Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,407 vulnerabilities found (page 1403 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| c1a4d8a3-5553-4b1c-b0f8-d6a372de3692 | < 1.5.1.6 |
MEDIUM | 4.3 | The Landing Page Builder β Lead Page β Optin Page β Squeeze Page β WordPress Landing Pages plugin for WordPress … | — | wordfence |
| c1a0200f-9861-4eca-adbf-d458eb6b4e63 | < 3.1.2 |
MEDIUM | 4.3 | The Canto plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 3.1.1. This is due… | — | wordfence |
| c19b24ef-cf49-4a5c-a187-0f09ac53c337 | < 2.0.1 |
MEDIUM | 4.3 | The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in vers… | — | wordfence |
| c195c772-dd88-4e35-bd95-ca2d8bb6ddb5 | MEDIUM | 4.3 | The ts-tree plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in… | — | wordfence | |
| c191da68-d531-4c01-a364-2621c822dc80 | < 3.4.1 |
MEDIUM | 4.3 | The Tutor LMS β eLearning and online course solution plugin for WordPress is vulnerable to HTML Injection in all versi… | — | wordfence |
| c189bdcb-3b72-4e25-8444-6852444b89f7 | < 1.5.2 |
MEDIUM | 4.3 | The Sync Post With Other Site plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… | — | wordfence |
| c189a778-0338-408c-bcca-a0ac76d8eb44 | < 2.5.1 |
MEDIUM | 4.3 | The AutomatorWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.0… | — | wordfence |
| c1870c6e-23b6-4f3b-adba-72633d62dfd0 | < 1.9.8 |
MEDIUM | 4.3 | The SiteAlert (Formerly WP Health) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… | — | wordfence |
| c186d5eb-abc2-47bd-9d3c-2b2f24d2f87e | MEDIUM | 4.3 | The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… | — | wordfence | |
| c17ef8db-98ea-47b0-8d7f-b2b3f01bf6ec | < 3.4.0 |
MEDIUM | 4.3 | The Inline Related Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
| c17d7fba-7b98-4a7a-a35e-78f16be81aca | < 3.9.3 |
MEDIUM | 4.3 | The Sliced Invoices plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the s… | — | wordfence |
| c174887b-e24d-4100-97da-8e0923ebafe5 | MEDIUM | 4.3 | The jQuery Hover Footnotes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… | — | wordfence | |
| c16e1fdc-63b3-4af0-8327-23175191f4ee | < 5.4 |
MEDIUM | 4.3 | The Just Writing Statistics plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … | — | wordfence |
| c16b299e-a300-4d02-9ffe-52166d3791f4 | < 1.4.4 |
MEDIUM | 4.3 | The SureForms β Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access due… | — | wordfence |
| c1520cce-4ed7-4815-9023-4a994200601a | < 4.5.2 |
MEDIUM | 4.3 | The Sensei LMS plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.5.1. This… | — | wordfence |
| c1466b0c-0476-48f7-8817-f2951a8fe78b | MEDIUM | 4.3 | The Flo Forms β Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missi… | — | wordfence | |
| c132cfc1-03b3-4616-9a66-871e88c857cb | < 2.0.1 |
MEDIUM | 4.3 | The WP To Do plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.… | — | wordfence |
| c12c7f08-5132-4209-ae4e-fb67bf885e57 | < 2.15.0 |
MEDIUM | 4.3 | The Tourfic plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… | — | wordfence |
| c12094bd-aa23-4f9b-92e1-d1d4284fb2a0 | < 1.4.4 |
MEDIUM | 4.3 | The Elementor Addons, Widgets and Enhancements β Stax plugin for WordPress is vulnerable to Cross-Site Request Forgery… | — | wordfence |
| c0ef3ae7-b3c0-4f54-a95d-9f8cf9497d8f | < 2.4.5 |
MEDIUM | 4.3 | The Homey theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th… | — | wordfence |
| c0ed65f8-a2af-476e-a3f5-51f7b01724f2 | < 4.9.6 |
MEDIUM | 4.3 | The WpStream β Live Streaming, Video on Demand, Pay Per View plugin for WordPress is vulnerable to unauthorized access… | — | wordfence |
| c0d8ac01-ac73-47ea-839b-edc820436f27 | < 3.11.19 |
MEDIUM | 4.3 | The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient user v… | — | wordfence |
| c0c8d882-32e7-4aa5-8428-f3ce7924ab54 | MEDIUM | 4.3 | The Table Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence | |
| c0c44335-5d05-48cb-a3a2-574d65f02866 | < 3.0.9 |
MEDIUM | 4.3 | The Newspack Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … | — | wordfence |
| c0c13b83-6885-46db-bf33-0b2b63ff06db | < 1.9.4 |
MEDIUM | 4.3 | The Contact Form 7 β PayPal & Stripe Add-on plugin for WordPress is vulnerable to Cross-Site Request Forgery in versio… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →