Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1028 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| cc6f017d-b0ba-494d-9ad1-8b6cdca48fb1 | < 1.0.77.33 |
MEDIUM | 5.5 | Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP … | — | wordfence |
| cc0e133d-b1c7-42c4-bd1f-7b91f0ec4fb3 | < 3.8.2 |
MEDIUM | 5.5 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in René Hermenau's Social Media Share Buttons pl… | — | wordfence |
| cb610baa-093d-4a41-8e28-c65fdb0e32aa | < 7.6 |
MEDIUM | 5.5 | The ANAC XML Bandi di Gara plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in… | — | wordfence |
| cb56b00c-31dd-4076-aeaf-9b249f04f1c6 | < 1.6.6 |
MEDIUM | 5.5 | The WBW Currency Switcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blockip’ parame… | — | wordfence |
| ca6b7886-790a-4f00-855c-6dc913ea01db | < 1.10.2 |
MEDIUM | 5.5 | The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘exclusion_list’ p… | — | wordfence |
| ca1316be-1978-46c1-8685-10a8d4c34bdb | < 1.15.32 |
MEDIUM | 5.5 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Store… | — | wordfence |
| c96b9599-b1a5-4aa6-85fe-7af3f12d1776 | < 7.1 |
MEDIUM | 5.5 | The LiteSpeed Cache plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includi… | — | wordfence |
| c85f6c1b-673d-4fe9-acef-a15d90fcf414 | MEDIUM | 5.5 | The Quizlord plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unspecified parameter in versions … | — | wordfence | |
| c8582af5-92e9-43ef-836f-d87d5cf827d8 | < 2.9.14 |
MEDIUM | 5.5 | The Affiliates Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parame… | — | wordfence |
| c83a2c4d-a264-49ec-85f1-e3f48715d725 | < 4.7.34 |
MEDIUM | 5.5 | WordPress Core is vulnerable to CSS Injection in all versions up to, and including, 7.0.2 due to insufficient sanitizati… | — | wordfence |
| c825723b-2ec5-4af8-91a1-454d35a7f1bb | < 1.1.7 |
MEDIUM | 5.5 | The WP Live Chat + Chatbots Plugin for WordPress – Chaport plugin for WordPress is vulnerable to Stored Cross-Site Scr… | — | wordfence |
| c7d215e9-e615-46ab-b0b8-b37f10cfae98 | < 1.0.12 |
MEDIUM | 5.5 | The ZeroBounce Email Verification & Validation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm… | — | wordfence |
| c7112f34-3055-4033-82ba-d59489cd8c6b | < 2.8.4 |
MEDIUM | 5.5 | The Wise Chat plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.8.3. This allows u… | — | wordfence |
| c6d45e18-7aa0-4f73-bf07-069870b467f4 | < 2.1.9 |
MEDIUM | 5.5 | The WP-Paginate WordPress plugin before 2.1.9 does not escape one of its settings, which could allow high privilege user… | — | wordfence |
| c6cd7986-6d3b-426b-a539-8dc11f0d7b04 | MEDIUM | 5.5 | The Client Dash plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.2.0 due t… | — | wordfence | |
| c6b079f5-715d-4fb3-bcaf-539412d5e956 | MEDIUM | 5.5 | The MyBB Cross-Poster WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation… | — | wordfence | |
| c68a9b05-5e60-4d5f-9d00-a9a5b85271f2 | < 5.2.1 |
MEDIUM | 5.5 | The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters i… | — | wordfence |
| c648fbb1-cc12-4334-b334-0f784542ab6d | < 1.2.6 |
MEDIUM | 5.5 | The FormCraft WordPress plugin before 1.2.6 does not sanitise and escape Field Labels, allowing high privilege users suc… | — | wordfence |
| c5a2d57d-eaa1-4a8a-86cb-f28adf13fab2 | < 5.9.6 |
MEDIUM | 5.5 | The Icegram Express Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inc… | — | wordfence |
| c59871cc-2d62-4eea-a78b-19810570c47d | < 3.2.1 |
MEDIUM | 5.5 | The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new soci… | — | wordfence |
| c56b1dca-3841-48df-837e-7973940e74e3 | < 2.1.4 |
MEDIUM | 5.5 | The Breeze plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘breeze_api_token’ parameter in… | — | wordfence |
| c53ebf2f-44ab-4d0f-ac3d-c08806c07343 | MEDIUM | 5.5 | The Live Gold Price & Silver Price Charts Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | — | wordfence | |
| c5203a17-cc4f-4545-a231-dfbfb900f0fd | < 1.3.6 |
MEDIUM | 5.5 | The BuddyPress xProfile Checkout Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bf… | — | wordfence |
| c4d552a7-499f-4946-b0ec-5f733c01a365 | < 3.4 |
MEDIUM | 5.5 | The WP eBay Product Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters … | — | wordfence |
| c476d9af-9060-4294-874a-86e550253d3b | < 27.0 |
MEDIUM | 5.5 | The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 du… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →