Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1064 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| cb649fb2-2d0e-4fe3-89d5-90bcbc0bcfcf | < 1.18.0 |
MEDIUM | 5.4 | The Popup Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… | — | wordfence |
| cb5f5e33-e066-4a85-9367-4b8c2f948adf | MEDIUM | 5.4 | The PDF Catalog for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pdfcatalog' A… | — | wordfence | |
| cb4e3b3c-20f4-4591-af0a-539b405d675e | < 4.2.3 |
MEDIUM | 5.4 | The Ultimate Product Catalog plugin for WordPress is vulnerable to SQL Injection via the ‘CatID’ parameter in versio… | — | wordfence |
| cb47b6cc-87e4-4d29-bbc7-6d7552bc3943 | < 1.3.60 |
MEDIUM | 5.4 | The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compa… | — | wordfence |
| cb08cf02-4766-4093-9306-3b4581f54f77 | MEDIUM | 5.4 | The Responsive Image Gallery, Gallery Album plugin for WordPress is vulnerable to unauthorized modification of data and … | — | wordfence | |
| cb0261c6-0477-4769-b92a-b49a192df4bb | < 4.10.32 |
MEDIUM | 5.4 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Glob… | — | wordfence |
| cae1e209-96f3-49ed-a233-768db8e36c5b | < 3.8.5 |
MEDIUM | 5.4 | The Event Management, Events Calendar, RSVP Event Tickets Plugin for WordPress is vulnerable to Stored Cross-Site Script… | — | wordfence |
| cac9614d-3fe5-4657-af6b-81acb71f51f1 | < 3.2.18 |
MEDIUM | 5.4 | The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup… | — | wordfence |
| ca66afc3-a749-4ddc-8e2f-959f65cebd45 | < 3.3.3 |
MEDIUM | 5.4 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … | — | wordfence |
| ca17fd4a-fd14-46e6-9348-19b74fec5df8 | < 1.5.0 |
MEDIUM | 5.4 | The Display Post Metadata for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_fields’ parameter… | — | wordfence |
| ca058dde-48fd-46f4-b16c-97cdf79578ff | < 4.9.24 |
MEDIUM | 5.4 | The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Cross-Site Request Forgery in versio… | — | wordfence |
| c95505e3-6851-476e-af40-bb841eb01be7 | < 3.7.31 |
MEDIUM | 5.4 | WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider t… | — | wordfence |
| c9176a81-fe51-48dd-a151-4596443b430f | < 6.5.8 |
MEDIUM | 5.4 | The WP Ultimate CSV Importer plugin for WordPress is vulnerable to authorization bypass due to a missing capability chec… | — | wordfence |
| c89d56e2-68aa-4caf-bc1b-9aa32ec11ba3 | < 2.0.7 |
MEDIUM | 5.4 | WordPress Plugin Gravity Forms is prone to a cross-site scripting vulnerability because it fails to properly sanitize us… | — | wordfence |
| c829217a-c5be-4713-bbf4-c1ba829c1187 | < 4.8.0 |
MEDIUM | 5.4 | The Affiliate For WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability che… | — | wordfence |
| c79fd08c-97bc-4d55-832e-92d0897bc3dc | < 1.4.5 |
MEDIUM | 5.4 | The Protected Posts Logout Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… | — | wordfence |
| c75e6d27-7f6b-4bec-b653-c2024504f427 | < 8.0.9 |
MEDIUM | 5.4 | The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| c6f0b546-efd2-4592-a9c1-4784e13209d8 | < 3.7 |
MEDIUM | 5.4 | The WP Clone any post type plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.6… | — | wordfence |
| c6b3d91c-591b-444d-888b-1b443e72afca | < 1.0.17 |
MEDIUM | 5.4 | The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it b… | — | wordfence |
| c674bb2a-8ecf-4aea-a729-c9bdf4ee35fd | < 3.7.15 |
MEDIUM | 5.4 | WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute fr… | — | wordfence |
| c6683edc-8c77-446c-bd7e-e97b8c5d0c57 | < 1.0.0.29 |
MEDIUM | 5.4 | The WordPress plugin Gallery for Social Photo is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
| c62860e2-8c89-4f1c-a7d8-ef13f545ad52 | < 2.3.4 |
MEDIUM | 5.4 | In the GetPaid WordPress plugin before 2.3.4, users with the contributor role and above can create a new Payment Form, h… | — | wordfence |
| c60ddcba-99e7-4cba-8bee-f2b01369b025 | MEDIUM | 5.4 | The Spreadconnect plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… | — | wordfence | |
| c5e516d6-eece-42d3-9349-29be685a3509 | < 2.23 |
MEDIUM | 5.4 | The Pure Chat plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2… | — | wordfence |
| c5b67927-5993-4e21-af52-8ebe7fee48ab | < 3.9.13 |
MEDIUM | 5.4 | The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gu… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →