Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 442 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| c2e770e0-1a39-4946-838b-4fd1f1dea1c8 | < 1.3.8 |
MEDIUM | 6.5 | The WordPress Header Builder Plugin β Pearl plugin for WordPress is vulnerable to unauthorized site option deletion du… | — | wordfence |
| c2a166de-3bdf-4883-91ba-655f2757c53b | < 5.4.0 |
MEDIUM | 6.5 | Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various vers… | — | wordfence |
| c250bc90-130a-489a-b0da-6996073f44b5 | MEDIUM | 6.5 | The Blrt WP Embed plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.9 due to ins… | — | wordfence | |
| c1b81a26-c12c-4b57-9ef1-c53e0b87ad9a | < 1.7.7 |
MEDIUM | 6.5 | The tutor_mark_answer_as_correct AJAX action from the Tutor LMS β eLearning and online course solution WordPress plugi… | — | wordfence |
| c19fde88-236d-4c27-a97c-e2fef49b7862 | < 1.6.8 |
MEDIUM | 6.5 | The The Doctreat - Hospitals and Doctors Directory WordPress Listing Theme theme for WordPress is vulnerable to arbitrar… | — | wordfence |
| c19dd824-eefb-4bf9-94a8-ce4be637fbac | < 1.1.11 |
MEDIUM | 6.5 | The Hydra Booking plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.10 due to in… | — | wordfence |
| c19d9288-39b2-4db1-abc6-ba87f98fecad | MEDIUM | 6.5 | Open redirect vulnerability in track-click.php in the Ad-Manager plugin 1.1.2 for WordPress allows remote attackers to r… | — | wordfence | |
| c15e111f-7e37-4ff5-bf1e-e472a05990a9 | < 2.2.0 |
MEDIUM | 6.5 | The WP Roadmap plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.3 due to insuff… | — | wordfence |
| c0da4d55-5025-47cf-9f45-377d8943fc94 | < 5.0.10 |
MEDIUM | 6.5 | The CF7 Google Sheets Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… | — | wordfence |
| c0b3662d-e369-4978-aa7a-debbb3ee37e4 | < 3.5.1 |
MEDIUM | 6.5 | The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address values in all vers… | — | wordfence |
| c093ed6a-0f3d-4ad9-a57c-cec1c2e7bd8e | < 3.0.0 |
MEDIUM | 6.5 | The WP Project Manager plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in the '/pm/v2/ac… | — | wordfence |
| c0248af2-f9f3-4652-bf6d-b46aa91b66f3 | < 2.2.15 |
MEDIUM | 6.5 | The School Management System β WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' paramet… | — | wordfence |
| c0179947-9346-4411-a946-09d58b556b9c | MEDIUM | 6.5 | The Limb Gallery | Create Beautiful Image & Video Galleries plugin for WordPress is vulnerable to Directory Traversal in… | — | wordfence | |
| bf88b1db-ca99-4bca-857d-fdc39aa81758 | < 5.4.5 |
MEDIUM | 6.5 | The LBG Zoominoutslider plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.4.4 due … | — | wordfence |
| bf297cd8-3d67-4750-b856-38ded4daf4ad | < 3.2.20 |
MEDIUM | 6.5 | The Booking Calendar WpDevArt plugin is vulnerable to time-based, blind SQL injection via the `id` parameter in the βw… | — | wordfence |
| bedfb712-faf6-4131-b254-e6d7c367f49f | < 4.7.1 |
MEDIUM | 6.5 | The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… | — | wordfence |
| be700f83-248f-4d22-b53d-7cc61e1f7d7d | < 5.2.4 |
MEDIUM | 6.5 | The Wordfence Plugin is vulnerable to multiple protection mechanism bypasses in version up to, and including, 5.2.3. The… | — | wordfence |
| be5d86ad-f94b-4fcb-9b74-ecddde2bf29d | < 4.17.5 |
MEDIUM | 6.5 | The MStore API β Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege… | — | wordfence |
| be4515d8-0d5d-4925-a9a4-64ba9d51fe02 | < 2.0.5 |
MEDIUM | 6.5 | WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, whic… | — | wordfence |
| be39e24f-d7d7-44db-9ffd-a4605de8e577 | < 2.9.6 |
MEDIUM | 6.5 | The AI Engine plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability che… | — | wordfence |
| be0ef9d4-abb0-4801-b847-b84912bc6677 | < 1.5.8 |
MEDIUM | 6.5 | The BCS BatchLine Book Importer plugin for WordPress is vulnerable to Unauthenticated Product Import/Update in versions … | — | wordfence |
| bdf8d5c2-dbb1-47d5-b858-da6f6e1989f4 | < 2.8.8 |
MEDIUM | 6.5 | The Bit integrations β Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vu… | — | wordfence |
| bdf63cff-a159-42a3-a5b5-24a3623bfc1e | MEDIUM | 6.5 | The Short URL plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.6.8 due to ins… | — | wordfence | |
| bdb8cb7f-38fc-41d7-aa78-abe11c6402b6 | < 1.9.10 |
MEDIUM | 6.5 | The Public Post Preview plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on … | — | wordfence |
| bd54a50b-13ce-43ce-bce1-8fe132abc07e | < 2.6.18 |
MEDIUM | 6.5 | The WP Project Manager β Task, team, and project management plugin featuring kanban board and gantt charts plugin for … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →