Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 133 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| c9a9675f-76f5-4551-8d2d-60ae7a8378d1 | HIGH | 8.8 | The Marketing Automation by AZEXO plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and … | — | wordfence | |
| c99e7f4c-ba91-4d64-b8d4-23940381e79a | < 2.0.0 |
HIGH | 8.8 | The Simple Personal Message plugin for WordPress is vulnerable to SQL Injection via the ‘message’ parameter in versi… | — | wordfence |
| c964c99b-f751-4e81-b6bf-f10a3b1106ba | < 1.3.13 |
HIGH | 8.8 | The WP Posts Carousel plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.1… | — | wordfence |
| c958880e-6068-4e7d-a780-1251f3ab9bf7 | < 5.2.8 |
HIGH | 8.8 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege es… | — | wordfence |
| c943cf0b-0e99-4d47-808d-2b803369d53a | < 3.6 |
HIGH | 8.8 | The Popup with fancybox plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to… | — | wordfence |
| c90844e1-0502-4d08-888f-4835f63f8dd0 | < 3.7.38 |
HIGH | 8.8 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object … | — | wordfence |
| c906a988-ad45-49cc-9d77-6b501445ddc5 | < 1.0.0.27 |
HIGH | 8.8 | The plugin Gallery for Social Photo is vulnerable to SQL Injection via the post parameter in the function gifeed_duplica… | — | wordfence |
| c901f85d-fcdb-43e5-8626-f2410e4e328f | < 1.7.9 |
HIGH | 8.8 | The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.7.… | — | wordfence |
| c8dc9fd0-929e-447f-be05-085be98e4d0f | < 1.6.2 |
HIGH | 8.8 | The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-ad… | — | wordfence |
| c8b1015f-6825-4813-b5db-71f1c1e88310 | < 1.3.6.6 |
HIGH | 8.8 | The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forge… | — | wordfence |
| c8af0c5c-3d7b-416d-9d10-6867fcf909a5 | HIGH | 8.8 | The WHMPress - WHMCS Client Area plugin for WordPress is vulnerable to unauthorized modification of data that can lead t… | — | wordfence | |
| c8ae0a47-cba5-468e-8d25-7b7176373b9c | < 3.6.1 |
HIGH | 8.8 | The ElementsKit Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6… | — | wordfence |
| c8a1127c-308d-4347-bd42-2071b906e247 | HIGH | 8.8 | The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could… | — | wordfence | |
| c873d838-58e8-4f69-bccb-6d1de8d91877 | < 2.1 |
HIGH | 8.8 | The Login as User or Customer Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… | — | wordfence |
| c8440240-f652-4372-9ed8-f3eb3b8336e0 | < 4.0.7 |
HIGH | 8.8 | The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions s… | — | wordfence |
| c829894f-05b8-4c65-9f3a-3a5d6e212cde | < 7.3.11 |
HIGH | 8.8 | The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| c7caf1f4-a8dd-4016-91eb-2adbeed5290a | < 1.8.1 |
HIGH | 8.8 | The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the w… | — | wordfence |
| c7bb055d-dd43-4c40-be30-325ecb6d7731 | HIGH | 8.8 | The Amplus theme for WordPress is vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce va… | — | wordfence | |
| c7b540b9-cdf1-40ea-b693-c237e76c0958 | HIGH | 8.8 | Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a reques… | — | wordfence | |
| c77fce42-92e9-43bc-ab3b-599e036ed648 | < 3.4.1 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to h… | — | wordfence |
| c72a6459-f5a7-4b3d-ac70-c685fb90f903 | < 2.0.2 |
HIGH | 8.8 | The Charety - Charity & Donation WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to miss… | — | wordfence |
| c7296fdb-d5d6-4d4f-ac80-b9d5452191b4 | < 16.01 |
HIGH | 8.8 | The WP Symposium Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 16.01. This is … | — | wordfence |
| c7266ce6-2853-4c5d-9e36-8c5b7418b072 | < 1.3.28 |
HIGH | 8.8 | The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in versions less than, … | — | wordfence |
| c6efb57a-9638-44d1-a8d1-8eeadcc81ecc | < 4.2.3 |
HIGH | 8.8 | The Analytify – Google Analytics Dashboard For WordPress plugin for WordPress is vulnerable to Cross-Site Request Forg… | — | wordfence |
| c6ea48b4-b4ef-40e2-ade9-8bf44147e8c7 | < 3.4.13 |
HIGH | 8.8 | The Post Grid Master plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.4.12… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →