Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1393 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| cd1fc89f-b0f0-43a3-a311-07a79232a3ea | < 7.2.8 |
MEDIUM | 4.3 | The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attack… | — | wordfence |
| cd132aa5-d30a-41de-aa8d-aefae6c95c47 | < 4.0.3 |
MEDIUM | 4.3 | The Aurum - WordPress & WooCommerce Shopping Theme theme for WordPress is vulnerable to unauthorized modification of dat… | — | wordfence |
| cd0fe8d5-ff39-44b3-91ce-8fd211fdbaea | MEDIUM | 4.3 | The Ai Image Alt Text Generator for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi… | — | wordfence | |
| cd0abdf2-24da-4e87-825b-0796af6c3ccd | MEDIUM | 4.3 | The Remove/hide Author, Date, Category Like Entry-Meta plugin for WordPress is vulnerable to Cross-Site Request Forgery … | — | wordfence | |
| cd01d83e-a337-4f93-8bd0-0c9f3c786583 | MEDIUM | 4.3 | The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could al… | — | wordfence | |
| ccf77cb1-b6b6-49de-8de4-20eddd3b5e62 | < 8.3.7 |
MEDIUM | 4.3 | The Media Library Folders plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, … | — | wordfence |
| cce48da9-9c9b-49ef-bc03-371cb0e99242 | < 1.1.8 |
MEDIUM | 4.3 | The Custom Login Logo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… | — | wordfence |
| ccc1dd7b-61f3-4358-bbf8-75f44200d3b1 | < 1.2.5 |
MEDIUM | 4.3 | The Activity Log WinterLock plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … | — | wordfence |
| ccbf6d57-44ba-4064-8880-81cd9136ca33 | < 4.0.8 |
MEDIUM | 4.3 | The Widget Options plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wi… | — | wordfence |
| ccb34b44-9fa4-4ebe-b217-b2a42920247f | < 3.4.2 |
MEDIUM | 4.3 | The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… | — | wordfence |
| ccaba382-7fe8-4197-bec4-87c35d9a7a81 | < 1.0.2 |
MEDIUM | 4.3 | The Notify Odoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… | — | wordfence |
| cca71257-05dc-43d5-8de6-faf0a2feab2e | < 1.4.5 |
MEDIUM | 4.3 | The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forger… | — | wordfence |
| cc9dd55d-3c37-4f24-81a1-fdc8ca284566 | < 3.1.14 |
MEDIUM | 4.3 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to … | — | wordfence |
| cc9935d8-7790-457b-88bf-bee5e13b0f5a | < 5.5.6 |
MEDIUM | 4.3 | The Ivory Search β WordPress Search Plugin plugin for WordPress is vulnerable to unauthorized modification of data due… | — | wordfence |
| cc97109c-187f-43b7-b5ed-5afeec5ea8fd | MEDIUM | 4.3 | The Clock In Portal plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… | — | wordfence | |
| cc727156-28dc-4b0a-b777-52a1bbc72f79 | MEDIUM | 4.3 | The AccessPress Anonymous Post plugin for WordPress is vulnerable to Arbitrary Redirect in versions up to, and including… | — | wordfence | |
| cc6b521b-32a4-40a2-bb4e-c0c7642693c9 | < 4.0.6 |
MEDIUM | 4.3 | The Nelio Content plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… | — | wordfence |
| cc65d444-741d-4d27-84a8-07d916caf0e4 | MEDIUM | 4.3 | The Pricing Table builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence | |
| cc588948-151d-4bdb-96a2-cdfde2cb0965 | < 5.11.1 |
MEDIUM | 4.3 | The WP Job Board plugin for WordPress is vulnerable to Directory Traversal in all versions up to 5.11.1 (exclusive). Thi… | — | wordfence |
| cc5754c2-a052-41ac-af19-7c4f55860f95 | < 5.1 |
MEDIUM | 4.3 | The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all vers… | — | wordfence |
| cc4ec554-f7f5-4c0a-9f86-8d5c74bfe0ab | < 2.16.2.1 |
MEDIUM | 4.3 | The Knowledge Base documentation & wiki plugin β BasePress plugin for WordPress is vulnerable to unauthorized access d… | — | wordfence |
| cc490eea-455d-46f1-bbb1-d57af8ab5e74 | < 2.5.4 |
MEDIUM | 4.3 | The WPGraphQL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.3. … | — | wordfence |
| cc33b2fc-291a-49d5-8fe7-7bf4e9ebab5d | < 3.8.3 |
MEDIUM | 4.3 | The Mobile App Canvas β Convert your Website Into an App for iOS and Android plugin for WordPress is vulnerable to una… | — | wordfence |
| cc0af0a4-81b5-425e-aba3-0c422aa33634 | MEDIUM | 4.3 | The WP DB Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… | — | wordfence | |
| cc03b3f4-2edb-463b-812b-6a187a7a893c | < 1.95.0.3 |
MEDIUM | 4.3 | The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →