Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,758 vulnerabilities found (page 29 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| c814924a-bdcd-4b73-905b-a469f4d37ddf | < 2.731 |
CRITICAL | 9.8 | The Post Pay Counter plugin before 2.731 for WordPress has PHP Object Injection via deserialization of untrusted input v… | — | wordfence |
| c7e3a8ee-9950-4da4-8450-8b5902b3b876 | < 1.0.94 |
CRITICAL | 9.8 | The User Verification plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when gen… | — | wordfence |
| c7a97aeb-f34c-4997-864b-132bb5ed28e7 | < 2.3.9 |
CRITICAL | 9.8 | The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL stateme… | — | wordfence |
| c7a6eff3-a592-4476-aff4-c133bb4e5870 | < 1.1.23 |
CRITICAL | 9.8 | WordPress WP GPX Maps Plugin before 1.1.23 allows remote attackers to execute arbitrary PHP code via improper file uploa… | — | wordfence |
| c77619cd-8d14-42b9-a536-cf39c50e714a | < 0.5.4 |
CRITICAL | 9.8 | The Front End Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation vi… | — | wordfence |
| c764e742-1135-43aa-a190-3b7ec6767f1c | CRITICAL | 9.8 | The LogisticsHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … | — | wordfence | |
| c764811f-e9dc-4c3d-b696-5792e70ff0b6 | CRITICAL | 9.8 | The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stockt… | — | wordfence | |
| c754d957-26a8-4fef-a487-96d566c2dc36 | < 6.6.8 |
CRITICAL | 9.8 | The WP Travel Engine β Tour Booking Plugin β Tour Operator Software plugin for WordPress is vulnerable to arbitrary … | — | wordfence |
| c74ce3e8-cab9-4cc6-a1ad-1e51f7268474 | < 2.17.1 |
CRITICAL | 9.8 | The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all ve… | — | wordfence |
| c7476f2c-c32f-4ff7-ad32-70cf68387342 | < 2.76 |
CRITICAL | 9.8 | The Disqus Comment System plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, … | — | wordfence |
| c741350a-e083-499c-992d-727f46ca57f9 | < 1.1.2 |
CRITICAL | 9.8 | The simple-login-log plugin before 1.1.2 for WordPress has SQL injection via the 'order' parameter in the get_results fu… | — | wordfence |
| c726d8f0-7f2a-414b-9d73-a053921074d9 | < 3.9.1 |
CRITICAL | 9.8 | The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This… | — | wordfence |
| c7214f90-a205-4d7e-94c8-ee07515ebbf1 | < 1.4.7 |
CRITICAL | 9.8 | The Material Dashboard plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, … | — | wordfence |
| c714e2b3-8a96-4078-99a4-4ce620939828 | < 1.4.12 |
CRITICAL | 9.8 | The SigmaForms Pro β AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici… | — | wordfence |
| c6f68bfd-36c3-45f5-a50b-6803b5967e52 | CRITICAL | 9.8 | The Download from files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… | — | wordfence | |
| c6ef0c41-e498-4de6-a86a-d23f65a7a824 | < 1.0.9 |
CRITICAL | 9.8 | controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users… | — | wordfence |
| c6ee9437-a12a-476b-9a4b-8da8d9fbfeb3 | < 5.2.13 |
CRITICAL | 9.8 | The Fluent Forms Pro in version 6.2.7 and the Ninja Tables Pro in version 5.2.13 plugins for WordPress are vulnerable to… | — | wordfence |
| c6a0811e-f02b-49d1-915e-cf7ac4b5e1f5 | CRITICAL | 9.8 | The Power Zoomer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via th… | — | wordfence | |
| c6a02da1-b005-4fa9-9657-1c5f019f3858 | < 2.0.8 |
CRITICAL | 9.8 | The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the '*_ordering' parameter in all versions … | — | wordfence |
| c6998185-0f9b-48ab-9dca-05adf5ae603a | CRITICAL | 9.8 | The LazyTasks β Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerabl… | — | wordfence | |
| c691d129-35db-4de8-a28e-5e77347e2280 | < 1.15.20 |
CRITICAL | 9.8 | The Form Maker by 10Web plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valid… | — | wordfence |
| c66d88a1-0936-40c4-adcf-ad79b9c57a80 | < 4.4.3 |
CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to exec… | — | wordfence |
| c63048ad-3d37-402e-8e61-415d2d6caa69 | CRITICAL | 9.8 | The Form Lightbox plugin for WordPress is vulnerable to arbitrary option updates due to a missing capability check in th… | — | wordfence | |
| c62d8146-e4b1-4c86-9d8a-c3a9bbfb0763 | < 1.1.60 |
CRITICAL | 9.8 | The Profile Builder β User Profile & User Registration Forms Plugin for WordPress is vulnerable to authentication bypa… | — | wordfence |
| c5fee6e4-b985-4190-953b-133bc90e47da | < 1.6 |
CRITICAL | 9.8 | The Freshmail plugin for WordPress is vulnerable to Multiple SQL Injections via the 'include/wp_ajax_fm_form.php' and 'i… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →