πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 826 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c3ce0b74-cc65-4ea9-9fcc-d7bcd00bb67f
< 2.7.0
MEDIUM 6.1 The PeproDev WooCommerce Receipt Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versio… wordfence
c3b0c2c0-4eaf-4158-94e1-0cfb60310a1d MEDIUM 6.1 The Buooy Sticky Header plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… wordfence
c3799c76-2b25-4346-948e-14445d93b7f1 MEDIUM 6.1 The Zarinpal Paid Download plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… wordfence
c36b0d08-7289-4410-adfb-99dbe1ac4c03
< 2.0.59
MEDIUM 6.1 The OTP-less one tap Sign in plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… wordfence
c36181aa-39c2-4009-b687-5964a6cc45c8
< 1.8
MEDIUM 6.1 The Awin Data Feed WordPress plugin through 1.7 does not sanitise and escape a parameter before outputting it back via a… wordfence
c3613f95-8338-40b8-8b16-2714fa3474ce
< 4.0.50
MEDIUM 6.1 The Limit Login Attempts WordPress plugin before 4.0.50 does not escape the IP addresses (which can be controlled by att… wordfence
c3489038-2833-4080-b802-5733afab5de8
< 5.48.0
MEDIUM 6.1 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' pa… wordfence
c343cee6-909d-4c1a-a6e4-f916a2ae223e
< 4.2.4
MEDIUM 6.1 The YML for Yandex Market plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the feed_id paramete… wordfence
c340b7c0-35ab-4707-a999-261a721a9a37
< 2.1.20
MEDIUM 6.1 The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did no… wordfence
c322841a-4134-4c21-8028-0ccacd46335b
< 1.9.9.41
MEDIUM 6.1 The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'sub… wordfence
c31e9400-ee59-4c7e-a52f-e0774c0d9af8 MEDIUM 6.1 The URL-Preview-Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
c319dd9f-d07d-42ea-bce8-1a99435347c5
< 1.3.59
MEDIUM 6.1 The LabelGrid Tools plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… wordfence
c30d517b-e051-408c-a022-4399c3d62390
< 6.8.8
MEDIUM 6.1 The Easy Forms for MailChimp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the in versions up… wordfence
c30aeafe-725b-47be-b49d-00f58b474c3a
< 3.3.2
MEDIUM 6.1 The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… wordfence
c2fde092-0a12-42ab-abbb-7f5ff5de9af2
< 1.5.11
MEDIUM 6.1 The ShopSite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.… wordfence
c2f4461b-1373-4d09-8430-14d1961e1644
< 0.9.4
MEDIUM 6.1 The Microsoft Clarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
c2e6a555-6f7e-48bd-8e8d-dfdcbd5f1e77
< 8.5.5
MEDIUM 6.1 The WP eStore plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Discount Editing in all versions … wordfence
c2c74678-ff9e-4b67-9061-505dbebcf9aa MEDIUM 6.1 The SpotBot plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 0… wordfence
c2c11644-b9b5-40c7-b558-995b621fc5d6 MEDIUM 6.1 The MinhNhut Link Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter o… wordfence
c2bc94a7-5a03-48be-be77-b05681033ba3
< 1.4.7
MEDIUM 6.1 The Snow Storm plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… wordfence
c2b7802a-3cbe-4488-93d2-5f8a34faf8ae
< 1.2.2
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in sabre_class_admin.php in the SABRE plugin before 2.1 for WordPress allows re… wordfence
c2b3113e-7a47-4a32-aafd-bc806f99f8b6 MEDIUM 6.1 The WP Keyword Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
c2a761ce-5a0c-4ba6-91f7-82ef7935f734
< 1.0.15
MEDIUM 6.1 The AWcode Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… wordfence
c2a57428-3473-4f24-ae30-5f6cada7481c
< 2.8.1
MEDIUM 6.1 The HandL UTM Grabber / Tracker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … wordfence
c2a515d9-dc4c-4755-b602-a9eb22f8e814
< 2.7.5
MEDIUM 6.1 The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputtin… wordfence
← Prev 823 824 825 826 827 828 829 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top