Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 415 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| c884af7a-cd66-4f38-887d-a782ffb32219 | < 2.0.9.1 |
HIGH | 7.1 | The AffiliateWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filter_from’ parameter… | — | wordfence |
| c77295f3-0a37-4fa8-a375-b4bd3dc55945 | < 1.1.48 |
HIGH | 7.1 | The Contact Form Email plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cal’ parameter … | — | wordfence |
| c7641d52-e930-4143-9180-2903d018da91 | < 2.6.4 |
HIGH | 7.1 | The Index Now plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6… | — | wordfence |
| c6aaabe9-4f55-4c01-b350-573e6a944353 | < 2.8.9 |
HIGH | 7.1 | The ShopLentor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… | — | wordfence |
| c5f23c14-e9ed-474c-9acc-2d6d43201572 | HIGH | 7.1 | Cross-site scripting (XSS) vulnerability in includes/getTipo.php in the ToolPage plugin 1.6.1 and earlier for WordPress … | — | wordfence | |
| c39c1b72-e3e0-44fb-8fb8-602cb0aa61e3 | < 3.1.9 |
HIGH | 7.1 | The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to,… | — | wordfence |
| c38b6cce-ea8b-48f3-a995-173047d1caf8 | < 1.5.2 |
HIGH | 7.1 | Cross-site scripting (XSS) vulnerability in the Polylang plugin before 1.5.2 for WordPress allows remote attackers to in… | — | wordfence |
| c3678b4d-0cd0-4873-8cf3-90c557931f4c | < 5.9.8.5 |
HIGH | 7.1 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due … | — | wordfence |
| c237c4bc-b971-4d76-97a1-155ef7a3e5df | HIGH | 7.1 | The Easy Blocks pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… | — | wordfence | |
| c1532e12-b786-4b87-ae19-951297c47a6c | < 2.26.6 |
HIGH | 7.1 | The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_block… | — | wordfence |
| bf0f549d-1d88-415a-81f3-b50f977e2c17 | < 8.2.4 |
HIGH | 7.1 | Cross-site request forgery (CSRF) vulnerability in the All in One Webmaster plugin before 8.2.4 for WordPress allows rem… | — | wordfence |
| bb5f73c3-f40b-45d5-9947-c1a514d230f7 | < 2.4.45 |
HIGH | 7.1 | The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… | — | wordfence |
| b948574a-0aab-4596-83e6-04be21f78bc1 | HIGH | 7.1 | Several YITHEMES plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the c… | — | wordfence | |
| b8d63789-16b3-443b-8dcb-67b1e5e25d20 | < 1.3.21 |
HIGH | 7.1 | The Cloudflare plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 1.3.… | — | wordfence |
| b722bf4e-1e04-4d80-b359-7d43596751a8 | HIGH | 7.1 | The Flashlight theme plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.8.4 … | — | wordfence | |
| b6de66ee-08f6-47f6-b6d1-edbf7bea70d8 | < 2.1 |
HIGH | 7.1 | Cross-site scripting (XSS) vulnerability in the Custom Banners plugin before 2.1 for WordPress allows remote attackers t… | — | wordfence |
| b647a6c5-3710-43ec-bf31-87b5a26d54b3 | < 5.5.7 |
HIGH | 7.1 | The Formidable Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
| b46b5299-2c14-4eb7-872c-f43518e1d31d | HIGH | 7.1 | Cross-site scripting (XSS) vulnerability in process.php in the Malware Finder plugin 1.1 and earlier for WordPress allow… | — | wordfence | |
| b4503e2c-0d0d-45de-a597-baace44a98a7 | < 5.6.18 |
HIGH | 7.1 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cro… | — | wordfence |
| b0d8499a-a630-4c2b-9381-78ac83da119d | < 3.2.13 |
HIGH | 7.1 | The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… | — | wordfence |
| b0b2bdb3-713c-47c6-8907-ac0f86038dc2 | < 3.10.4 |
HIGH | 7.1 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is… | — | wordfence |
| b05ece19-ba0d-456e-bdab-86abe9a13e70 | < 5.2.0 |
HIGH | 7.1 | The Newsletter Meenews plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 5.1.… | — | wordfence |
| af1796b7-64b4-4198-9ba4-8a77a0f1cf02 | HIGH | 7.1 | Cross-site scripting (XSS) vulnerability in oleggo-twitter/twitter_login_form.php in the Oleggo LiveStream plugin 0.2.6 … | — | wordfence | |
| aed2ec57-2475-4e77-8219-399cf769ba5a | < 3.1.2.6 |
HIGH | 7.1 | The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘quiz’ parameter in versi… | — | wordfence |
| ae1e198b-0c0d-47aa-8a56-ec4e790c8022 | < 4.16.12 |
HIGH | 7.1 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →