Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1065 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| c58fa0a0-0b22-42df-8d3a-c3de78e12aa7 | < 1.3.7 |
MEDIUM | 5.4 | The DW Question & Answer Pro WordPress plugin through 1.3.6 does not check that the comment to edit belongs to the user … | — | wordfence |
| c58d9011-a082-48ca-b702-ef5563af2c66 | < 1.9.0 |
MEDIUM | 5.4 | The Saphali Woocommerce Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… | — | wordfence |
| c55ca7d4-6bc0-49c9-8ce0-50fff8775a76 | < 7.5.39.7212 |
MEDIUM | 5.4 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β_fv_player_u… | — | wordfence |
| c55792d6-3f31-4635-ad5c-17d03a5b2977 | MEDIUM | 5.4 | The WordPress Related Posts plugin through 3.6.4 contains an authenticated (admin+) stored XSS vulnerability in the titl… | — | wordfence | |
| c544c86d-e414-49c2-ae57-3293b1a6409d | < 3.5.1 |
MEDIUM | 5.4 | The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct … | — | wordfence |
| c510063e-1c64-40fa-842a-e7efd3dc550a | < 3.7.30 |
MEDIUM | 5.4 | WordPress before 5.2.3 allows XSS in shortcode previews. | — | wordfence |
| c4f76e1d-23f2-4dff-98eb-c73f7e7f10cb | MEDIUM | 5.4 | The Print Science Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… | — | wordfence | |
| c4c2689d-be51-4907-b624-c85da39f545d | < 2.0 |
MEDIUM | 5.4 | The Easy WP Cleaner plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… | — | wordfence |
| c4b1cae3-dc08-43b1-9a20-62b7263efeba | < 2.0.7 |
MEDIUM | 5.4 | The WPCode plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capabilit… | — | wordfence |
| c46bcbd1-566d-4b21-84a1-f25e3df7ddc7 | < 3.0 |
MEDIUM | 5.4 | The Paid Memberships Pro β Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulner… | — | wordfence |
| c454a958-91c4-4847-91f6-dedebf857964 | < 4.9.14 |
MEDIUM | 5.4 | The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capabil… | — | wordfence |
| c4006612-770a-482f-a8c2-e62f607914a9 | < 2.6 |
MEDIUM | 5.4 | The Product Expiry for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a miss… | — | wordfence |
| c3728280-3487-4cb2-8e37-f33811bc0a22 | < 2.18.17 |
MEDIUM | 5.4 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a… | — | wordfence |
| c3016491-6a6a-433f-9018-5e84f9e3e37c | < 5.5.4 |
MEDIUM | 5.4 | The Bulk Delete plugin for WordPress is vulnerable to missing authorization due to missing capability checks on several … | — | wordfence |
| c2e80e6f-08e7-426b-9797-97483c3dc410 | < 2.5.19 |
MEDIUM | 5.4 | Cross-site scripting (XSS) vulnerability in the Google Doc Embedder plugin before 2.5.19 for WordPress allows remote att… | — | wordfence |
| c2cdf4e5-0a40-42ca-b5ac-78511fdd2b77 | < 4.3.3 |
MEDIUM | 5.4 | The RSS Aggregator by Feedzy β Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress … | — | wordfence |
| c1f643bd-a168-4506-9606-0b8b91573ebb | < 2.1.0 |
MEDIUM | 5.4 | Stored Cross-Site Scripting (XSS) in Yoo Slider β Image Slider & Video Slider (WordPress plugin) allows attackers with… | — | wordfence |
| c1c106e8-9642-4294-90fd-6838cc551b90 | < 6.4.5 |
MEDIUM | 5.4 | The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… | — | wordfence |
| c177440a-4575-4202-be16-ac7ab0fbb90b | < 2.4.7 |
MEDIUM | 5.4 | The give plugin before 2.4.7 for WordPress has XSS via a donor name. | — | wordfence |
| c13bb699-f065-4065-9ea5-bb86d24e09ab | < 2.2.1 |
MEDIUM | 5.4 | The PopupKit plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.0. Thi… | — | wordfence |
| c11ab6ef-90c4-4091-8025-b182cf40f61c | MEDIUM | 5.4 | The CF7 Submissions plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… | — | wordfence | |
| c10600ae-1ff0-4f12-ae53-39d9342640f4 | MEDIUM | 5.4 | The aBlocks β WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and d… | — | wordfence | |
| c0daeb94-1028-4163-af9d-0a6d7a00269f | < 2.1.7 |
MEDIUM | 5.4 | The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its … | — | wordfence |
| c06f9f6d-3cd0-4700-834b-435a99983453 | < 1.3.3.379 |
MEDIUM | 5.4 | The Surfer plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability … | — | wordfence |
| c06db4a6-fb17-4fcc-95df-f84ac59cc42c | MEDIUM | 5.4 | The Subresource Integrity (SRI) Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capab… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →