πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 825 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c4ece408-a370-4848-9705-3f8d3de8ca03
< 2.2.2
MEDIUM 6.1 The Gyan Elements plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
c4debc89-d5ea-4cf1-8e69-197a75794d0b
< 2.28.1
MEDIUM 6.1 The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Reflected Cross-… wordfence
c4d86204-51df-4adf-aac4-f5e007d9f3c3
< 6.0.0
MEDIUM 6.1 The Booster plugins (Booster, Booster Plus, and Booster Elite) for WordPress are vulnerable to Reflected Cross-Site Scri… wordfence
c4d19f85-e39f-46e6-b62c-b6d3dc51a0df
< 3.4.7
MEDIUM 6.1 The wp-all-import plugin before 3.4.7 for WordPress has XSS. wordfence
c4c438e0-ea25-4372-8e4e-5d7163cc3447
< 29.8
MEDIUM 6.1 The WooCommerce Customers Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions u… wordfence
c4aceec4-4832-4d83-98b3-f705c391b0c9
< 3.2.9
MEDIUM 6.1 The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter. wordfence
c4a649b0-d5b2-4e4c-833c-01ecf12611a5
< 1.1.8
MEDIUM 6.1 The Integration for Contact Form 7 and Zoho CRM, Bigin plugin for WordPress is vulnerable to Reflected Cross-Site Script… wordfence
c49f27d8-2c4d-4cbf-945c-f12878f4c17f MEDIUM 6.1 The HTML5 Video Player plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inclu… wordfence
c49dcb39-7d03-4d7e-9a07-7ac8a6506e7f
< 1.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in ThemeBeans Blooog theme 1.1 for WordPress allows remote attackers to inject … wordfence
c49c97cf-78e9-4da2-ab0d-ff014c29feaa
< 2.31.5
MEDIUM 6.1 The Strong Testimonials plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜id’ parameter … wordfence
c4979e2f-225a-4f76-a324-dae5c84883f7
< 5.4.9
MEDIUM 6.1 The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up… wordfence
c496a5f8-9cfc-49b3-b360-d942d554b860
< 3.63
MEDIUM 6.1 The 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin plugin for WordPress is vulnerable to Re… wordfence
c4747f6c-d083-4f7e-a9ef-3dd9c8f6047b
< 2.5.4
MEDIUM 6.1 XSS exists in admin/gb-dashboard-widget.php in the Gwolle Guestbook (gwolle-gb) plugin before 2.5.4 for WordPress via th… wordfence
c46cf202-320b-40a0-9de0-e4992f23395f
< 1.0.5
MEDIUM 6.1 The wp-piwik plugin before 1.0.5 for WordPress has XSS. wordfence
c46b26c7-3302-4730-915c-1882b315600c
< 2.7
MEDIUM 6.1 The Wise Chat plugin for WordPress is vulnerable to Reverse Tabnabbing in versions up to, and including, 2.6.3. This is … wordfence
c467a634-d5cf-4e80-9a64-009cdad2a684
< 5.3.02
MEDIUM 6.1 The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th… wordfence
c4665b87-e1f8-4a73-b6d6-1d5c14067b3a
< 7.2.4
MEDIUM 6.1 The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_q… wordfence
c463ad1f-5522-41f2-8749-e19fcba46409 MEDIUM 6.1 The Appointment Buddy Widget By Accrete plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all vers… wordfence
c4580748-f5dc-4f05-81d2-a8e9b76a7a7d MEDIUM 6.1 The Fotobook WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping and the use o… wordfence
c42b646f-7a41-416b-8632-d088b8d0cb7c
< 1.0.5
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in index.php in the PhotoSmash plugin before 1.0.5 for WordPress allows remote … wordfence
c4048480-25a8-449f-8edb-a2a8854425ff
< 4.7.2
MEDIUM 6.1 The Gwolle Guestbook plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
c3efb7b1-5230-40f9-a8a0-3712916284be
< 4.6.0
MEDIUM 6.1 The YITH WooCommerce Product Add-Ons plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and i… wordfence
c3ea04ba-b609-49cd-aae8-68f5b51df154
< 1.9.2
MEDIUM 6.1 The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripti… wordfence
c3d7728f-7c25-4505-8db3-b67a5c17a439
< 1.6.4
MEDIUM 6.1 The Post Connector plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.0.3 du… wordfence
c3d356d1-2f6d-42e0-b774-6384872c0a90
< 1.0.43
MEDIUM 6.1 The music-store plugin before 1.0.43 for WordPress has XSS via the wp-admin/admin.php?page=music-store-menu-reports from… wordfence
← Prev 822 823 824 825 826 827 828 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top