
c565f455-6c83-42af-9f79-dcf4d03320a8 MEDIUM 6.1 The Affiliate Disclosure Statement plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
c55e1d38-081c-4ef6-aad7-04ef52c6bee0
< 2.5.3
MEDIUM 6.1 The Commentator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘provider’ parameter in… wordfence
c55487f9-dc8a-41a0-b052-625665c1543f
< 1.1.0
MEDIUM 6.1 Easy US Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_… wordfence
c5372890-72d4-482d-a7f2-04a50520c4dc
< 1.6.5
MEDIUM 6.1 The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the … wordfence
c509345b-441f-474d-ad3a-720801859f86
< 1.7.2
MEDIUM 6.1 The FAQ Builder AYS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ays_faq_tab' parameter… wordfence
c508d38c-f5e3-4193-8209-0083a8a18da4
< 1.4.7
MEDIUM 6.1 The Helloprint plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'success' parameter in versi… wordfence
← Prev 821 822 823 824 825 826 827 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top