Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 132 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| cbff92c1-8492-4d0d-bd90-8fd33625bf6f | < 67.2.0 |
HIGH | 8.8 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing … | — | wordfence |
| cbfbb06c-f048-4912-9ff7-59aa10bc96bd | < 4.7.0 |
HIGH | 8.8 | The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.6.9 … | — | wordfence |
| cbe8cf6c-b1fa-4f71-bb63-c8b181e54882 | < 6.6.11 |
HIGH | 8.8 | The Essential Addons for Elementor β Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authe… | — | wordfence |
| cbcd978b-e81f-4c39-b2f7-adc948d21b1b | < 3.2.7 |
HIGH | 8.8 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to privilege escalation due t… | — | wordfence |
| cbb51383-1eab-4490-aa4c-bd1488312400 | < 1.2.3 |
HIGH | 8.8 | The Trust Payments Gateway (3DS2) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… | — | wordfence |
| cb37b784-b1ff-4cee-889d-751218e5b95d | < 5.3.3 |
HIGH | 8.8 | The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type… | — | wordfence |
| cb1dc7e4-a339-4760-9f63-aaa6590bd5e0 | < 2.3.29 |
HIGH | 8.8 | The GigPress plugin for WordPress is vulnerable to SQL Injection via shortcode attributes in versions up to, and includi… | — | wordfence |
| cb158acc-69d7-4a7d-b356-7de1f6b37019 | < 5.1.9 |
HIGH | 8.8 | The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.… | — | wordfence |
| cb105ff0-5085-4813-81a6-b1f0798d576c | < 4.0.8 |
HIGH | 8.8 | Several MainWP extensions for WordPress are vulnerable to Cross-Site Request Forgery due to missing or incorrect nonce v… | — | wordfence |
| cabb9be3-581a-48d9-afa2-929921eae52d | < 1.3.1 |
HIGH | 8.8 | The Consulting Elementor Widgets plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and … | — | wordfence |
| cab9f082-6f9d-443c-8cf0-4cfe2516e39c | < 1.4.6 |
HIGH | 8.8 | The Material Dashboard plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.… | — | wordfence |
| cab2f0d7-f288-4462-b2a7-7a999cd47466 | < 1.2.66 |
HIGH | 8.8 | The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF. | — | wordfence |
| ca9c10b6-6d32-45c9-beb1-7a5c84d0863d | < 3.7.3 |
HIGH | 8.8 | The I Recommend This plugin for WordPress is vulnerable to SQL Injection via the 'post_type' attribute called via the pl… | — | wordfence |
| ca64692b-b194-4ceb-975e-72e4041252f2 | HIGH | 8.8 | The Link Optimizer Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in vers… | — | wordfence | |
| ca564941-4780-4da2-b937-c9bd45966d81 | < 3.6.0 |
HIGH | 8.8 | The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… | — | wordfence |
| ca46ea28-3115-4db1-8aeb-cbef731b0376 | < 2.1.0 |
HIGH | 8.8 | The wpForo Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.… | — | wordfence |
| ca132d26-e927-41f1-be57-0c3bdeace2e6 | < 0.4.13 |
HIGH | 8.8 | The Fontsampler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ajax_get_mock_fontsampler func… | — | wordfence |
| ca064db0-2718-4521-9467-335b59208858 | < 1.2.4 |
HIGH | 8.8 | The JVM Gutenberg Rich Text Icons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type … | — | wordfence |
| c9fc747c-3b13-4a49-a181-fe6a952a4ce3 | < 1.1.2 |
HIGH | 8.8 | The Error Log Viewer WordPress plugin through 1.1.1 does not perform nonce check when deleting a log file and does not h… | — | wordfence |
| c9f8e9b5-f4bf-48e3-b315-1b9b24be6e93 | < 1.0.13 |
HIGH | 8.8 | The Journey Analytics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence |
| c9d58fde-54f6-4892-b5ed-2029593c3fa4 | < 2.2.7 |
HIGH | 8.8 | The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF bug with Reflected XSS. | — | wordfence |
| c9cf97a6-38bb-4499-98f0-ca2b7111f654 | HIGH | 8.8 | The UltraPress theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.2 via… | — | wordfence | |
| c9c2fb7f-a05b-4852-97eb-7befe880d703 | < 7.1.8 |
HIGH | 8.8 | The Booster Elite for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type … | — | wordfence |
| c9c29130-1b42-4edd-ad62-6f635e03ae31 | < 3.7 |
HIGH | 8.8 | The Cyr to Lat plugin for WordPress is vulnerable to authenticated SQL Injection via the 'ctl_sanitize_title' function i… | — | wordfence |
| c9b09489-9f32-41f6-befd-7c08612d3edc | < 0.3.4 |
HIGH | 8.8 | The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.3.… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →