Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1136 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| c16c8f50-4fb6-4fe6-aa35-ad5105dee8d9 | MEDIUM | 5.3 | The Wp EMember plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, v1… | — | wordfence | |
| c1558b08-a33b-4cf2-bacb-c88065f513cc | < 4.5.6 |
MEDIUM | 5.3 | The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in… | — | wordfence |
| c12cca1e-2d6a-4946-bff7-bb71e570e9d5 | < 2.0.7 |
MEDIUM | 5.3 | The CatFolders Document Gallery & PDF Library plugin for WordPress is vulnerable to unauthorized access in all versions … | — | wordfence |
| c1033b4d-82a0-4484-aebf-f35d6a2a9a13 | < 3.8.0 |
MEDIUM | 5.3 | The EmbedPress plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on t… | — | wordfence |
| c0d1145d-f888-4217-963c-c058a6a56f74 | < 3.6.8 |
MEDIUM | 5.3 | The Easy Digital Downloads β eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to unau… | — | wordfence |
| c0c60ee5-65e4-45a7-a4b5-53de7dd6a65b | < 1.6.1 |
MEDIUM | 5.3 | The UPI QR Code Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missi… | — | wordfence |
| c0bba475-b498-4c2d-a3f2-f4766a2b8616 | < 3.5.2 |
MEDIUM | 5.3 | wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause… | — | wordfence |
| c0a42af0-72da-49f3-a2c5-e76a9e918446 | < 4.9.9 |
MEDIUM | 5.3 | The All in One SEO β AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin … | — | wordfence |
| c09318f1-04b2-44e5-a184-c07942ae5778 | < 3.2.2 |
MEDIUM | 5.3 | The NotificationX β FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & … | — | wordfence |
| c092629f-177c-4201-9fdd-defe47f85811 | MEDIUM | 5.3 | The Post From Frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence | |
| c08444ef-77bc-4e9d-8d94-04b90cc99ded | < 3.5.4 |
MEDIUM | 5.3 | The JetFormBuilder β Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized modification of da… | — | wordfence |
| c034d2a2-20c4-4c32-8cfe-b80a62bdfdeb | < 1.7.1 |
MEDIUM | 5.3 | The ShareYourCart plugin before 1.7.1 for WordPress allows remote attackers to obtain the installation path via unspecif… | — | wordfence |
| c023b91e-f633-41a6-b2d7-bcb3f1d026b7 | < 2.1.1 |
MEDIUM | 5.3 | The Spin Wheel plugin for WordPress is vulnerable to client-side prize manipulation in all versions up to, and including… | — | wordfence |
| c01a8fbc-c16a-40e2-b628-f874cd3b21e4 | < 1.3.3 |
MEDIUM | 5.3 | The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Sensitive Information Exposure in all … | — | wordfence |
| c0163382-9b53-4c74-b9bd-c3baa14faee1 | MEDIUM | 5.3 | The EventON (Pro) - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized access du… | — | wordfence | |
| bfef0be2-b73d-43f9-a3bc-f61846fa0704 | MEDIUM | 5.3 | The Xendit Payment plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… | — | wordfence | |
| bfe48948-7fc9-4806-b1b5-9fac5a6c7d96 | < 1.68.5 |
MEDIUM | 5.3 | Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests… | — | wordfence |
| bfcbd6fb-f599-4a85-aabb-d03d2716ba00 | MEDIUM | 5.3 | The YT Player β Embed and Customize Video Players plugin for WordPress is vulnerable to unauthorized access due to a m… | — | wordfence | |
| bfba1c2c-6679-4c6c-95fd-bae391e6aa0b | < 1.2 |
MEDIUM | 5.3 | The WpXmas-Snow plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… | — | wordfence |
| bfb473a6-08ba-4b23-877d-4aa661c0053f | < 2.3.28 |
MEDIUM | 5.3 | The Contact Form builder with drag & drop - Kali Forms plugin for WordPress is vulnerable to unauthorized modification o… | — | wordfence |
| bfa9a9f6-dfbb-442c-af2c-af3d44e7b0f1 | < 1.1.1 |
MEDIUM | 5.3 | The TrustedLogin Vendor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions prior to 1.… | — | wordfence |
| bf8aa169-df51-46db-8c65-f1543d4f75f9 | < 2.7.7 |
MEDIUM | 5.3 | The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6.… | — | wordfence |
| bf79cc31-5dd4-4b4f-9c5d-5adaea7689a5 | < 1.26.9 |
MEDIUM | 5.3 | The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve… | — | wordfence |
| bf5dab26-6674-49d9-bc14-13430f4d644f | < 5.5.8 |
MEDIUM | 5.3 | The App Builder β Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to unauthorized ac… | — | wordfence |
| bf4eca37-066f-428c-a4f7-061ce06e1142 | < 4.2.20 |
MEDIUM | 5.3 | The MultiVendorX β Empower Your WooCommerce Store with a Dynamic Multivendor Marketplace β Build the Next Amazon, eB… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →