Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 135 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| c38a5e59-3233-4b37-bd6f-baf5dc9f9a01 | < 3.7.27 |
HIGH | 8.8 | WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/… | — | wordfence |
| c3871a1e-513a-4bc4-a90d-a46cb56780d7 | < 2.3.12 |
HIGH | 8.8 | The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inc… | — | wordfence |
| c32ba2a0-a9a7-4f17-8169-912cecc40b7b | < 1.8.4 |
HIGH | 8.8 | The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation i… | — | wordfence |
| c3248327-6e10-420e-83cf-a23296eb2e6f | < 3.3.6 |
HIGH | 8.8 | The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missin… | — | wordfence |
| c30f2322-14b1-476a-bbaf-99a14bc9e017 | < 9.7 |
HIGH | 8.8 | The Stockholm theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.6. This … | — | wordfence |
| c30801d1-9335-4bba-b344-f0ff57cecf84 | < 7.0.8 |
HIGH | 8.8 | The Conversios β Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPre… | — | wordfence |
| c2fcf51d-ed21-4438-9179-07a56ed97251 | < 10.4.1 |
HIGH | 8.8 | The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,… | — | wordfence |
| c2a30bb9-501b-44bd-8121-c137bb1c3ae5 | < 1.5 |
HIGH | 8.8 | The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php. | — | wordfence |
| c2663150-61f9-49e3-9219-fbe89cc6b03c | < 3.2.8 |
HIGH | 8.8 | The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence |
| c248f11c-f381-4335-b6f7-bb18bbf1f7b0 | < 4.3.2 |
HIGH | 8.8 | The WP-Invoice β Web Invoice and Billing plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … | — | wordfence |
| c2421108-d4b0-480e-a020-95712cdfae8e | < 3.6.3 |
HIGH | 8.8 | The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due t… | — | wordfence |
| c237cfa7-1b55-4cca-91de-0fde3d598329 | HIGH | 8.8 | The WP Remote Thumbnail plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… | — | wordfence | |
| c232b39c-7144-4d3a-9770-883986ca8b29 | < 4.1.0 |
HIGH | 8.8 | The WooCommerce plugin for WordPress is vulnerable to arbitrary product meta data creation/overwriting due to a lack o… | — | wordfence |
| c22c2c17-c9c5-46eb-877a-a49ccf1a74ef | HIGH | 8.8 | The Rename Media Files plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including,… | — | wordfence | |
| c2151c87-0df3-477a-a1b2-7d2e5bc44eb5 | HIGH | 8.8 | The Minterpress plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escal… | — | wordfence | |
| c1d9ee9f-d8d0-4a9d-b414-bc79c4255b4e | < 2.3.2 |
HIGH | 8.8 | The Events Shortcodes & Templates For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the pl… | — | wordfence |
| c1d2b6bd-a75a-4a07-b2f0-8ec206d41211 | < 3.1.7 |
HIGH | 8.8 | The SupportCandy plugin for WordPress is vulnerable to SQL injection via the 'id' parameter used in the /wp-json/support… | — | wordfence |
| c19b0da5-db46-4a27-86a6-445dd9a3350d | < 4.2.3 |
HIGH | 8.8 | The KBucket: Your Curated Content in WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missi… | — | wordfence |
| c190c2d7-961b-4643-a7fe-6d4a22b0d5d7 | < 1.0.69 |
HIGH | 8.8 | The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action… | — | wordfence |
| c187ed25-6ba7-4a58-97df-5fea723d485a | < 0.9.5 |
HIGH | 8.8 | The W3 Total Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in v… | — | wordfence |
| c170a228-4abd-4ee6-ba37-bdcde1cb7fc5 | < 4.7.1 |
HIGH | 8.8 | The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to a missing file type validati… | — | wordfence |
| c1690fe3-f03f-4640-9948-2109d73a841c | < 8.0.0 |
HIGH | 8.8 | The WP Support Plus Responsive Ticket System plugin for WordPress is vulnerable to generic SQL Injection via the "$_POST… | — | wordfence |
| c16543db-2f8c-4266-9fb2-fc429f5647b6 | HIGH | 8.8 | The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logg… | — | wordfence | |
| c1621cd2-78d3-4429-862a-b425f5436f38 | < 3.9.001 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows re… | — | wordfence |
| c15eda1f-dc9f-4601-a337-ad3e66baf3b2 | < 1.3.7.1 |
HIGH | 8.8 | The WooCommerce Currency Switcher plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and incl… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →