Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 136 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| c13f370b-c9f6-4e58-b6a7-6aa03a0ed5cd | HIGH | 8.8 | The Open Close WooCommerce Store plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inclu… | — | wordfence | |
| c1197d19-e49f-4d44-8efe-ef8d7e91bce0 | HIGH | 8.8 | The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not … | — | wordfence | |
| c10a5583-5273-4b94-8e2e-e3d24ea941b0 | < 2.1.4.6 |
HIGH | 8.8 | The InPost Gallery plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.4.5.… | — | wordfence |
| c0eae97c-d7e5-4dde-a323-d90a20826341 | < 5.6.1 |
HIGH | 8.8 | The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF. | — | wordfence |
| c0d68506-ee5c-4b01-a0d2-caf2482106e0 | < 1.2.3 |
HIGH | 8.8 | The wp-rollback plugin before 1.2.3 for WordPress has CSRF. | — | wordfence |
| c0ce3a76-5e16-4772-a802-9e5ce1345f95 | HIGH | 8.8 | The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF. | — | wordfence | |
| c0c74d48-6cfc-4899-bd2c-4a80b1f6e05f | HIGH | 8.8 | The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3… | — | wordfence | |
| c0a2a379-bd33-4c7d-8b79-e48a2df7e281 | < 1.3.6 |
HIGH | 8.8 | The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the order… | — | wordfence |
| c09f9f61-c25f-49dc-a97c-8e145e1141b6 | < 2.3.15 |
HIGH | 8.8 | The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and i… | — | wordfence |
| c07ea205-5a05-43f5-993e-c6e30f660ac8 | < 2.2.41 |
HIGH | 8.8 | The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation v… | — | wordfence |
| c062d60b-eda8-4039-8655-64f32e70839a | < 3.1.5 |
HIGH | 8.8 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection… | — | wordfence |
| c042b347-2884-436d-abd3-6931548f18d6 | < 2.2 |
HIGH | 8.8 | The Shopper Approved Reviews plugin for WordPress is vulnerable to unauthorized modification of data that can lead to pr… | — | wordfence |
| c03e74c5-ad32-4651-a55a-cc8d89b8a991 | HIGH | 8.8 | The Hillter theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.7 via deseri… | — | wordfence | |
| c0363732-0a67-4a58-9b54-6315328c70ec | HIGH | 8.8 | The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allow… | — | wordfence | |
| c01bce24-3563-40bd-83c5-8d54bd622151 | < 1.0.1 |
HIGH | 8.8 | The "Ultimate WordPress Auction Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions bef… | — | wordfence |
| c000a424-4060-4dcc-bae3-fa8cfc00ddda | < 1.4.4 |
HIGH | 8.8 | The Per page add to head WordPress plugin before 1.4.4 is lacking any CSRF check when saving its settings, which could a… | — | wordfence |
| bff9866e-3967-426e-9b8d-17b317aac7a3 | < 1.9.9.5.2 |
HIGH | 8.8 | The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versio… | — | wordfence |
| bff3a160-5238-4478-ab11-3300cac51cf2 | < 2.20.7 |
HIGH | 8.8 | The ArtPlacer Widget plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions up to, and i… | — | wordfence |
| bfeb5a08-4aad-421b-9e50-68dd84adc396 | < 3.7.59 |
HIGH | 8.8 | The Challan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.58. T… | — | wordfence |
| bfc62289-9ac0-4aeb-96ac-010af6f437a6 | < 1.9.9.5.2 |
HIGH | 8.8 | The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versio… | — | wordfence |
| bfc04273-0d72-4b18-bcb5-eb1530aefcc0 | < 2.12 |
HIGH | 8.8 | The WordPress User Registration Forms by Formidable Forms plugin for WordPress is vulnerable to arbitrary user password … | — | wordfence |
| bfb53b61-f476-4b92-b87a-de10e18428a3 | < 1.1.4 |
HIGH | 8.8 | The GoDaddy Email Marketing plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.1.4. T… | — | wordfence |
| bf893b1e-9fcf-4a3a-862e-4f050617acc6 | < 2.9 |
HIGH | 8.8 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plu… | — | wordfence |
| bf50922a-58a6-4ca4-80b7-cafb37b87216 | HIGH | 8.8 | The Horizontal scrolling announcement plugin for WordPress is vulnerable to SQL Injection via the plugin's [horizontal-s… | — | wordfence | |
| bf152269-73e1-473f-8d97-ce94e9b885d0 | HIGH | 8.8 | The 'Videospirecore Theme Plugin' plugin for WordPress is vulnerable to privilege escalation via account takeover in all… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →