Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 285 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| cee0fbbb-64eb-4022-8220-dfcc5c37aa40 | HIGH | 7.5 | The WP JobHunt plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi… | — | wordfence | |
| ce047db1-b701-4903-9244-68b3ecaad78f | < 2.4.9 |
HIGH | 7.5 | common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not con… | — | wordfence |
| ce032abe-ee9d-4be1-ac97-5fa95d598e85 | < 2.6 |
HIGH | 7.5 | The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2… | — | wordfence |
| cdcae7fe-1cc1-4168-8b4b-fcee5bf91be2 | < 2.5.5 |
HIGH | 7.5 | The Booking and Rental Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includi… | — | wordfence |
| cdbbccc5-07e5-48fb-8242-cd100a76eb9f | < 3.2.0 |
HIGH | 7.5 | The Amely theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.4 due to insufficient… | — | wordfence |
| cdac6080-5e23-488d-8b3c-de0c6c92e344 | < 3.2 |
HIGH | 7.5 | The Service Finder - Provider and Business Listing theme for WordPress is vulnerable to Path Traversal in versions up to… | — | wordfence |
| cd9eb6e5-5566-4a11-bcca-26c166a5b4c5 | HIGH | 7.5 | The Download Counter plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.4… | — | wordfence | |
| ccf7ecf9-4e73-437d-98c2-be9ff3f1cdb6 | HIGH | 7.5 | The CHATLIVE plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.1 due to insuffic… | — | wordfence | |
| ccced656-0907-48d2-a8ab-32ac86c1e6c9 | HIGH | 7.5 | The Easy Guide plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.0 due to insuff… | — | wordfence | |
| ccb24a6d-5df4-4b56-b63a-353ad41e7f1c | < 1.0.11 |
HIGH | 7.5 | The Antideo Email Validator plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.10… | — | wordfence |
| cc42ac65-969a-476d-993e-7d8bc2b4fa96 | < 2.2 |
HIGH | 7.5 | The Method Theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.1. This is d… | — | wordfence |
| cc3cf6c5-643e-49ca-b09c-bd7cfec328ee | < 1.13.19 |
HIGH | 7.5 | The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'map_post_type' parameter in all v… | — | wordfence |
| cbe2be48-cad8-4679-beb8-c4c80c045d37 | HIGH | 7.5 | The Nuss - Hotel Booking WordPress theme for WordPress is vulnerable to Local File Inclusion in versions up to, and incl… | — | wordfence | |
| cbd8d37d-50f7-4480-acef-cdec33c9f07f | < 0.2.4 |
HIGH | 7.5 | The WP Attachment Export WordPress plugin before 0.2.4 does not have proper access controls, allowing unauthenticated us… | — | wordfence |
| cbb7bdcf-9f93-4c86-a4b3-ad5aaf7521b0 | < 1.0.8 |
HIGH | 7.5 | The ShipEngine Shipping Quotes plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all ve… | — | wordfence |
| cb981b48-a31a-4ebb-96c9-c6d31e2dfe02 | < 1.5.0 |
HIGH | 7.5 | The Visionary Core plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.9 vi… | — | wordfence |
| cb8eea53-64d1-4375-9364-292b96080f68 | < 4.2 |
HIGH | 7.5 | Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote att… | — | wordfence |
| cb855743-1d08-4e21-a23c-a4ffba615f57 | < 2.0.7 |
HIGH | 7.5 | The NextGen Gallery plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.0 via the '… | — | wordfence |
| cacf2e32-12cf-41a9-a57f-1135c165494c | < 1.2.36 |
HIGH | 7.5 | The Booking for Appointments and Events Calendar β Amelia plugin for WordPress is vulnerable to SQL Injection via the … | — | wordfence |
| caa66246-7ffa-4944-ae3a-9c872300b7d4 | < 3.7.28 |
HIGH | 7.5 | In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler … | — | wordfence |
| ca878f27-f837-412b-8d63-9decb40dc8a5 | < 1.4.3 |
HIGH | 7.5 | The Simple Video Directory plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.4… | — | wordfence |
| ca72924f-23fc-42ef-9556-8fb9f5e88add | HIGH | 7.5 | Absolute path traversal vulnerability in Cross-RSS (wp-cross-rss) plugin 1.7 for WordPress allows remote attackers to re… | — | wordfence | |
| ca4e2fa0-9b18-4318-b588-33d5bc3c5ab9 | < 1.7.5 |
HIGH | 7.5 | The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions u… | — | wordfence |
| ca41c951-318f-47a7-9a30-c1d4eea1b1b5 | < 5.9.0 |
HIGH | 7.5 | The PGS Core plugin for WordPress is vulnerable to SQL Injection via the 'event' parameter in the 'save_header_builder' … | — | wordfence |
| ca263c58-addd-4cd6-b55b-82b7023849e1 | < 0.9.106 |
HIGH | 7.5 | The Migration, Backup, Staging β WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in all v… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →