Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 131 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ce90db0c-d4ca-4b32-8a64-681642aaf032 | HIGH | 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Image Slider by NextCode plugin <= 1.1.2 at WordPress allows deleting… | — | wordfence | |
| ce779d08-93bf-4634-bb83-f5573876e086 | < 2.5.9 |
HIGH | 8.8 | The Powerkit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.8 Th… | — | wordfence |
| ce5b3390-75c2-4288-91a6-f9ceb893a952 | < 1.4 |
HIGH | 8.8 | The Duplicate Title Validate plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 d… | — | wordfence |
| ce3ff7f9-ccad-45c0-a278-f66fbb6263ee | HIGH | 8.8 | The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which… | — | wordfence | |
| ce340b88-cbab-4ba8-93ae-8790f2348456 | < 5.1.1 |
HIGH | 8.8 | The All In One WP Security & Firewall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… | — | wordfence |
| ce1ac711-6026-49ef-b66b-2cc199697942 | < 1.5.67 |
HIGH | 8.8 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file upl… | — | wordfence |
| cde6e758-9723-43f2-9972-32be8aeb2b91 | < 7.11.5 |
HIGH | 8.8 | The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due … | — | wordfence |
| cdd7971c-6f1c-437a-832c-e2b2817a197e | < 2.2.1 |
HIGH | 8.8 | The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… | — | wordfence |
| cd97a7a4-9f57-4882-9e3e-0e9853416af9 | < 3.6.7 |
HIGH | 8.8 | The Simple JWT Login β Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication B… | — | wordfence |
| cd90d9c0-0cab-4fd3-b016-106032f300f7 | < 7.2 |
HIGH | 8.8 | The Vertical marquee plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, a… | — | wordfence |
| cd7c763f-5c2b-407e-bdb1-4ea34fac5f4d | < 3.1.3 |
HIGH | 8.8 | cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary co… | — | wordfence |
| cd393566-b037-40ce-b3cd-12e323e9451b | < 3.1.26 |
HIGH | 8.8 | The FULL Customer plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.1.25. T… | — | wordfence |
| cd36530d-4165-4b98-a75f-b9c88178a5b6 | HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attacker… | — | wordfence | |
| cd2b419f-7b79-4988-ade3-5e7f53f3da58 | < 1.3.3 |
HIGH | 8.8 | The Qi Blocks plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.2. This m… | — | wordfence |
| cd106b92-48ee-46f4-b0a3-f595d227a0a1 | < 1.0.6 |
HIGH | 8.8 | The pretix widget plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.5. Th… | — | wordfence |
| cd091bd5-6b6a-4964-9249-525bbbec702c | < 3.29.3 |
HIGH | 8.8 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i… | — | wordfence |
| ccc75dee-1cf8-4fda-b2a1-f5d68e6c7887 | HIGH | 8.8 | The Advanced AJAX Page Loader plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload … | — | wordfence | |
| ccad206a-407e-4c49-9a4a-d5dce3e9612a | < 3.1.5 |
HIGH | 8.8 | The Two Way Chat plugin for WordPress is vulnerable to multiple Cross-Site Request Forgery in versions up to, and includ… | — | wordfence |
| cc994b2a-b3da-4edc-ada3-1150065efd30 | < 7.3.6 |
HIGH | 8.8 | The themify-ultra theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.3.5.… | — | wordfence |
| cc910c27-d83c-4f3d-b491-f3e169d8f25f | < 2.2.7 |
HIGH | 8.8 | The Fluid Responsive Slideshow plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… | — | wordfence |
| cc886378-cebf-4c0b-a089-62e9469dd954 | < 2.3 |
HIGH | 8.8 | The KONTXT Content Advisor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| cc6d943d-32c0-45d7-9de9-b576199e6fe7 | < 2.3 |
HIGH | 8.8 | The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plug… | — | wordfence |
| cc525501-1fe9-4c31-a126-c1984446b978 | < 3.3.0 |
HIGH | 8.8 | The Houzez Login Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin… | — | wordfence |
| cc13d13c-6b79-4bf1-8e77-c8cb836dc0c5 | < 3.41.2 |
HIGH | 8.8 | The LifterLMS β WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escala… | — | wordfence |
| cc0d15ab-e0a4-4ac5-8558-23aeaf00b11a | < 2.0.3 |
HIGH | 8.8 | Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary c… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →