Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 354 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2026-2019 | HIGH | 7.2 | The Cart All In One For WooCommerce plugin for WordPress is vulnerable to Code Injection in all versions up to, and incl… | — | nvd | |
| CVE-2026-1945 | HIGH | 7.2 | The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_ema… | — | nvd | |
| CVE-2026-1931 | HIGH | 7.2 | The Rent Fetch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'keyword' parameter in all vers… | — | nvd | |
| CVE-2026-1216 | HIGH | 7.2 | The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in … | — | nvd | |
| CVE-2025-14452 | HIGH | 7.2 | The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' param… | — | nvd | |
| CVE-2025-12886 | HIGH | 7.2 | The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, … | — | nvd | |
| cffaa829-3eee-4390-b3c0-5c0f04ff9e8f | < 1.15.15 |
HIGH | 7.2 | The Asgaros Forum WordPress plugin before 1.15.15 does not validate or escape the forum_id parameter before using it in … | — | wordfence |
| cfc6b4a5-ff13-457f-9e06-de15e8cb5510 | < 3.9.27 |
HIGH | 7.2 | The WP Import Export Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includin… | — | wordfence |
| cfb53e44-7f9d-490f-b938-f428c20219d7 | < 28.0 |
HIGH | 7.2 | The Online Scheduling and Appointment Booking System β Bookly plugin for WordPress is vulnerable to Stored Cross-Site … | — | wordfence |
| cf992c75-a1ae-49c3-8110-2f3b31b23f6c | < 1.1 |
HIGH | 7.2 | The Zyrex Popup plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … | — | wordfence |
| cf902756-21f3-483b-a5d8-a9b4226bde22 | < 1.18.11 |
HIGH | 7.2 | The Mail Mint plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pr… | — | wordfence |
| cf803368-64ff-4dbe-85ae-af30e18bc833 | < 2.6 |
HIGH | 7.2 | Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN development versions only, allows remote attackers… | — | wordfence |
| cf3efda0-8609-4a75-a00b-735b49ef260b | < 1.9.15 |
HIGH | 7.2 | The WCPOS β Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the 't… | — | wordfence |
| cf3c2031-06c7-42c9-a099-a798dc0cc3d0 | < 1.7.0 |
HIGH | 7.2 | The Barcode Scanner (+Mobile App) β Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPr… | — | wordfence |
| cf346e71-9baa-473b-8a65-1f22dae8118f | < 6.0.12 |
HIGH | 7.2 | The Kirki β Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Server-Side Requ… | — | wordfence |
| cf0f5fd4-cd06-4d11-9f22-1f417b546afb | < 2.4.1 |
HIGH | 7.2 | The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βitemβ pa… | — | wordfence |
| cefcd612-0ba8-4225-8f23-817b7220ee7b | < 2.9.9.8 |
HIGH | 7.2 | The EleForms β All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Stored Cro… | — | wordfence |
| cee6a100-cda5-48a6-9f9c-ea17f80c4165 | < 2.3.8 |
HIGH | 7.2 | The Product Import Export for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… | — | wordfence |
| cec5bfa6-96ed-4a5a-be19-63434af32c89 | < 4.0.4 |
HIGH | 7.2 | Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to i… | — | wordfence |
| ce6cfed1-b19c-4000-81a1-fad13dc526d3 | < 12.1.1.1 |
HIGH | 7.2 | The ICS Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 12.… | — | wordfence |
| ce5c048a-0dbf-448d-bfca-aff347d9466b | < 3.10.01 |
HIGH | 7.2 | The ElementsKit Elementor Addons β Advanced Widgets & Templates Addons for Elementor plugin for WordPress is vulnerabl… | — | wordfence |
| ce489717-6489-40a7-9f69-74ba841ed235 | HIGH | 7.2 | The Kush Micro News plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… | — | wordfence | |
| ce4872f8-f589-4ae9-a5c5-4bb66043bfeb | < 4.7.8 |
HIGH | 7.2 | The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… | — | wordfence |
| ce330cae-c2f8-42f3-822b-ca24bf46e433 | < 2.11.0 |
HIGH | 7.2 | The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up t… | — | wordfence |
| ce010c6f-16bd-4178-a621-31ba6378946a | HIGH | 7.2 | The HTTP Headers plugin for WordPress is vulnerable to External Control of File Name or Path leading to Remote Code Exec… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →