Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 819 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| cb112c12-2587-46de-a688-d0f04e1ec431 | < 2.8.1 |
MEDIUM | 6.1 | The WP Google Analytics Events β No-Code Custom Event Tracking for Google Analytics plugin for WordPress is vulnerable… | — | wordfence |
| cb072bfa-991a-4839-996d-fdc803427076 | < 2.8.1 |
MEDIUM | 6.1 | Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to redirect us… | — | wordfence |
| cb028377-d62d-4172-9253-6870c985736f | MEDIUM | 6.1 | The OWL Carousel Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and … | — | wordfence | |
| cae72c7e-9bc8-40a7-b125-c9e8c86b14bf | < 1.1.3 |
MEDIUM | 6.1 | The Advance Search WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the wpas_id parameter found in t… | — | wordfence |
| cae45f7d-0ffe-41c4-9d1c-3211d6f86e5c | < 0.5.4 |
MEDIUM | 6.1 | The Stop Comment Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… | — | wordfence |
| cae1f5c7-ae91-4f45-8b4f-b2be89d36437 | < 0.6 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in the Video Lead Form plugin for WordPress allows remote attackers to inject a… | — | wordfence |
| cae1e984-95b2-4b76-b6b3-563dc3104a72 | < 1.3.5 |
MEDIUM | 6.1 | The Woo Custom Checkout Field plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versi… | — | wordfence |
| cad7731a-1f81-4055-9b49-15b35edd3fcf | < 1.2.0 |
MEDIUM | 6.1 | The Hash Form β Drag & Drop Form Builder plugin for WordPress is vulnerable to limited file uploads due to a misconfig… | — | wordfence |
| cad5274f-0d73-425d-bdfb-478c77d55d6c | < 2.9.97 |
MEDIUM | 6.1 | The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includi… | — | wordfence |
| cad4300f-02f9-4c9f-9bb3-1c9da8b78ac9 | < 2.0.11 |
MEDIUM | 6.1 | The WP Simple Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad… | — | wordfence |
| cace29fd-95d0-48ea-8dfa-6fd12dd9ccbf | < 3.2.44 |
MEDIUM | 6.1 | The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attr… | — | wordfence |
| cac4482e-bdf8-434a-ad22-ca2eeec15906 | < 3.6.5 |
MEDIUM | 6.1 | The NiceJob plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.4… | — | wordfence |
| cabf7aae-0673-4358-a2df-0ca22c8432b5 | < 3.1.25 |
MEDIUM | 6.1 | The Ditty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via unescaped URLs in versions up to, and… | — | wordfence |
| caae093e-58e8-48b1-8665-2a5f49e98c58 | < 1.1.6 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in admin/OptionsPostsList.php in the TheCartPress plugin for WordPress before 1… | — | wordfence |
| caa23ec8-547b-425e-94bd-297d12702256 | < 2.41 |
MEDIUM | 6.1 | The Ravpage plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.40 … | — | wordfence |
| caa09e12-60f9-4ef4-85f7-dadb6833e077 | < 4.1.12 |
MEDIUM | 6.1 | The theplus_more_post AJAX action of The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.12 did not p… | — | wordfence |
| ca8c676a-144c-4809-b8f6-50cb9e1390b5 | < 1.0.4 |
MEDIUM | 6.1 | The Easy Digital Downloads (EDD) Invoices extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9… | — | wordfence |
| ca77c769-a5e4-406f-954b-00bd767909ec | MEDIUM | 6.1 | The Onlywire Multi Autosubmitter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… | — | wordfence | |
| ca62b54e-dde6-440f-bed9-db320179269e | < 5.1.7 |
MEDIUM | 6.1 | The Photo Gallery by Ays plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc… | — | wordfence |
| ca32fd93-cab3-431b-91c3-9ed244f9d1f1 | < 2.3.7 |
MEDIUM | 6.1 | The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg()… | — | wordfence |
| ca2d687f-0358-4642-849b-100bf40cbbf1 | < 1.1.3 |
MEDIUM | 6.1 | The MediaView plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the βid' parameter in all versi… | — | wordfence |
| ca203777-84ea-47ab-bafc-f2cc8f778fcd | < 4.1.6.6 |
MEDIUM | 6.1 | The LearnPress β WordPress LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of … | — | wordfence |
| ca11e840-04bd-4731-bfa9-3bf8ed98e155 | < 2.1 |
MEDIUM | 6.1 | The Image Gallery β Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via … | — | wordfence |
| ca0e51b2-640a-4bd1-b667-74107b7dcc6f | < 1.33.10 |
MEDIUM | 6.1 | The WordPress Webinar Plugin β WebinarPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in al… | — | wordfence |
| ca09ce0d-3989-420d-9457-f0acd709cc6b | < 2.3.8 |
MEDIUM | 6.1 | The Stagtools plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'popup' parameter in versions… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →