Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 29 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| c54d503f-9de5-496f-bd6d-2e417a5c1b67 | CRITICAL | 9.8 | The Picturesurf Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… | — | wordfence | |
| c542b535-f75c-4f63-a3d8-7f80139ac97e | < 1.0.3 |
CRITICAL | 9.8 | The FrieChat - WordPress Chat Plugin for WordPress is vulnerable to generic SQL Injection via the ‘time’ parameter i… | — | wordfence |
| c52a8b78-39bd-473b-ad78-377c31453f4e | < 1.4.3 |
CRITICAL | 9.8 | The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the di… | — | wordfence |
| c52435f3-cc1c-4d3a-a664-a07e60fad6ae | < 4.4.3 |
CRITICAL | 9.8 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Local… | — | wordfence |
| c508cb73-53e6-4ebe-b3d0-285908b722c9 | < 0.9.2 |
CRITICAL | 9.8 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 thr… | — | wordfence |
| c5007dd0-a62c-4ad8-8f8b-eb3f4387c370 | < 1.0.12 |
CRITICAL | 9.8 | The AI Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actual… | — | wordfence |
| c4ea7512-34f4-4f58-8564-74a79c84d9d8 | < 1.5.7 |
CRITICAL | 9.8 | The Sogrid plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.6. This make… | — | wordfence |
| c4d99e64-1daf-4349-9702-341f05a65c21 | < 1.4.14 |
CRITICAL | 9.8 | CVE-2019-1010209: GoUrl.io GoURL Wordpress Plugin 1.4.13 and earlier is affected by: CWE-434. The impact is: unauthentic… | — | wordfence |
| c4c530fa-eaf4-4721-bfb6-9fc06d7f343c | < 3.16.2 |
CRITICAL | 9.8 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in al… | — | wordfence |
| c493191e-b2ec-4e5e-ac41-0cff24635a25 | < 3.1.7 |
CRITICAL | 9.8 | The PlainInventory plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.1.6 vi… | — | wordfence |
| c4679fa7-be6b-4f50-8cdf-ff9822794f19 | < 6.0.2.7 |
CRITICAL | 9.8 | The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to … | — | wordfence |
| c466c0ff-d84b-4536-bea7-ada2a80aad15 | < 2.2.0 |
CRITICAL | 9.8 | The WordPress Share Buttons Plugin – AddThis for WordPress is vulnerable to code injection in versions up to, and incl… | — | wordfence |
| c44b9eb6-96a8-4e19-b4c1-72a69b9f159f | CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allow remote atta… | — | wordfence | |
| c42428c6-5d9d-4679-91fe-8ec6f3a3bf9e | < 4.1.8 |
CRITICAL | 9.8 | The Gift Vouchers plugin before 4.1.8 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/adm… | — | wordfence |
| c42203bc-3f69-44d2-b165-abb55937f65b | CRITICAL | 9.8 | SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary… | — | wordfence | |
| c4073c20-e5ca-4978-86a4-7715ba2921bb | < 2.5.5 |
CRITICAL | 9.8 | The Axeptio plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.5.4. This mak… | — | wordfence |
| c4039a27-0100-49c5-8dce-cf015a08ef04 | < 1.1.9 |
CRITICAL | 9.8 | The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the c… | — | wordfence |
| c3f50771-f889-4de9-9d43-a736c4c24efc | < 1.2.3 |
CRITICAL | 9.8 | SQL injection vulnerability in the Landing Pages plugin before 1.2.3 for WordPress allows remote attackers to execute ar… | — | wordfence |
| c3f13f7a-95ed-4f90-8c65-7a4318a8b542 | < 1.5.4 |
CRITICAL | 9.8 | The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to arbitrary file uploads due to mi… | — | wordfence |
| c3d42b22-cf8f-4726-9188-4c7baf8e5200 | < 1.9.9.1 |
CRITICAL | 9.8 | The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to Privilege Escalat… | — | wordfence |
| c3b6c3ab-529d-44f2-b901-ea720cbc3fbc | < 2.1.57 |
CRITICAL | 9.8 | The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name. | — | wordfence |
| c31906da-f2fd-40ac-86e0-3f1ed0409d0c | < 3.9.6 |
CRITICAL | 9.8 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulne… | — | wordfence |
| c317fe6a-b691-40bb-a646-a06a8337da31 | < 3.0.0 |
CRITICAL | 9.8 | The Axact Author List Widget plugin for WordPress is vulnerable to generic SQL Injection via the ‘listItem’ paramete… | — | wordfence |
| c309e32f-9b1a-453f-873c-cc9bd18bc115 | < 2.3.2 |
CRITICAL | 9.8 | The WP Job Portal plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.1. Th… | — | wordfence |
| c2c2385e-0d1e-435a-9b82-972964084148 | < 1.1 |
CRITICAL | 9.8 | The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3. This is due t… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →