Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 28 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| c754d957-26a8-4fef-a487-96d566c2dc36 | < 6.6.8 |
CRITICAL | 9.8 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary … | — | wordfence |
| c74ce3e8-cab9-4cc6-a1ad-1e51f7268474 | < 2.17.1 |
CRITICAL | 9.8 | The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all ve… | — | wordfence |
| c7476f2c-c32f-4ff7-ad32-70cf68387342 | < 2.76 |
CRITICAL | 9.8 | The Disqus Comment System plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, … | — | wordfence |
| c741350a-e083-499c-992d-727f46ca57f9 | < 1.1.2 |
CRITICAL | 9.8 | The simple-login-log plugin before 1.1.2 for WordPress has SQL injection via the 'order' parameter in the get_results fu… | — | wordfence |
| c726d8f0-7f2a-414b-9d73-a053921074d9 | < 3.9.1 |
CRITICAL | 9.8 | The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This… | — | wordfence |
| c7214f90-a205-4d7e-94c8-ee07515ebbf1 | < 1.4.7 |
CRITICAL | 9.8 | The Material Dashboard plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, … | — | wordfence |
| c6f68bfd-36c3-45f5-a50b-6803b5967e52 | CRITICAL | 9.8 | The Download from files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… | — | wordfence | |
| c6ef0c41-e498-4de6-a86a-d23f65a7a824 | < 1.0.9 |
CRITICAL | 9.8 | controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users… | — | wordfence |
| c6ee9437-a12a-476b-9a4b-8da8d9fbfeb3 | < 5.2.13 |
CRITICAL | 9.8 | The Fluent Forms Pro in version 6.2.7 and the Ninja Tables Pro in version 5.2.13 plugins for WordPress are vulnerable to… | — | wordfence |
| c6a0811e-f02b-49d1-915e-cf7ac4b5e1f5 | CRITICAL | 9.8 | The Power Zoomer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via th… | — | wordfence | |
| c6a02da1-b005-4fa9-9657-1c5f019f3858 | < 2.0.8 |
CRITICAL | 9.8 | The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the '*_ordering' parameter in all versions … | — | wordfence |
| c6998185-0f9b-48ab-9dca-05adf5ae603a | CRITICAL | 9.8 | The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerabl… | — | wordfence | |
| c691d129-35db-4de8-a28e-5e77347e2280 | < 1.15.20 |
CRITICAL | 9.8 | The Form Maker by 10Web plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valid… | — | wordfence |
| c66d88a1-0936-40c4-adcf-ad79b9c57a80 | < 4.4.3 |
CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to exec… | — | wordfence |
| c63048ad-3d37-402e-8e61-415d2d6caa69 | CRITICAL | 9.8 | The Form Lightbox plugin for WordPress is vulnerable to arbitrary option updates due to a missing capability check in th… | — | wordfence | |
| c62d8146-e4b1-4c86-9d8a-c3a9bbfb0763 | < 1.1.60 |
CRITICAL | 9.8 | The Profile Builder – User Profile & User Registration Forms Plugin for WordPress is vulnerable to authentication bypa… | — | wordfence |
| c5fee6e4-b985-4190-953b-133bc90e47da | < 1.6 |
CRITICAL | 9.8 | The Freshmail plugin for WordPress is vulnerable to Multiple SQL Injections via the 'include/wp_ajax_fm_form.php' and 'i… | — | wordfence |
| c5c17dea-7b61-4e73-ac61-3fe536c22962 | < 2.1.66 |
CRITICAL | 9.8 | The WooCommerce Products Vendor plugin for WordPress is vulnerable to blind SQL Injection via the ‘s_postcode’ param… | — | wordfence |
| c5bd11c6-2f55-4eee-834a-c4e405482b9c | < 5.7.24 |
CRITICAL | 9.8 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin… | — | wordfence |
| c5bc757d-2495-4be2-bccd-d4090e66ced4 | CRITICAL | 9.8 | The Fresh Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.… | — | wordfence | |
| c5ada976-03b8-4219-9ae3-9060fb7b9de5 | < 1.7 |
CRITICAL | 9.8 | The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to … | — | wordfence |
| c5a5c209-0ccd-4fa9-b22d-05bb22247441 | < 2.1.6 |
CRITICAL | 9.8 | The OneLogin SAML-SSO plugin for WordPress is vulnerable to authentication bypass due to insufficient user validation in… | — | wordfence |
| c58d5a57-6b87-4a39-b995-c86fbc779565 | < 3.2.11 |
CRITICAL | 9.8 | A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful explo… | — | wordfence |
| c5757abd-33dc-4751-bc55-afd944ff2341 | < 1.3.0 |
CRITICAL | 9.8 | The Duplicator – WordPress Migration & Backup Plugin plugin for WordPress is vulnerable to Remote Code Execution in al… | — | wordfence |
| c5519d4e-84b5-4901-b55c-a0a919f4b6c9 | < 1.0.6.1 |
CRITICAL | 9.8 | The Active Products Tables for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →