🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 827 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c2a121db-8a04-4da2-98b8-05a5eba06e45
< 5.2.4
MEDIUM 6.1 The TravelTour theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to 5.2.4 (exclusiv… wordfence
c298c87e-cf3c-4b72-bb0e-a01ca2dfe52f
< 2.7.6
MEDIUM 6.1 The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting… wordfence
c287ed1d-83ff-4ee7-bebc-e57850d081a0 MEDIUM 6.1 The Quick Code plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… wordfence
c27f2d6c-826b-4b17-b432-cd142f96ce7a MEDIUM 6.1 The mybb Last Topics plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
c27bbfeb-bdc2-4348-848a-4051b9af2959 MEDIUM 6.1 The WP Hide Categories plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and i… wordfence
c27b390f-282b-4a18-98c3-3442554d63e1
< 7.7.4
MEDIUM 6.1 The Photography theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.… wordfence
c26c5e45-d3e9-4fa1-9aed-323b100c9bee
< 5.8.0
MEDIUM 6.1 The Revi.io plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.7.3… wordfence
c2385865-ff03-4daf-bf81-3ec3ea11c91f
< 3.7.10
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the legacy theme preview implementation in wp-includes/theme.php in WordPres… wordfence
c232344c-5070-4461-b143-0f53d61d6eac MEDIUM 6.1 The real3d-flipbook-lite plugin 1.0 for WordPress has XSS via the wp-content/plugins/real3d-flipbook/includes/flipbooks.… wordfence
c21b5436-4421-4a09-952c-3dc0d9adb356 MEDIUM 6.1 The rng-refresh plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includin… wordfence
c2020323-b08d-4a5c-818f-1c440e057e75
< 2.76
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress al… wordfence
c2005b0a-4305-4eb0-ad4d-432c7c3ce3f6
< 1.6.1
MEDIUM 6.1 The Motta Addons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 1.6.1 due to ins… wordfence
c1f94034-ea8e-461e-8be1-c429283a6dbc MEDIUM 6.1 The Go To Top plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0… wordfence
c1eaa4b8-7bed-435f-b408-f74572147c09 MEDIUM 6.1 The ClickBank Storefront WordPress Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all ve… wordfence
c1c7f1dc-d2c3-43d1-ba76-a2763dfac9d0 MEDIUM 6.1 The CAMOO SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
c1b513dc-ead4-46ec-a06e-4e856134a170
< 1.1.8
MEDIUM 6.1 The WIP WooCarousel Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
c1b0ac88-8afd-4e46-9721-7aab91090e37
< 3.5.1
MEDIUM 6.1 The PublishPress: Editorial Calendar, Workflow, Comments, Notifications and Statuses plugin for WordPress is vulnerable … wordfence
c1acc256-c8f5-4738-8788-d52b4e2b80ef
< 7.5.0
MEDIUM 6.1 When subscribing using AcyMailing versions before 7.5.0, the 'redirect' parameter isn't properly sanitized. Turning the … wordfence
c1a5f593-92b5-41f0-9ad9-1f9e8c4f5e41 MEDIUM 6.1 The ID Arrays plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.1… wordfence
c1a0d54f-08f7-4ec5-8cfe-6c4a6eb26748
< 4.26.2
MEDIUM 6.1 The Ajax Search Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via some of its parameters in v… wordfence
c195d62d-5f2f-4248-9a84-b551f532256b
< 1.11
MEDIUM 6.1 The manual-image-crop plugin before 1.11 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?actio… wordfence
c191c57b-895c-4ae9-9eed-0125f34d438c
< 0.9.33
MEDIUM 6.1 The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
c14f473f-ca49-4610-b5df-9eb0e064ece5
< 2.3.1
MEDIUM 6.1 The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-syste… wordfence
c14b948f-129d-4223-b3ee-0bef1f9fc703
< 26.8
MEDIUM 6.1 The Betheme theme for WordPress is vulnerable to Reflected Cross-Site Scripting on shop pages in versions up to, and inc… wordfence
c1441e68-5c41-4c90-ba99-1656af87a29d MEDIUM 6.1 The Honeypot for WP Comment plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ page’ par… wordfence
← Prev 824 825 826 827 828 829 830 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top