Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 440 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| cb5cb94b-1f4c-4e93-9764-c50e8449acfb | < 2.4.1 |
MEDIUM | 6.5 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versi… | — | wordfence |
| cb51383f-03c8-4e81-bfed-40fd9f5c4d20 | < 5.7.6 |
MEDIUM | 6.5 | The AutomateWoo plugin for WordPress is vulnerable to unauthorized functionality access due to a missing capability chec… | — | wordfence |
| cb453fe3-ba89-437c-b3fb-9ec207eaa9f0 | < 9.0.8 |
MEDIUM | 6.5 | The teachPress plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tpsearch' shortcode… | — | wordfence |
| cb371826-3fbd-4884-945f-cc040512dc95 | MEDIUM | 6.5 | The LambertGroup - AllInOne - Banner with Playlist plugin for WordPress is vulnerable to SQL Injection in versions up to… | — | wordfence | |
| cae7dabd-ce43-43e3-9f67-b2de55bd720b | < 1.8.42 |
MEDIUM | 6.5 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Inject… | — | wordfence |
| ca989077-60c8-4bd9-a91b-fbefd2ccc49b | < 5.6.3 |
MEDIUM | 6.5 | The Client Portal Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.… | — | wordfence |
| ca729178-8df0-437e-82cc-70c4975f7b47 | < 2.7.3 |
MEDIUM | 6.5 | The MailPoet Newsletters plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 2… | — | wordfence |
| ca6aa922-9c58-445c-b88a-3d1d1c95102c | < 4.5.4 |
MEDIUM | 6.5 | The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through … | — | wordfence |
| ca5cb925-6f95-4f81-92d0-5f3c8e5f7d59 | < 3.10.0 |
MEDIUM | 6.5 | The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable t… | — | wordfence |
| ca481a37-8c45-499c-bf68-3af6795af827 | < 1.2.3 |
MEDIUM | 6.5 | The Predictive Search plugin for WordPress is vulnerable to unauthorized disclosure of data due to a missing capability … | — | wordfence |
| c9ebc817-ccae-4ad2-8eea-eade1c2a1a0c | < 3.1.73 |
MEDIUM | 6.5 | The Smartcat Translator for WPML plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ pa… | — | wordfence |
| c9d07faf-cc88-4233-a552-55e3376a2fc4 | < 3.11.0 |
MEDIUM | 6.5 | The FunnelKit Checkout plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check… | — | wordfence |
| c9694f9b-beaa-44c9-b577-aae4fd14936b | < 1.0.23 |
MEDIUM | 6.5 | The Booktics plugin for WordPress is vulnerable to SQL Injection in versions up to 1.0.22 due to insufficient escaping o… | — | wordfence |
| c940719c-f233-41bb-8866-2487ba0719e2 | < 3.16.3.3 |
MEDIUM | 6.5 | The BM Content Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and excluding, 3.16.3… | — | wordfence |
| c8f3c96b-9a78-47cb-9266-ff87d9409160 | < 1.17.5 |
MEDIUM | 6.5 | The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Inje… | — | wordfence |
| c8e9a333-a6b7-4b5e-93c1-b95566e5d6fb | < 2.2.8 |
MEDIUM | 6.5 | The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery i… | — | wordfence |
| c8c95e9a-9d4d-4a94-bd71-d5d53085df90 | < 2.48.2 |
MEDIUM | 6.5 | The Simple Giveaways plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.48.1 due to… | — | wordfence |
| c8bd778b-1d56-4544-b2c3-a77a7ec05aa4 | < 2.4.2 |
MEDIUM | 6.5 | The Product Sort and Display for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due… | — | wordfence |
| c8a14993-6faa-47fd-a066-d827ab143d9b | < 5.19 |
MEDIUM | 6.5 | The WP Tools plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.18. Th… | — | wordfence |
| c87adbd9-3b09-403e-921a-31b3f58962e9 | < 1.7.3 |
MEDIUM | 6.5 | The PixMagix – WordPress Image Editor plugin for WordPress is vulnerable to Directory Traversal in all versions up to,… | — | wordfence |
| c873c76a-144e-4945-8fa2-c9ffe0e3c061 | < 3.16.5 |
MEDIUM | 6.5 | The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil… | — | wordfence |
| c86f157e-e7f2-4b00-977c-c4cc7c2b3b0b | < 1.6.30 |
MEDIUM | 6.5 | The SalesKing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … | — | wordfence |
| c84e274e-292f-4d0f-b847-4a786b4cb15a | < 2.1 |
MEDIUM | 6.5 | WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain f… | — | wordfence |
| c7f041a7-f5cc-463c-97b0-d4ecb3edb77a | < 2.2.0 |
MEDIUM | 6.5 | The PopupKit plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.5 due to insuffic… | — | wordfence |
| c76da3a4-ec6f-4aa3-8f13-4daa212441f2 | MEDIUM | 6.5 | The iNET Webkit plugin for WordPress is vulnerable to SQL Injection in versions up to 1.2.4 due to insufficient escaping… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →