Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 356 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| cae74177-7bfc-4fe2-9d45-0bc567a17909 | < 2.5 |
HIGH | 7.2 | The White Label CMS plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.4 via… | — | wordfence |
| cae284dd-34e0-4dc5-a954-b37935f3cfbc | < 1.8 |
HIGH | 7.2 | The Awin Data Feed WordPress plugin through 1.6 does not sanitise and escape a header when processing request to generat… | — | wordfence |
| cabdc9db-2d1c-4390-a4b7-65648ef9f16a | HIGH | 7.2 | The SIS Handball plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in versions … | — | wordfence | |
| caa5b9aa-e98c-48fc-9e63-0a1380465918 | < 5.0.1 |
HIGH | 7.2 | The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin… | — | wordfence |
| caa39613-aaf3-4e47-8866-8fda1f7fc15b | < 3.2.12 |
HIGH | 7.2 | The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to SQL Injection via the '$email_add… | — | wordfence |
| ca97a718-7508-4bc0-8f8e-7849eb9a0dc0 | < 3.3 |
HIGH | 7.2 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cro… | — | wordfence |
| ca91e41d-b728-4eb0-86d5-043813d8c2c1 | < 4.5.13 |
HIGH | 7.2 | The WP Meta SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Referer’ header in all ve… | — | wordfence |
| ca73de6d-2d47-4d7c-a917-0f99fed8c27d | < 2.1.0 |
HIGH | 7.2 | The SVG Sanitizer library is vulnerable to XSS Bypass in versions up to, and including, 0.15.4. This may allow an attack… | — | wordfence |
| ca6c0527-5a1c-4bf3-af71-8e40381f0c1c | < 4.15 |
HIGH | 7.2 | The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.14… | — | wordfence |
| ca616ae6-59d3-4037-b538-d371f007a037 | HIGH | 7.2 | The Frontend Registration – Contact Form 7 plugin for WordPress is vulnerable to privilege escalation in versions up t… | — | wordfence | |
| ca1fd2f3-7f3a-4227-b013-95e4ec59fce4 | < 1.0.8 |
HIGH | 7.2 | The PostmagThemes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and includ… | — | wordfence |
| c9fe3574-f338-474c-af78-f843501d422c | < 1.2.4 |
HIGH | 7.2 | The Site Mailer – SMTP Replacement, Email API Deliverability & Email Log plugin for WordPress is vulnerable to Stored … | — | wordfence |
| c9c1ddaf-4bf2-4937-b7bf-a09162db043e | < 5.4.11 |
HIGH | 7.2 | The WP EasyCart plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in versio… | — | wordfence |
| c9a989db-683c-492c-8c26-abef0fecf00e | < 9.1.2 |
HIGH | 7.2 | The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection. | — | wordfence |
| c92776c4-643c-40f2-ac28-5df5d6bf7fcd | < 2.37 |
HIGH | 7.2 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to arbitrary file … | — | wordfence |
| c91a14d3-bc41-4490-888c-486ad2994095 | < 1.7.1057 |
HIGH | 7.2 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter … | — | wordfence |
| c8f42f17-bce2-421e-9031-bfa0f8c26b2a | HIGH | 7.2 | The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inc… | — | wordfence | |
| c8bc1653-8fee-468a-bb6d-f24959846ee5 | < 2.8.4 |
HIGH | 7.2 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… | — | wordfence |
| c88f9c43-6772-4406-b1f0-2d20f970f1c2 | < 7.1.0 |
HIGH | 7.2 | The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 7.0.0-7.0.16 d… | — | wordfence |
| c8416840-c022-40a1-bcd3-17b34df11d95 | < 4.5.4 |
HIGH | 7.2 | The ProfilePress plugin for WordPress is vulnerable to Cross-Site Scripting via $data['name'] parameter in versions up t… | — | wordfence |
| c80e6f0b-ccca-4755-b64e-cfcebc5cc1fe | < 1.4.0 |
HIGH | 7.2 | The WP Sticky Button plugin for WordPress is vulnerable to stored cross-site scripting in versions up to, and including,… | — | wordfence |
| c7f10f62-98cf-4629-9a48-59a42490276d | < 2.1.1 |
HIGH | 7.2 | The Catch Themes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and includi… | — | wordfence |
| c7f098b9-eca3-41c7-9c74-0f4b3f75c915 | < 8.14.1 |
HIGH | 7.2 | The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFi… | — | wordfence |
| c7b1216e-b174-4598-bd7b-27a34d251d8a | < 15.0.6 |
HIGH | 7.2 | The Simple Link Directory Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… | — | wordfence |
| c7ab6715-78ac-4030-9147-73c472c6b2e0 | < 1.1.0 |
HIGH | 7.2 | The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPr… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →