πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,113
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 22, 2026
Last Updated

40,113 vulnerabilities found (page 828 of 1605)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c13ba1df-25fa-4cc8-9745-2d6f6168788a MEDIUM 6.1 The Delete Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
c131c746-3029-4791-b564-f6e530e63ea9
< 3.1.3
MEDIUM 6.1 The mTouch Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜quiz’ parameter in ver… wordfence
c12e6063-2db7-4f8b-a7c3-3e40bc9ff2a4 MEDIUM 6.1 Cross-site request forgery (CSRF) vulnerability in the WP Smiley plugin 1.4.1 for WordPress allows remote attackers to h… wordfence
c127c6e3-a6ac-433e-8278-5fcc675c5dc1 MEDIUM 6.1 The Multiple Location Google Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
c11a561a-c798-46e7-bf2d-12933978aa29
< 2.25
MEDIUM 6.1 The AJAX Login and Registration modal popup + inline form plugin for WordPress is vulnerable to Reflected Cross-Site Scr… wordfence
c11456bb-dde3-4ab8-b00b-a6cdcc68a760
< 3.1.8
MEDIUM 6.1 The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress is vulnerable to Cross-Site Request Forg… wordfence
c10c2256-4ffd-489a-afae-b455bf45c3ca
< 4.1
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in the WordPress Backup to Dropbox plugin before 4.1 for WordPress. wordfence
c0f671be-758e-4b10-ae1f-b18822ab633f MEDIUM 6.1 The yCyclista plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,… wordfence
c0f1d229-a4c1-478c-a736-c3f0ea699e63 MEDIUM 6.1 The Wp Slide Categorywise plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
c0e6f20a-3a5c-4782-9852-9891b93d765f
< 2.05.03
MEDIUM 6.1 The Formidable Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'before_html' p… wordfence
c0dc5349-139a-4bf3-8503-0e75b132c68c MEDIUM 6.1 The Publish 2 Ping.fm plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
c0d0c31e-1641-48e6-bd3e-47d8afb1b3b8
< 1.3.3
MEDIUM 6.1 The Appsero Helper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
c0c57743-9fdd-4fc0-9a27-787834b64846
< 3.2.1
MEDIUM 6.1 The KiviCare plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'filterType' parameter in vers… wordfence
c09d5743-e7d0-4017-9037-401d683395ed MEDIUM 6.1 The Related Posts Widget with Thumbnails plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version… wordfence
c0793db6-5a9b-4726-935e-c8d614443611
< 4.8.4
MEDIUM 6.1 The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability… wordfence
c0706234-f672-4db1-8dea-e4cd9d881f68
< 7.4.3
MEDIUM 6.1 The Zigaform – Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up … wordfence
c06207da-d15d-4540-84be-218fa9055fd5 MEDIUM 6.1 The Overstock Affiliate Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PH… wordfence
c0390885-d380-400f-832d-2a75fd3b94ee
< 1.8.1
MEDIUM 6.1 The Plugin Oficial – Getnet para WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in a… wordfence
c0382ab4-6d2f-476b-a78f-cfabbfe2df43
< 7.10.04
MEDIUM 6.1 The Compress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.10… wordfence
c0294278-581d-4c1e-b77e-a598ea6c816b MEDIUM 6.1 The BU Section Editing plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'perm_panel' paramet… wordfence
c0170668-65bc-4d65-a88b-9398391c98d9
< 0.0.22
MEDIUM 6.1 The Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS plugin for WordPress is … wordfence
bfeee1b9-2490-40ad-a49c-f18ed7b11070 MEDIUM 6.1 The Custom Login Redirect WordPress plugin through 1.0.0 does not have CSRF check in place when saving its settings, and… wordfence
bfe35762-2cb1-4b62-8865-ab217ff29450
< 1.98.0
MEDIUM 6.1 The dejure.org Vernetzungsfunktion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
bfd59736-1223-4e6c-8915-162d0898ae99
< 4.0.0
MEDIUM 6.1 The PlainInventory – Inventory Management Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in a… wordfence
bfccbf41-c861-4bf1-b400-7858cb255b9a
< 1.6.28
MEDIUM 6.1 The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'map' p… wordfence
← Prev 825 826 827 828 829 830 831 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top