Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 25 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| cff74b3d-f056-4e9f-a62d-a3d79b4f4d56 | < 3.1 |
CRITICAL | 9.8 | The Car Rental System plugin for WordPress is vulnerable to blind SQL Injection via the ‘pickuploc’ and 'dropoff' pa… | — | wordfence |
| cfe5d24a-a2ed-46c1-8d9b-9bd2c63cb8b3 | CRITICAL | 9.8 | The MoveTo plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including… | — | wordfence | |
| cfd32e46-a4fc-4c10-b546-9f9da75db791 | < 2.3.8 |
CRITICAL | 9.8 | The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is … | — | wordfence |
| cf85ddc7-cb90-4502-9936-f2c51030b4a6 | CRITICAL | 9.8 | The Disc Golf Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.0… | — | wordfence | |
| cf851bed-f5d8-44e2-810d-906ba3d3c1c5 | < 33.0.16 |
CRITICAL | 9.8 | The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads… | — | wordfence |
| cf3df923-9426-4e5b-ba59-eda0b5c18d40 | < 2.3.1 |
CRITICAL | 9.8 | The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1… | — | wordfence |
| cf34eb9f-f6e9-4a7a-8459-c86f9fa3dad8 | < 1.7.27 |
CRITICAL | 9.8 | The Login with phone number plugin for WordPress is vulnerable to authentication bypass in versions up to, and including… | — | wordfence |
| cf24216c-7882-4359-b526-44d845de0249 | CRITICAL | 9.8 | The EZPZ One Click Backup (ezpz-one-click-backup) plugin 12.03.10 and earlier for WordPress allows remote attackers to e… | — | wordfence | |
| cf159a11-9490-4f79-a62d-c279cfe26108 | CRITICAL | 9.8 | The Ripe HD FLV plugin for WordPress is vulnerable to generic SQL Injection via the 'id' parameter in the 'config.php' f… | — | wordfence | |
| cef83a3e-9e8b-4c4c-9adc-cdcebefadd39 | CRITICAL | 9.8 | The Image Gallery with Slideshow plugin for WordPress is vulnerable to generic SQL Injection via the ‘gid’ parameter… | — | wordfence | |
| cecffd72-4597-4308-9f21-4731269e8cf1 | < 3.45 |
CRITICAL | 9.8 | A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitat… | — | wordfence |
| cece751c-400d-42b4-9438-950d5aca51fc | < 3.0.4 |
CRITICAL | 9.8 | The AIT CSV import/export plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… | — | wordfence |
| ce8ec66f-5efc-4354-8871-8e35ab4e51fc | < 1.6.2 |
CRITICAL | 9.8 | The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions u… | — | wordfence |
| ce834ae1-e05a-4b0e-9d7f-144669437d70 | < 1.7.7 |
CRITICAL | 9.8 | The Caldera Forms Pro plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on th… | — | wordfence |
| ce544dd0-6e4a-4a73-bba0-db2d667e378e | < 3.1.2 |
CRITICAL | 9.8 | The Pie Register plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions before 3.1.2 d… | — | wordfence |
| ce4c4395-6d1a-4d5f-885f-383e5c44c0f8 | < 2.7.1 |
CRITICAL | 9.8 | The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due … | — | wordfence |
| ce3ae202-1227-4247-9133-5c7284392c9f | < 2.0.0 |
CRITICAL | 9.8 | The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin fo… | — | wordfence |
| ce38401f-443b-42b8-ae4e-53700f25bee7 | < 1.6.11 |
CRITICAL | 9.8 | The Seofy Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.8. This … | — | wordfence |
| ce332037-bfa3-42a6-a352-ba13439db62f | < 1.0.53.1 |
CRITICAL | 9.8 | The Capie theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.40. This makes… | — | wordfence |
| ce119965-01a0-4cff-a0b2-e99bceb1406c | < 6.6.8 |
CRITICAL | 9.8 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File… | — | wordfence |
| ce0dcbe6-9231-45d9-9658-5d775e02cfcb | < 4.1.1 |
CRITICAL | 9.8 | The Estatik Real Estate Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc… | — | wordfence |
| cdbf2658-b819-4fd3-ac89-8b90a7e3a2cf | < 7.11 |
CRITICAL | 9.8 | The Social Share, Social Login and Social Comments plugin for WordPress is vulnerable to authorization bypass due to a m… | — | wordfence |
| cdb35927-b239-4243-a2d0-2e2c2cc61668 | < 1.5.0 |
CRITICAL | 9.8 | The WP Fundraising Donation and Crowdfunding Platform WordPress plugin through 1.4.2 does not sanitise and escape a para… | — | wordfence |
| cd8a45c9-ca48-4ea6-b34e-f05206f16155 | < 1.8.90 |
CRITICAL | 9.8 | The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… | — | wordfence |
| cd4f7b73-947b-4962-9880-5f279580f43c | < 3.20.0 |
CRITICAL | 9.8 | The Yith WooCommerce Gift Cards Premium plugin for WordPress is vulnerable to arbitrary file uploads due to missing file… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →