Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,758 vulnerabilities found (page 28 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| cb2e9370-f50e-4792-99f6-4678e0256a56 | < 3.0.61 |
CRITICAL | 9.8 | The Gallery Bank – WordPress Photo Gallery Plugin for WordPress is vulnerable to arbitrary file uploads due to missing… | — | wordfence |
| cb1626ae-cf58-4377-ab4f-58e4536825fe | CRITICAL | 9.8 | The Foodbakery Sticky Cart plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, … | — | wordfence | |
| cb102a58-2fc0-4441-8f51-a6109e323878 | < 1.1 |
CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow re… | — | wordfence |
| cb03eb79-27c9-4a9d-b690-71946e11f39f | < 5.4.4 |
CRITICAL | 9.8 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, … | — | wordfence |
| cae6e8b9-a8a9-41d3-83e8-d833515a0244 | < 3.2 |
CRITICAL | 9.8 | The Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics plugin for WordPress is vulnerable to PHP O… | — | wordfence |
| cadd47e9-1d5b-4f04-8421-7707dad53ea6 | < 0.91 |
CRITICAL | 9.8 | The Google Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.90 via d… | — | wordfence |
| cadb77be-1b57-4c05-8fb2-cc5916a215a4 | CRITICAL | 9.8 | The My Geo Posts Free plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2 v… | — | wordfence | |
| caa1a42a-6bb2-42c8-aae7-fb1c895573a8 | < 5.0.4 |
CRITICAL | 9.8 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions… | — | wordfence |
| ca868ec4-9d28-4edd-b31c-a8546f9ced9e | CRITICAL | 9.8 | The FAT Event Lite plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1. Thi… | — | wordfence | |
| ca3775db-0722-4090-924e-81e38d5dce97 | CRITICAL | 9.8 | The Extensions by HocWP Team plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin… | — | wordfence | |
| ca2b6f6e-4cc0-40ae-8969-c82c5a231f41 | < 5.1.94 |
CRITICAL | 9.8 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Local File I… | — | wordfence |
| ca1d5275-3398-47a7-889b-4050ebe635ee | < 2.1.7 |
CRITICAL | 9.8 | The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … | — | wordfence |
| ca02cd21-e278-478e-80e8-18ff51f6ed10 | < 1.6.7 |
CRITICAL | 9.8 | The Car Dealer theme for WordPress is vulnerable to PHP Object Injection in versions up to, and excluding, 1.6.7 via des… | — | wordfence |
| c9fb3480-f83a-4cf1-873e-4a938805666b | CRITICAL | 9.8 | The AJAX Random Posts plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.3.3… | — | wordfence | |
| c9f4760c-a794-43e0-80a3-88b3f41810f5 | < 1.2.0 |
CRITICAL | 9.8 | A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 1.2.0 for WordP… | — | wordfence |
| c9cd43f5-c3d0-4eb2-9c18-1af2edca37ff | CRITICAL | 9.8 | The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the reg… | — | wordfence | |
| c9a5f8ca-7efc-401b-8a93-07fbe7204dce | < 3.1 |
CRITICAL | 9.8 | The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path vali… | — | wordfence |
| c97b31bc-75d6-40af-bf4a-714ea69d2c28 | CRITICAL | 9.8 | The Easy Career Openings plugin for WordPress is vulnerable to SQL Injection via the ‘jobid’ parameter in versions u… | — | wordfence | |
| c978a252-1f77-4c8d-b51a-04ed3493ee34 | CRITICAL | 9.8 | The Dynamic Font Replacement DFR4WP EN plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ para… | — | wordfence | |
| c96507cf-3c2d-4516-92f5-d08384aa6b1a | < 2.8.1 |
CRITICAL | 9.8 | The WORDPRESS VIDEO GALLERY Plugin for WordPress is vulnerable to SQL Injection via the ‘vid' parameter in versions up… | — | wordfence |
| c959fac5-d881-403d-85e0-edf4cb1be02e | CRITICAL | 9.8 | Multiple plugins and/or themes for WordPress are vulnerable to Privilege Escalation in various versions. This is due to … | — | wordfence | |
| c8e634ef-b496-40cd-ab20-32f68c0be7ee | < 4.2 |
CRITICAL | 9.8 | The ARPrice plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.1.3 via deser… | — | wordfence |
| c8de9ce3-c96a-4fe5-a1f9-8019ca13cc11 | < 1.4.6 |
CRITICAL | 9.8 | The Sigma Forms Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence |
| c89b4177-2e8b-4124-9517-6a1ff6830308 | < 4.5.1 |
CRITICAL | 9.8 | The couponxl theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.5.0. This… | — | wordfence |
| c880470f-3f81-47a2-b450-7074410e9f43 | < 1.0.5 |
CRITICAL | 9.8 | The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →