Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1029 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| c3c961eb-0174-4aa3-a117-7f72998eefbb | < 2.2 |
MEDIUM | 5.5 | An issue was discovered in the read-and-understood plugin 2.1 for WordPress. XSS exists via the wp-admin/options-general… | — | wordfence |
| c394295f-d1b5-48be-978f-f15a6b56e40f | < 1.7.0 |
MEDIUM | 5.5 | The WP Server Health Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘API Pro Key’ p… | — | wordfence |
| c34b21da-6c35-4eec-826b-47dc46575971 | < 4.1.11 |
MEDIUM | 5.5 | The Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.… | — | wordfence |
| c29cb99f-72e9-4178-b961-7ab50a5b6c7d | < 3.0.0 |
MEDIUM | 5.5 | The Rock Convert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's settings … | — | wordfence |
| c2121162-68db-47c4-80f6-222f013f48c2 | < 1.0.36 |
MEDIUM | 5.5 | The External Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… | — | wordfence |
| c2110dbe-a625-4fa5-8426-8f11b3c33844 | MEDIUM | 5.5 | The GD Mylist WordPress plugin through 1.1.1 does not sanitise and escape some of its settings, allowing high privilege … | — | wordfence | |
| c1ec113c-d11f-4b0b-8d4a-46d37687b3b2 | < 1.8.3 |
MEDIUM | 5.5 | The Countdown and CountUp, WooCommerce Sales Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… | — | wordfence |
| c1d67b80-67b7-4194-ab90-e9f8cea1ac33 | < 1.0.6 |
MEDIUM | 5.5 | The youForms for WordPress plugin through 1.0.5 does not sanitise escape the Button Text field of its Templates, allowin… | — | wordfence |
| c133c31e-e80a-4293-b19d-22e8bc8f677b | < 3.8.2 |
MEDIUM | 5.5 | The WordPress to Buffer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in vers… | — | wordfence |
| c10917f9-f0e0-40af-84e3-38f588051186 | < 1.1.7 |
MEDIUM | 5.5 | The Page Takeover plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… | — | wordfence |
| c101b579-de72-4f33-8fd2-7fcd7c25044c | MEDIUM | 5.5 | The DW Promobar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dwpb_bar_text' parameter in v… | — | wordfence | |
| c0ba19a2-0a30-4346-88a2-d1166ab13388 | < 3.5.9 |
MEDIUM | 5.5 | The Flower Delivery by Florist One plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in … | — | wordfence |
| c031d2a4-d009-4422-a751-b8476e15a808 | < 1.3.2.3 |
MEDIUM | 5.5 | The Chained Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'facebook_appid' parameter in… | — | wordfence |
| bff16371-51a9-44c9-ba6f-3680f84b880a | < 6.0.5 |
MEDIUM | 5.5 | The WP Social Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters including t… | — | wordfence |
| bf36c00f-e6a2-4630-b5ef-9015365be436 | < 2.3.0 |
MEDIUM | 5.5 | The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in al… | — | wordfence |
| bf02edc9-2bb6-4ceb-b2a1-63f95c8becb3 | < 3.1.7 |
MEDIUM | 5.5 | The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text… | — | wordfence |
| be374684-bb02-4d2c-b8a0-ed435c7c8569 | < 1.0.4 |
MEDIUM | 5.5 | The Microsoft Advertising Universal Event Tracking (UET) WordPress plugin before 1.0.4 does not sanitise and escape its … | — | wordfence |
| be24d47e-4880-4d7f-9be2-cf8eb1afe888 | < 2.8.4 |
MEDIUM | 5.5 | The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allo… | — | wordfence |
| be0db9ff-dc95-4c92-8dc4-472c5df9c0dd | < 1.11.0 |
MEDIUM | 5.5 | The Lana Downloads Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the endpoint parameters… | — | wordfence |
| be091637-0fcb-4d30-8eaa-2fe18d8eb42c | < 1.5 |
MEDIUM | 5.5 | The CampTix Event Ticketing plugin before 1.5 for WordPress allows XSS in the admin section via a ticket title or body. | — | wordfence |
| bddba0a8-03cf-441f-9411-f770766b4f63 | MEDIUM | 5.5 | The Comment Engine Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… | — | wordfence | |
| bd57edf5-a75e-4677-a51e-9dd262eeba4a | < 4.8.7 |
MEDIUM | 5.5 | The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Stored Cross-Site Scripting via the textarea form fiel… | — | wordfence |
| bd4a1fd2-8831-482d-8ae3-fb78c2657b86 | MEDIUM | 5.5 | The WP DoNotTrack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘whitelist’ and 'blackli… | — | wordfence | |
| bd2f7567-a438-417b-bf0f-dec7a9f098b2 | < 3.7.0 |
MEDIUM | 5.5 | The WP Mapa Politico Espana WordPress plugin before 3.7.0 does not sanitise or escape some of its settings before output… | — | wordfence |
| bd248252-4329-4b3c-acf1-3b3d8cc9887c | MEDIUM | 5.5 | The Easy Smooth Scroll Links WordPress plugin before 2.23.1 does not sanitise and escape its settings, which could allow… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →