Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1398 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| c6d2c4b4-8795-4252-bb43-4cfa4bc6fa06 | < 10.51 |
MEDIUM | 4.3 | The FluentSnippets β The High-Performance file based Custom Code Snippets Plugin plugin for WordPress is vulnerable to… | — | wordfence |
| c6c5bea1-c34d-428d-a77e-16cdd45fbc40 | < 2.0.9 |
MEDIUM | 4.3 | The Page Builder: Pagelayer β Drag and Drop website builder plugin for WordPress is vulnerable to Sensitive Informatio… | — | wordfence |
| c6c48173-ffe3-40f8-a2fa-cee66869e343 | < 2.0.1 |
MEDIUM | 4.3 | The All in One Time Clock Lite β Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to In… | — | wordfence |
| c6c236c0-95a4-479a-a154-d267ce2c0aba | MEDIUM | 4.3 | The Woocommerce Envato Affiliates plugin for WordPress is vulnerable to unauthorized access due to a missing capability … | — | wordfence | |
| c6b7447c-c61f-40c7-a423-877dcf3e6709 | < 1.40 |
MEDIUM | 4.3 | The PW WooCommerce On Sale! plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … | — | wordfence |
| c6ab1328-b5a0-4592-8455-0bc1874f2b3e | < 0.1.2.7 |
MEDIUM | 4.3 | The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… | — | wordfence |
| c69805c9-7e29-470c-b501-39b64d60367c | < 2.9.5 |
MEDIUM | 4.3 | The Ultimate Store Kit β Addon For WooCommerce, EDD and Elementor plugin for WordPress is vulnerable to unauthorized a… | — | wordfence |
| c67ee9bc-3626-4323-8b16-0fcae0db1991 | < 1.3.4 |
MEDIUM | 4.3 | The Nudgify Social Proof, Sales Popup & FOMO plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… | — | wordfence |
| c675f883-7e6f-43c3-a901-82ed2d2b3772 | < 1.8.7 |
MEDIUM | 4.3 | The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in it… | — | wordfence |
| c667be65-e6d3-40e1-aeec-384d309fde3d | < 16.26.12 |
MEDIUM | 4.3 | The WP-Recall β Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Information Exposure in a… | — | wordfence |
| c6451aaa-d4ef-4903-8e30-97dfee456d93 | < 1.3.4 |
MEDIUM | 4.3 | The Cron Logger plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… | — | wordfence |
| c63eb95c-cda6-4f88-8b23-5162663150c1 | MEDIUM | 4.3 | The Evergreen Post Tweeter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence | |
| c63e7dbb-af56-47b9-8206-5bef96754a38 | < 1.1.5 |
MEDIUM | 4.3 | The JobScout theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. Th… | — | wordfence |
| c63ddc62-a4f1-4da4-a65e-4573369d6c30 | < 1.0.7.5 |
MEDIUM | 4.3 | The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… | — | wordfence |
| c624e17f-66f8-4389-b922-b97c73b3c4a2 | < 3.5.29 |
MEDIUM | 4.3 | The MasterStudy LMS WordPress Plugin β for Online Courses and Education plugin for WordPress is vulnerable to unauthor… | — | wordfence |
| c61b5668-18d8-42e0-9ee3-d26ab7424350 | MEDIUM | 4.3 | The WP Category Post List Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… | — | wordfence | |
| c619cb36-7216-4a23-96d2-57d8142be4af | MEDIUM | 4.3 | The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users… | — | wordfence | |
| c61877f7-b037-4ddb-8f04-14c01268884b | < 4.1 |
MEDIUM | 4.3 | The Rootspersona plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence |
| c61093b0-6004-4f20-bea5-95c891f44a13 | < 1.3.0 |
MEDIUM | 4.3 | The Super Blank plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… | — | wordfence |
| c5fcbb61-5f22-4333-bdd9-7d843dd7e45a | < 1.8.1 |
MEDIUM | 4.3 | TablePress prior to version 1.8.1 allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vector… | — | wordfence |
| c5f30190-4576-4c2b-b069-72501538733b | < 3.9.7 |
MEDIUM | 4.3 | The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the m… | — | wordfence |
| c5f12e55-3608-415a-82ce-34781994111c | MEDIUM | 4.3 | The JAMstack Deployments plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on … | — | wordfence | |
| c5e65bba-e1eb-43b9-b3a6-7b8437692318 | MEDIUM | 4.3 | The Anything Order by Terms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … | — | wordfence | |
| c5decbb3-05a0-403f-918a-9b516df85778 | MEDIUM | 4.3 | The WP Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… | — | wordfence | |
| c5d96be2-b89a-46b0-a4f1-da44f9b54b2d | < 1.5.36 |
MEDIUM | 4.3 | The Page Builder: Live Composer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →