Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,758 vulnerabilities found (page 30 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| c5c17dea-7b61-4e73-ac61-3fe536c22962 | < 2.1.66 |
CRITICAL | 9.8 | The WooCommerce Products Vendor plugin for WordPress is vulnerable to blind SQL Injection via the ‘s_postcode’ param… | — | wordfence |
| c5bd11c6-2f55-4eee-834a-c4e405482b9c | < 5.7.24 |
CRITICAL | 9.8 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin… | — | wordfence |
| c5bc757d-2495-4be2-bccd-d4090e66ced4 | CRITICAL | 9.8 | The Fresh Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.… | — | wordfence | |
| c5ada976-03b8-4219-9ae3-9060fb7b9de5 | < 1.7 |
CRITICAL | 9.8 | The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to … | — | wordfence |
| c5a5c209-0ccd-4fa9-b22d-05bb22247441 | < 2.1.6 |
CRITICAL | 9.8 | The OneLogin SAML-SSO plugin for WordPress is vulnerable to authentication bypass due to insufficient user validation in… | — | wordfence |
| c58d5a57-6b87-4a39-b995-c86fbc779565 | < 3.2.11 |
CRITICAL | 9.8 | A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful explo… | — | wordfence |
| c5757abd-33dc-4751-bc55-afd944ff2341 | < 1.3.0 |
CRITICAL | 9.8 | The Duplicator – WordPress Migration & Backup Plugin plugin for WordPress is vulnerable to Remote Code Execution in al… | — | wordfence |
| c5519d4e-84b5-4901-b55c-a0a919f4b6c9 | < 1.0.6.1 |
CRITICAL | 9.8 | The Active Products Tables for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up… | — | wordfence |
| c54d503f-9de5-496f-bd6d-2e417a5c1b67 | CRITICAL | 9.8 | The Picturesurf Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… | — | wordfence | |
| c542b535-f75c-4f63-a3d8-7f80139ac97e | < 1.0.3 |
CRITICAL | 9.8 | The FrieChat - WordPress Chat Plugin for WordPress is vulnerable to generic SQL Injection via the ‘time’ parameter i… | — | wordfence |
| c52a8b78-39bd-473b-ad78-377c31453f4e | < 1.4.3 |
CRITICAL | 9.8 | The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the di… | — | wordfence |
| c52435f3-cc1c-4d3a-a664-a07e60fad6ae | < 4.4.3 |
CRITICAL | 9.8 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Local… | — | wordfence |
| c508cb73-53e6-4ebe-b3d0-285908b722c9 | < 0.9.2 |
CRITICAL | 9.8 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 thr… | — | wordfence |
| c5007dd0-a62c-4ad8-8f8b-eb3f4387c370 | < 1.0.12 |
CRITICAL | 9.8 | The AI Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actual… | — | wordfence |
| c4ea7512-34f4-4f58-8564-74a79c84d9d8 | < 1.5.7 |
CRITICAL | 9.8 | The Sogrid plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.6. This make… | — | wordfence |
| c4d99e64-1daf-4349-9702-341f05a65c21 | < 1.4.14 |
CRITICAL | 9.8 | CVE-2019-1010209: GoUrl.io GoURL Wordpress Plugin 1.4.13 and earlier is affected by: CWE-434. The impact is: unauthentic… | — | wordfence |
| c4c530fa-eaf4-4721-bfb6-9fc06d7f343c | < 3.16.2 |
CRITICAL | 9.8 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in al… | — | wordfence |
| c493191e-b2ec-4e5e-ac41-0cff24635a25 | < 3.1.7 |
CRITICAL | 9.8 | The PlainInventory plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.1.6 vi… | — | wordfence |
| c4679fa7-be6b-4f50-8cdf-ff9822794f19 | < 6.0.2.7 |
CRITICAL | 9.8 | The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to … | — | wordfence |
| c466c0ff-d84b-4536-bea7-ada2a80aad15 | < 2.2.0 |
CRITICAL | 9.8 | The WordPress Share Buttons Plugin – AddThis for WordPress is vulnerable to code injection in versions up to, and incl… | — | wordfence |
| c458e018-5901-4917-9847-35f07646e068 | < 4.4.6 |
CRITICAL | 9.8 | The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5.… | — | wordfence |
| c44b9eb6-96a8-4e19-b4c1-72a69b9f159f | CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allow remote atta… | — | wordfence | |
| c42428c6-5d9d-4679-91fe-8ec6f3a3bf9e | < 4.1.8 |
CRITICAL | 9.8 | The Gift Vouchers plugin before 4.1.8 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/adm… | — | wordfence |
| c42203bc-3f69-44d2-b165-abb55937f65b | CRITICAL | 9.8 | SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary… | — | wordfence | |
| c4073c20-e5ca-4978-86a4-7715ba2921bb | < 2.5.5 |
CRITICAL | 9.8 | The Axeptio plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.5.4. This mak… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →