Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1018 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a3ecc238-1f84-47fd-96b9-753d4b528c47 | < 2.4 |
MEDIUM | 6.0 | The WooCommerce - Store Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2… | — | wordfence |
| 8f1e6f04-04d4-4484-86bd-28df6388a953 | < 3.4.0 |
MEDIUM | 6.0 | The Simple History plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 3.3.1. This all… | — | wordfence |
| 62ac66d8-fc10-4ec2-a567-7b95eb6f2c76 | < 2.73.13 |
MEDIUM | 6.0 | The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and… | — | wordfence |
| 5dde4850-347f-40e6-9cea-87284aa655e7 | < 0.9.76 |
MEDIUM | 6.0 | The WPvivid plugin for WordPress is vulnerable to directory traversal in versions up to, and including, 0.9.75. This all… | — | wordfence |
| 084a209f-c67b-4df9-9f4b-c537ea065a50 | MEDIUM | 6.0 | The Emails & Newsletters with Jackmail plugin for WordPress is vulnerable to CSV Injection in versions up to, and includ… | — | wordfence | |
| fa452a9a-9e26-41a1-8dea-4bafaf735bee | MEDIUM | 5.9 | The Database Toolset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… | — | wordfence | |
| f8bbab6e-ed2f-4b90-a658-aae85906d06e | < 3.2.1 |
MEDIUM | 5.9 | The Filter & Grids plugin for WordPress is vulnerable to SQL Injection via the 'phrase' parameter in all versions up to,… | — | wordfence |
| f373a1d5-3d7e-4a0a-af03-28ca6ce6a170 | < 7.15 |
MEDIUM | 5.9 | The All-in-One WP Migration plugin for WordPress is vulnerable to unauthenticated arbitrary back-up downloads due to ins… | — | wordfence |
| e9f31ec5-c376-45b1-9ffe-35c80b89b60d | < 2.6.1 |
MEDIUM | 5.9 | The Feeds for YouTube Pro plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including… | — | wordfence |
| d360de79-8490-4e70-b2d9-4f01a1ed3305 | < 2.7.3 |
MEDIUM | 5.9 | The EUCookieLaw plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.7.2 vi… | — | wordfence |
| d33199ea-7c96-4c60-a7b8-5c7e9835e231 | < 2.3 |
MEDIUM | 5.9 | The 1 Click WordPress Migration Plugin β 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive … | — | wordfence |
| c70bb3d6-6acd-46b2-8e47-30be031f73e4 | MEDIUM | 5.9 | The asMember plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.4 d… | — | wordfence | |
| ab40146d-9b49-4214-af73-41c5b5512542 | < 1.19.2 |
MEDIUM | 5.9 | The WP Crontrol plugin for WordPress is vulnerable to blind Server-Side Request Forgery in versions 1.17.0 to 1.19.1 via… | — | wordfence |
| a1fadba1-674f-4f3d-997f-d29d3a887414 | < 4.4.1.2 |
MEDIUM | 5.9 | The MainWP Child plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, … | — | wordfence |
| 97cef309-da2f-461a-b5a3-3a85c540c7aa | < 3.25.2 |
MEDIUM | 5.9 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all … | — | wordfence |
| 8c052622-ac99-4069-b7df-41aea303ed9d | < 3.2.18 |
MEDIUM | 5.9 | The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to time-based SQL Injection via the … | — | wordfence |
| 869d7cab-cf21-4168-b45d-1681c76d896c | < 2.3.6 |
MEDIUM | 5.9 | The Everest Backup β WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to… | — | wordfence |
| 7fc9bf38-0214-4f0d-9f3d-5ba0da9b76d9 | < 1.5.5 |
MEDIUM | 5.9 | The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.5.4 due… | — | wordfence |
| 7e98b1ef-70dd-408d-8644-08933bca1cdd | MEDIUM | 5.9 | The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio… | — | wordfence | |
| 703ba736-5834-40f2-9cf6-a6a70a73e4d6 | < 6.4.0 |
MEDIUM | 5.9 | The Modern Events Calendar Lite plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'wp_aj… | — | wordfence |
| 6ee6dedb-72bc-43b0-a7cb-9069533df705 | < 1.5.6 |
MEDIUM | 5.9 | The User Blocker plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.5.5. This allow… | — | wordfence |
| 68f41e88-ed36-4361-bddd-41495a540cd9 | < 2.01 |
MEDIUM | 5.9 | The WP Reset β Most Advanced WordPress Reset Tool plugin for WordPress is vulnerable to Sensitive Information Exposure… | — | wordfence |
| 5f88a21d-28a9-4c91-9bf9-6b69f6a420e8 | < 4.4.6 |
MEDIUM | 5.9 | The Return Refund and Exchange For WooCommerce β Return Management System, RMA Exchange, Wallet And Cancel Order Featu… | — | wordfence |
| 5652f9c3-3cc9-4541-8209-40117b4d25d9 | < 1.15.23 |
MEDIUM | 5.9 | The Form Maker by 10Web β Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensi… | — | wordfence |
| 4fd6df9d-2963-44b1-bc4e-e53eda97a2a9 | < 6.5.0 |
MEDIUM | 5.9 | The Fancy Product Designer plugin for WordPress is vulnerable to Information Disclosure and PHAR Deserialization in all … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →