Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 31 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| c1001b2b-395a-44ee-827e-6e57f7a50218 | < 1.4.2 |
CRITICAL | 9.8 | The WPCasa plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.4.1. This is due… | — | wordfence |
| c0e9726f-45cc-4759-909d-3de2ae9b2334 | < 0.1.0.83 |
CRITICAL | 9.8 | The InstaWP Connect plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.1.0.8… | — | wordfence |
| c0b50597-18c1-4cbc-aebb-348f4d786ad9 | < 3.1.2 |
CRITICAL | 9.8 | The Leopard - WordPress Offload Media plugin for WordPress is vulnerable to unauthorized modification of data that can l… | — | wordfence |
| c0a617fc-da3d-4828-b027-44093dd11769 | CRITICAL | 9.8 | The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leadi… | — | wordfence | |
| c099f401-4b05-4532-8e31-af1b1dea7eca | < 5.4.7 |
CRITICAL | 9.8 | The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and i… | — | wordfence |
| c0856920-5463-4dd3-a4fd-e56901a89b83 | < 2.1.5 |
CRITICAL | 9.8 | The Import XML and RSS Feeds for WordPress is vulnerable to remote code execution in versions up to, and including, 2.1.… | — | wordfence |
| c080df50-1113-484b-80ed-09515982c585 | < 6.0.10 |
CRITICAL | 9.8 | The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. Thi… | — | wordfence |
| c035ac71-54f9-471b-93f3-6bd6a5b86ab2 | < 2.8 |
CRITICAL | 9.8 | SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin b… | — | wordfence |
| bfe92082-4944-43dc-b06c-3c3d22e93213 | < 1.3.1 |
CRITICAL | 9.8 | The FluentCommunity plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.15 … | — | wordfence |
| bfe1d122-610a-47c1-944d-bf7352e9ff38 | < 3.1.0 |
CRITICAL | 9.8 | The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads. | — | wordfence |
| bfd93c33-4672-4914-b052-7bea283ef60c | < 7.0.1 |
CRITICAL | 9.8 | An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthe… | — | wordfence |
| bfd3926e-cdb6-44a6-bada-cb83458ca172 | < 8.0.07 |
CRITICAL | 9.8 | The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution d… | — | wordfence |
| bfd1e244-27c2-4c3e-9d82-a7ffefd4eab6 | < 1.5.2 |
CRITICAL | 9.8 | The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using… | — | wordfence |
| bfc4863a-1b8c-4b13-9df1-18f221b40b26 | < 3.17.6 |
CRITICAL | 9.8 | The Flatsome theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.17.5 via dese… | — | wordfence |
| bf88e79b-262e-4fee-9cef-85d96d300972 | < 2.2.0021 |
CRITICAL | 9.8 | The BePro Listings plugin for WordPress is vulnerable to unauthenticated arbitrary file uploads in versions up to, and i… | — | wordfence |
| bf6b7d8d-fb13-4eb4-b0b4-d0a10ad2a21e | < 2.4.2.4 |
CRITICAL | 9.8 | The Oliver POS β A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposur… | — | wordfence |
| bf43d81f-2d34-4343-8b2a-e3288b1e21c5 | < 12.40 |
CRITICAL | 9.8 | The DZS Video Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 12.39… | — | wordfence |
| bf2a57fa-28f8-4fd0-814b-a4c9ae77817a | < 2.3.2 |
CRITICAL | 9.8 | The VR Calendar plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.2.2 via … | — | wordfence |
| bf203cb9-db7c-4794-b9b7-c054fe7fc0d2 | CRITICAL | 9.8 | The Fish House theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.7 via des… | — | wordfence | |
| bf037e4a-2dd7-4296-b86b-635901d2d68f | < 3.8.4 |
CRITICAL | 9.8 | The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ… | — | wordfence |
| bec7d613-b1cd-4a4e-bbd9-62bca3a864a2 | < 5.7.0 |
CRITICAL | 9.8 | The WPJobBoard plugin for WordPress is vulnerable to SQL Injections via the 'type' and 'category' parameters in versions… | — | wordfence |
| bec50640-a550-49a8-baf6-2dd53995f90b | CRITICAL | 9.8 | The IQ Testimonials plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validatio… | — | wordfence | |
| be97e1ca-6c9c-4641-ba7c-bbb14a58d99e | < 4.2.1 |
CRITICAL | 9.8 | The rtMedia for WordPress, BuddyPress and bbPress for WordPress is vulnerable to Direct file access in versions up to, a… | — | wordfence |
| be8afa0c-af65-46d7-af07-de67353eddb5 | < 1.2.4 |
CRITICAL | 9.8 | The TrueBooker β Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Privilege Escalation i… | — | wordfence |
| be2c1555-4616-4759-bd9b-12f8b3c3a3d4 | < 1.2.1 |
CRITICAL | 9.8 | The "Swape - App Showcase & App Store WordPress Theme" theme for WordPress is vulnerable to authorization bypass due to … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →