Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 355 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| cdec0d79-a78a-499d-a7d0-94b65bfb84bd | HIGH | 7.2 | The editid GET parameter of the Embed Youtube Video WordPress plugin through 1.0 is not sanitised, escaped or validated … | — | wordfence | |
| cde57dc8-9bfe-482c-8f04-654f4386e484 | < 3.1.5 |
HIGH | 7.2 | The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL s… | — | wordfence |
| cddfb3d3-89b8-4d93-8931-54de395fdb53 | < 6.1.9.8 |
HIGH | 7.2 | The WP Maintenance plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.1.9.7 … | — | wordfence |
| cdcdbba7-8280-457b-a511-66a486978a31 | < 2.5.1 |
HIGH | 7.2 | The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 … | — | wordfence |
| cdc993a4-6f65-4570-811c-13a80dbec064 | < 2.0.6 |
HIGH | 7.2 | The WooCommerce Order Proposal plugin for WordPress is vulnerable to privilege escalation via order proposal in all vers… | — | wordfence |
| cdb483db-56f7-4d12-9022-46c829091cc1 | < 0.9.8.6 |
HIGH | 7.2 | The Custom Content Type Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and inclu… | — | wordfence |
| cda83985-aa36-40ac-80ee-6963fcd77702 | < 8.12 |
HIGH | 7.2 | The Visitors Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … | — | wordfence |
| cd97d688-d8af-4598-8faa-97eefad63808 | HIGH | 7.2 | Cross-site scripting (XSS) vulnerability in mce_anyfont/dialog.php in the AnyFont plugin 2.2.3 and earlier for WordPress… | — | wordfence | |
| cd02c709-f0c0-43cc-b0b5-90b8cb1837fe | < 4.3.4 |
HIGH | 7.2 | The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cr… | — | wordfence |
| ccf0d2ca-2891-45d1-8ea2-90dd435b359f | < 7.11.7 |
HIGH | 7.2 | The Avada theme for WordPress is vulnerable to SQL Injection via the 'entry' parameter in all versions up to, and includ… | — | wordfence |
| cca551d0-24a7-457d-a221-ba0b68ab143e | < 4.3.3 |
HIGH | 7.2 | The Jobify theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.3.2 due … | — | wordfence |
| cc987edf-5a68-4baf-947c-e623c85ec659 | < 8.3.8 |
HIGH | 7.2 | Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.7, did not verify some of the uploaded fee… | — | wordfence |
| cc8e2042-93aa-454a-97b7-283d8a22bf46 | < 1.0.34 |
HIGH | 7.2 | Multiple cross-site scripting (XSS) vulnerabilities in the Mingle Forum plugin before 1.0.34 for WordPress allow remote … | — | wordfence |
| cc7075a6-5609-42ab-a4cb-9d33686c7de0 | < 1.6.4 |
HIGH | 7.2 | The Album Gallery β WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to… | — | wordfence |
| cc49db10-988d-42bd-a9cf-9a86f4c79568 | < 1.4.0 |
HIGH | 7.2 | The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.… | — | wordfence |
| cc174fc6-b72a-49ed-9aed-7a935a239295 | < 7.0.1 |
HIGH | 7.2 | The WPJAM Basic plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, … | — | wordfence |
| cbf8a398-334b-4b89-8a39-b8f0032fefc7 | < 1.0.9.2 |
HIGH | 7.2 | The Transposh WordPress Translation plugin for WordPress is vulnerable to remote code execution in versions up to, and i… | — | wordfence |
| cbdfef0e-aadd-456b-84f6-ecd626400cbe | < 2.0 |
HIGH | 7.2 | The Videopack (formerly Video Embed & Thumbnail Generator) plugin for WordPress is vulnerable to remote code execution i… | — | wordfence |
| cbd42fc4-ab4a-4053-b765-18272eacd2bc | < 3.7.4.1 |
HIGH | 7.2 | The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… | — | wordfence |
| cbc3210d-224e-4ed2-ada7-dc17deb17584 | < 2.3.5 |
HIGH | 7.2 | The Debug Log Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the auto-refresh debug log i… | — | wordfence |
| cb9ca8e0-741c-4763-b677-61f16e5a3b50 | < 1.2.1 |
HIGH | 7.2 | The Event Monster plugin for WordPress is vulnerable to SQL Injection via the βidβ parameter in versions up to, and… | — | wordfence |
| cb8c80fc-3b51-4003-b221-6f02e74bead0 | < 1.7.2 |
HIGH | 7.2 | The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging feature … | — | wordfence |
| cb73e92b-b807-4406-b378-cef6cff9eb82 | HIGH | 7.2 | The Estatik Mortgage Calculator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up … | — | wordfence | |
| cb713c9c-adb4-410c-a92f-d4d5b002d626 | < 5.12 |
HIGH | 7.2 | The MP3 Audio Player β Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Sid… | — | wordfence |
| cb02878a-2c85-4dcb-bdc0-e65addf9fb9c | < 1.14.15 |
HIGH | 7.2 | The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting in all versions up to, and including,… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →