Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,113 vulnerabilities found (page 826 of 1605)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| c3ce0b74-cc65-4ea9-9fcc-d7bcd00bb67f | < 2.7.0 |
MEDIUM | 6.1 | The PeproDev WooCommerce Receipt Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versio… | — | wordfence |
| c3b0c2c0-4eaf-4158-94e1-0cfb60310a1d | MEDIUM | 6.1 | The Buooy Sticky Header plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and incl… | — | wordfence | |
| c3799c76-2b25-4346-948e-14445d93b7f1 | MEDIUM | 6.1 | The Zarinpal Paid Download plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a… | — | wordfence | |
| c36b0d08-7289-4410-adfb-99dbe1ac4c03 | < 2.0.59 |
MEDIUM | 6.1 | The OTP-less one tap Sign in plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and… | — | wordfence |
| c36181aa-39c2-4009-b687-5964a6cc45c8 | < 1.8 |
MEDIUM | 6.1 | The Awin Data Feed WordPress plugin through 1.7 does not sanitise and escape a parameter before outputting it back via a… | — | wordfence |
| c3613f95-8338-40b8-8b16-2714fa3474ce | < 4.0.50 |
MEDIUM | 6.1 | The Limit Login Attempts WordPress plugin before 4.0.50 does not escape the IP addresses (which can be controlled by att… | — | wordfence |
| c3489038-2833-4080-b802-5733afab5de8 | < 5.48.0 |
MEDIUM | 6.1 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' pa… | — | wordfence |
| c343cee6-909d-4c1a-a6e4-f916a2ae223e | < 4.2.4 |
MEDIUM | 6.1 | The YML for Yandex Market plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the feed_id paramete… | — | wordfence |
| c340b7c0-35ab-4707-a999-261a721a9a37 | < 2.1.20 |
MEDIUM | 6.1 | The Ultimate Member β User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did no… | — | wordfence |
| c322841a-4134-4c21-8028-0ccacd46335b | < 1.9.9.41 |
MEDIUM | 6.1 | The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'sub… | — | wordfence |
| c31e9400-ee59-4c7e-a52f-e0774c0d9af8 | MEDIUM | 6.1 | The URL-Preview-Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | wordfence | |
| c319dd9f-d07d-42ea-bce8-1a99435347c5 | < 1.3.59 |
MEDIUM | 6.1 | The LabelGrid Tools plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includin… | — | wordfence |
| c30d517b-e051-408c-a022-4399c3d62390 | < 6.8.8 |
MEDIUM | 6.1 | The Easy Forms for MailChimp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the in versions up… | — | wordfence |
| c30aeafe-725b-47be-b49d-00f58b474c3a | < 3.3.2 |
MEDIUM | 6.1 | The TablePress β Tables in WordPress made easy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in… | — | wordfence |
| c2fde092-0a12-42ab-abbb-7f5ff5de9af2 | < 1.5.11 |
MEDIUM | 6.1 | The ShopSite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.… | — | wordfence |
| c2f4461b-1373-4d09-8430-14d1961e1644 | < 0.9.4 |
MEDIUM | 6.1 | The Microsoft Clarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… | — | wordfence |
| c2e6a555-6f7e-48bd-8e8d-dfdcbd5f1e77 | < 8.5.5 |
MEDIUM | 6.1 | The WP eStore plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Discount Editing in all versions … | — | wordfence |
| c2c74678-ff9e-4b67-9061-505dbebcf9aa | MEDIUM | 6.1 | The SpotBot plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 0… | — | wordfence | |
| c2c11644-b9b5-40c7-b558-995b621fc5d6 | MEDIUM | 6.1 | The MinhNhut Link Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter o… | — | wordfence | |
| c2bc94a7-5a03-48be-be77-b05681033ba3 | < 1.4.7 |
MEDIUM | 6.1 | The Snow Storm plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.… | — | wordfence |
| c2b7802a-3cbe-4488-93d2-5f8a34faf8ae | < 1.2.2 |
MEDIUM | 6.1 | Cross-site scripting (XSS) vulnerability in sabre_class_admin.php in the SABRE plugin before 2.1 for WordPress allows re… | — | wordfence |
| c2b3113e-7a47-4a32-aafd-bc806f99f8b6 | MEDIUM | 6.1 | The WP Keyword Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence | |
| c2a761ce-5a0c-4ba6-91f7-82ef7935f734 | < 1.0.15 |
MEDIUM | 6.1 | The AWcode Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… | — | wordfence |
| c2a57428-3473-4f24-ae30-5f6cada7481c | < 2.8.1 |
MEDIUM | 6.1 | The HandL UTM Grabber / Tracker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, … | — | wordfence |
| c2a515d9-dc4c-4755-b602-a9eb22f8e814 | < 2.7.5 |
MEDIUM | 6.1 | The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputtin… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →