Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1394 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| cc0087a8-ec3a-4c16-8ce3-d346ae0ca58d | < 8.2.1 |
MEDIUM | 4.3 | The WP Customer Area plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check… | — | wordfence |
| cbff7ec1-535d-43bf-be61-83a1e7625c77 | < 3.2.5 |
MEDIUM | 4.3 | The Top 10 β Popular posts plugin for WordPress is vulnerable to insufficient access control in the 'tptn_chart_data' … | — | wordfence |
| cbfd8d72-ce1a-4366-9d1b-13c8c5fe8b71 | < 1.0.253 |
MEDIUM | 4.3 | The Rank Math SEO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the tra… | — | wordfence |
| cbe7a209-d5c8-4616-bdcb-c52569231774 | < 2.8.4.4 |
MEDIUM | 4.3 | The WP Mobile Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… | — | wordfence |
| cbdfe58e-1e09-41b6-8ac9-6976c27aa58d | < 3.2.17 |
MEDIUM | 4.3 | The Strong Testimonials plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and i… | — | wordfence |
| cbcf3487-c1d4-4173-b197-1dd381990eb7 | MEDIUM | 4.3 | The WP Emoji One plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.… | — | wordfence | |
| cbc05086-e7ba-4139-a294-52a19ffc8b93 | < 3.3.202 |
MEDIUM | 4.3 | The Zephyr Project Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… | — | wordfence |
| cbbf9fbb-74fd-42eb-a781-2a720fe56b13 | < 6.20.02 |
MEDIUM | 4.3 | The WP Compress β Image Optimizer [All-In-One plugin for WordPress is vulnerable to Open Redirect in all versions up t… | — | wordfence |
| cbba781f-c710-4360-a4ed-21a8f7350bb9 | MEDIUM | 4.3 | The Database to Excel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… | — | wordfence | |
| cbb8501e-7e8b-4ed6-8792-c685a69de982 | < 5.0.6 |
MEDIUM | 4.3 | The Slimstat Analytics plugin for WordPress is vulnerable to unauthorized PageView Deletion due to a missing capability … | — | wordfence |
| cbb5e80a-4dfe-429c-96c1-7fab52e0ce21 | < 1.4.3 |
MEDIUM | 4.3 | The Contact Form Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence |
| cbb0f6cf-c41d-4e54-addd-3f2454d02152 | < 4.23.0 |
MEDIUM | 4.3 | The KALLYAS - Creative eCommerce Multi-Purpose WordPress Theme theme for WordPress is vulnerable to unauthorized access … | — | wordfence |
| cbaf06b2-9ac3-4882-9212-fdcecdc5fb8c | < 3.99 |
MEDIUM | 4.3 | The Memory Usage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence |
| cb879587-6210-4e23-8f02-9ce93a271962 | < 4.24.16 |
MEDIUM | 4.3 | The Flexible Shipping plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… | — | wordfence |
| cb7ec7ad-797b-4a5c-9b1c-31284083faef | < 2.25.2 |
MEDIUM | 4.3 | The GiveWP plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.1. This is due to m… | — | wordfence |
| cb5cb1a5-30d2-434f-90f9-d37aecfbe158 | < 3.9.7 |
MEDIUM | 4.3 | The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the m… | — | wordfence |
| cb427792-8675-4c38-a4e6-ba2b8091003f | < 4.2.3 |
MEDIUM | 4.3 | The TinyMCE Advanced plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| cb3d8d70-a965-4ef7-9b03-f64cb0fdbf8f | MEDIUM | 4.3 | The Zajax β Ajax Navigation plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… | — | wordfence | |
| cb3157b3-0ba1-4471-a3d7-bab65c68a611 | < 8.4.2 |
MEDIUM | 4.3 | The Stripe Payment Forms by WP Full Pay β Accept Credit Card Payments, Donations & Subscriptions plugin for WordPress … | — | wordfence |
| cb18d6d8-28e5-4125-9209-a71403f678f0 | < 1.0.2 |
MEDIUM | 4.3 | The Form Block plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1.… | — | wordfence |
| caff9be6-4161-47a0-ba47-6c8fc0c4ab40 | < 2.6.0 |
MEDIUM | 4.3 | The WP 2FA β Two-factor authentication for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Refe… | — | wordfence |
| caf61bf9-4b0f-450a-b571-b0fec42e9e39 | < 1.2.7 |
MEDIUM | 4.3 | The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, whic… | — | wordfence |
| cad19306-6eef-4f80-9442-e7b314b3a873 | MEDIUM | 4.3 | The Bulk Edit Post Titles plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… | — | wordfence | |
| cacd9237-a330-4927-ac53-ee86b9ac8289 | < 4.7.10 |
MEDIUM | 4.3 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized access due to a mis… | — | wordfence |
| cac1c1fa-7d6c-43c3-885e-9be320cb8f83 | < 4.7.34 |
MEDIUM | 4.3 | WordPress Core is vulnerable to an Email Change Confirmation Bypass in all versions up to, and including, 7.0.2 due to i… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →