Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 26 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| cd3a7af1-0cae-4872-9e61-58e9a9e3eda5 | < 4.1.7 |
CRITICAL | 9.8 | The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious ac… | — | wordfence |
| cd328738-7467-4f30-83bb-9e1c836fa940 | < 6.00.03 |
CRITICAL | 9.8 | SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to e… | — | wordfence |
| cd28ac3c-aaef-49e3-843d-8532404703c9 | < 5.0.0 |
CRITICAL | 9.8 | The Export WP Page to Static HTML & PDF plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers… | — | wordfence |
| cd00d716-535c-41eb-a766-82079e0060e6 | < 3.4 |
CRITICAL | 9.8 | The Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and in… | — | wordfence |
| cccbdb49-d423-4955-a078-ae0acdb79804 | CRITICAL | 9.8 | SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress … | — | wordfence | |
| cc748d31-b8e6-44b6-af30-944c0b0f1f0c | < 0.1.14 |
CRITICAL | 9.8 | The Omni Secure Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation v… | — | wordfence |
| cc742fa0-7d10-4fe4-b95c-7d4ca563d402 | < 6.7.2 |
CRITICAL | 9.8 | The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel. | — | wordfence |
| cc550fd9-c332-4a40-b4a9-166d5ffebc76 | CRITICAL | 9.8 | The My Geo Posts Free plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2 v… | — | wordfence | |
| cc2f8da1-7503-45e3-8a7d-0031ce264edf | CRITICAL | 9.8 | The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress the… | — | wordfence | |
| cc26d20e-3ecd-438e-a123-5015ecc17290 | < 4.6.1 |
CRITICAL | 9.8 | The videowhisper-video-presentation plugin 4.1.4 and below for WordPress allows remote attackers to execute arbitrary co… | — | wordfence |
| cc1cf03f-265c-4cb5-b32b-8039b9e5da2a | < 6.9.0 |
CRITICAL | 9.8 | The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX a… | — | wordfence |
| cc0fbe84-e455-4e62-9c48-49340d08f81d | CRITICAL | 9.8 | The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, a… | — | wordfence | |
| cc01bb79-67cd-40d8-b0e0-1853df1aa3c4 | CRITICAL | 9.8 | The Product Catalog 8 plugin for WordPress is vulnerable to SQL Injection via the ‘selectedCategory’ parameter in ve… | — | wordfence | |
| cbbaa4bd-6460-4f2b-afb5-6bb973443902 | CRITICAL | 9.8 | The Fitrush theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.4. This make… | — | wordfence | |
| cb866476-14c0-4ade-90b0-670418b397fb | CRITICAL | 9.8 | The Webapp builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t… | — | wordfence | |
| cb7ee61d-2f2c-4e5e-891e-e8b7a5cd29fa | CRITICAL | 9.8 | The Grip theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.9. This makes i… | — | wordfence | |
| cb603be6-4a12-49e1-b8cc-b2062eb97f16 | < 6.72 |
CRITICAL | 9.8 | The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugi… | — | wordfence |
| cb5d3d64-a465-4c26-9cf7-7acc7dab862a | CRITICAL | 9.8 | The Spicy Blogroll plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.0 vi… | — | wordfence | |
| cb55be41-c3aa-4f1e-9330-a31181a3a264 | < 2.5.4 |
CRITICAL | 9.8 | The Shibboleth plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… | — | wordfence |
| cb334b74-5561-4ac7-b321-397600e26d06 | < 1.4.4 |
CRITICAL | 9.8 | The Motors – Car Dealer, Classifieds & Listin plugin for WordPress is vulnerable to arbitrary file uploads due to miss… | — | wordfence |
| cb2e9370-f50e-4792-99f6-4678e0256a56 | < 3.0.61 |
CRITICAL | 9.8 | The Gallery Bank – WordPress Photo Gallery Plugin for WordPress is vulnerable to arbitrary file uploads due to missing… | — | wordfence |
| cb1626ae-cf58-4377-ab4f-58e4536825fe | CRITICAL | 9.8 | The Foodbakery Sticky Cart plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, … | — | wordfence | |
| cb102a58-2fc0-4441-8f51-a6109e323878 | < 1.1 |
CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow re… | — | wordfence |
| cae6e8b9-a8a9-41d3-83e8-d833515a0244 | < 3.2 |
CRITICAL | 9.8 | The Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics plugin for WordPress is vulnerable to PHP O… | — | wordfence |
| cadd47e9-1d5b-4f04-8421-7707dad53ea6 | < 0.91 |
CRITICAL | 9.8 | The Google Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.90 via d… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →