Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 353 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| cf992c75-a1ae-49c3-8110-2f3b31b23f6c | < 1.1 |
HIGH | 7.2 | The Zyrex Popup plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … | — | wordfence |
| cf902756-21f3-483b-a5d8-a9b4226bde22 | < 1.18.11 |
HIGH | 7.2 | The Mail Mint plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pr… | — | wordfence |
| cf803368-64ff-4dbe-85ae-af30e18bc833 | < 2.6 |
HIGH | 7.2 | Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN development versions only, allows remote attackers… | — | wordfence |
| cf3c2031-06c7-42c9-a099-a798dc0cc3d0 | < 1.7.0 |
HIGH | 7.2 | The Barcode Scanner (+Mobile App) β Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPr… | — | wordfence |
| cf346e71-9baa-473b-8a65-1f22dae8118f | < 6.0.12 |
HIGH | 7.2 | The Kirki β Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Server-Side Requ… | — | wordfence |
| cf0f5fd4-cd06-4d11-9f22-1f417b546afb | < 2.4.1 |
HIGH | 7.2 | The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βitemβ pa… | — | wordfence |
| cefcd612-0ba8-4225-8f23-817b7220ee7b | < 2.9.9.8 |
HIGH | 7.2 | The EleForms β All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Stored Cro… | — | wordfence |
| cee6a100-cda5-48a6-9f9c-ea17f80c4165 | < 2.3.8 |
HIGH | 7.2 | The Product Import Export for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… | — | wordfence |
| cec5bfa6-96ed-4a5a-be19-63434af32c89 | < 4.0.4 |
HIGH | 7.2 | Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to i… | — | wordfence |
| ce6cfed1-b19c-4000-81a1-fad13dc526d3 | < 12.1.1.1 |
HIGH | 7.2 | The ICS Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 12.… | — | wordfence |
| ce5c048a-0dbf-448d-bfca-aff347d9466b | < 3.10.01 |
HIGH | 7.2 | The ElementsKit Elementor Addons β Advanced Widgets & Templates Addons for Elementor plugin for WordPress is vulnerabl… | — | wordfence |
| ce489717-6489-40a7-9f69-74ba841ed235 | HIGH | 7.2 | The Kush Micro News plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… | — | wordfence | |
| ce330cae-c2f8-42f3-822b-ca24bf46e433 | < 2.11.0 |
HIGH | 7.2 | The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up t… | — | wordfence |
| ce010c6f-16bd-4178-a621-31ba6378946a | HIGH | 7.2 | The HTTP Headers plugin for WordPress is vulnerable to External Control of File Name or Path leading to Remote Code Exec… | — | wordfence | |
| cdec0d79-a78a-499d-a7d0-94b65bfb84bd | HIGH | 7.2 | The editid GET parameter of the Embed Youtube Video WordPress plugin through 1.0 is not sanitised, escaped or validated … | — | wordfence | |
| cde57dc8-9bfe-482c-8f04-654f4386e484 | < 3.1.5 |
HIGH | 7.2 | The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL s… | — | wordfence |
| cddfb3d3-89b8-4d93-8931-54de395fdb53 | < 6.1.9.8 |
HIGH | 7.2 | The WP Maintenance plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.1.9.7 … | — | wordfence |
| cdcdbba7-8280-457b-a511-66a486978a31 | < 2.5.1 |
HIGH | 7.2 | The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 … | — | wordfence |
| cdc993a4-6f65-4570-811c-13a80dbec064 | < 2.0.6 |
HIGH | 7.2 | The WooCommerce Order Proposal plugin for WordPress is vulnerable to privilege escalation via order proposal in all vers… | — | wordfence |
| cdb483db-56f7-4d12-9022-46c829091cc1 | < 0.9.8.6 |
HIGH | 7.2 | The Custom Content Type Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and inclu… | — | wordfence |
| cd97d688-d8af-4598-8faa-97eefad63808 | HIGH | 7.2 | Cross-site scripting (XSS) vulnerability in mce_anyfont/dialog.php in the AnyFont plugin 2.2.3 and earlier for WordPress… | — | wordfence | |
| cd02c709-f0c0-43cc-b0b5-90b8cb1837fe | < 4.3.4 |
HIGH | 7.2 | The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cr… | — | wordfence |
| ccf0d2ca-2891-45d1-8ea2-90dd435b359f | < 7.11.7 |
HIGH | 7.2 | The Avada theme for WordPress is vulnerable to SQL Injection via the 'entry' parameter in all versions up to, and includ… | — | wordfence |
| cca551d0-24a7-457d-a221-ba0b68ab143e | < 4.3.3 |
HIGH | 7.2 | The Jobify theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.3.2 due … | — | wordfence |
| cc987edf-5a68-4baf-947c-e623c85ec659 | < 8.3.8 |
HIGH | 7.2 | Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.7, did not verify some of the uploaded fee… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →