Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1246 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| c42139fc-34a2-47ae-b172-d2cd4f1cf098 | < 1.1.4 |
MEDIUM | 4.9 | The Media Sweep β WordPress Media Cleaner plugin for WordPress is vulnerable to generic SQL Injection via the 'fields'… | — | wordfence |
| c2c58f4a-1436-4796-bf61-895177639dbe | < 0.9.7 |
MEDIUM | 4.9 | The Link Whisper Free plugin for WordPress is vulnerable to SQL Injection in all versions up to 0.9.7. This is due to in… | — | wordfence |
| c2ba5136-cd30-4b65-af3e-f1161ae6eeee | < 4.5.9 |
MEDIUM | 4.9 | The Dynamic Pricing With Discount Rules for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions … | — | wordfence |
| c2b36621-3322-4631-b693-629c5084708b | < 9.1.8 |
MEDIUM | 4.9 | The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7… | — | wordfence |
| c26e5109-aaf8-4bba-9331-b8baaf109a55 | < 3.9.26 |
MEDIUM | 4.9 | The Simple Download Monitor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.9.25… | — | wordfence |
| c2353d9d-d5ae-4470-9c0f-119acecd6686 | < 1.3.1 |
MEDIUM | 4.9 | The Easy Email Subscription plugin for WordPress is vulnerable to SQL Injection via the 'uid' parameter in all versions … | — | wordfence |
| c1d532f8-c8aa-4d1b-9a6b-cb12402bf1eb | < 1.1.8 |
MEDIUM | 4.9 | The BEAR plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.7.1 due to insufficie… | — | wordfence |
| c0c4028d-24b5-4293-8969-66e199556d73 | < 1.10.1 |
MEDIUM | 4.9 | The User Feedback plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.10.0 due to in… | — | wordfence |
| bf7c500e-311f-4db5-8a54-de7b02fb11dd | < 1.24.2 |
MEDIUM | 4.9 | The Mail Mint β Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable … | — | wordfence |
| bed2ada9-af3d-479e-8ae4-11eaad0b3842 | < 3.4.6 |
MEDIUM | 4.9 | The ShopLentor β All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-b… | — | wordfence |
| beb489d3-2c1b-4af5-b73e-126d2526e0a3 | < 2.3 |
MEDIUM | 4.9 | The Design Import/Export plugin for WordPress is vulnerable to SQL Injection via XML File Import in all versions up to, … | — | wordfence |
| be3bd1f2-092c-47c4-a4e4-3365e107c57f | < 1.2.8 |
MEDIUM | 4.9 | The Backuply β Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all ver… | — | wordfence |
| bdd03b29-daeb-43bb-b54d-6d7a053a051c | MEDIUM | 4.9 | The Altra Side Menu plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0 due to… | — | wordfence | |
| bd3e30ea-8f58-4895-b78c-fb18c94d5253 | < 1.0.5 |
MEDIUM | 4.9 | The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in… | — | wordfence |
| bd184c80-e785-4e9b-961d-9c3378688f91 | < 1.5.9 |
MEDIUM | 4.9 | The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'ce_venue_name' CSV field in the `on_sa… | — | wordfence |
| bced99cc-89db-4e42-9336-b83721826680 | < 1.1.1 |
MEDIUM | 4.9 | The Slider by BestWebSoft plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.0 du… | — | wordfence |
| bcae549f-6a10-4b0d-a8d1-5dcc83e1f2e5 | < 3.9.8 |
MEDIUM | 4.9 | The SMS Alert β SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulne… | — | wordfence |
| bc176920-04c4-42c7-ab9c-683788e998dd | < 2.8.1 |
MEDIUM | 4.9 | The Zoho Flow for WordPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.8.0… | — | wordfence |
| bbe9eed9-9a96-47da-95fa-b942817a9d4f | < 3.7.22 |
MEDIUM | 4.9 | Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme fil… | — | wordfence |
| bb9aedc6-42ef-4fd9-a9d5-2a79214be472 | < 7.4.5 |
MEDIUM | 4.9 | The Complianz β GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all vers… | — | wordfence |
| bb8f7748-8268-4a38-b794-495c5f6eb5ca | < 4.0.1 |
MEDIUM | 4.9 | The Advanced Shipment Tracking for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, an… | — | wordfence |
| bb3859eb-5a1f-408c-84aa-acfc68bd0bb5 | < 2.5.0 |
MEDIUM | 4.9 | The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowi… | — | wordfence |
| bb23bc2e-4484-46d5-b46e-5e43e5a1bf12 | MEDIUM | 4.9 | The Pinpoint Booking System β Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' para… | — | wordfence | |
| ba60fb73-9056-4163-9874-f0f4af35f5b3 | < 1.5.25 |
MEDIUM | 4.9 | The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversa… | — | wordfence |
| ba326241-46a3-4891-a180-d7977f4e83ed | < 4.4.0 |
MEDIUM | 4.9 | The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in version … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →