Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1019 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4eeae6dd-a41f-4878-aa92-064ec78367d7 | < 6.7.0.57 |
MEDIUM | 5.9 | The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and inc… | — | wordfence |
| 3cb73d5d-ca4a-4103-866d-f7bb369a8ce4 | < 3.7.2 |
MEDIUM | 5.9 | The Ninja Forms Contact Form β The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Seco… | — | wordfence |
| 33e8a48e-0ddb-4278-a023-818aebe92dab | < 2.6.1 |
MEDIUM | 5.9 | The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before … | — | wordfence |
| 30147e39-af94-4620-870b-71a0a46b7509 | < 1.6.2 |
MEDIUM | 5.9 | The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposu… | — | wordfence |
| 2fdc32a4-adf8-4174-924b-5d0b763d010c | < 1.12.3.1 |
MEDIUM | 5.9 | The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in… | — | wordfence |
| 2745a40c-b011-4fe5-b2f7-d97ee6972568 | MEDIUM | 5.9 | The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in a… | — | wordfence | |
| 254b5dd2-c3d9-45d9-8328-6cc8ef29c9db | < 5.5 |
MEDIUM | 5.9 | WordPress up to version 5.5 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier fo… | — | wordfence |
| 20caab24-4af7-4592-9b18-f2f5acb423c9 | < 1.3.0 |
MEDIUM | 5.9 | The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Reads in all versions u… | — | wordfence |
| 1dbdc673-b0ee-4d1d-8cd9-603056f41cda | < 1.51.0 |
MEDIUM | 5.9 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and incl… | — | wordfence |
| 18d6dffd-8df3-4611-ad94-6d806aa7328a | < 3.25 |
MEDIUM | 5.9 | The Order Export for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… | — | wordfence |
| 12ab3e54-a0b9-4420-ac90-f16e23688cca | < 5.5.0 |
MEDIUM | 5.9 | The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure … | — | wordfence |
| 02066dcd-1f2f-4ed3-b1f4-7ea8711918e8 | < 5.2.0 |
MEDIUM | 5.9 | The All In One WP Security plugin for WordPress is vulnerable to sensitive information disclosure in version 5.1.9. This… | — | wordfence |
| 01def852-367b-4f64-9c5a-58dcc3478b2e | MEDIUM | 5.9 | The Clipr WordPress plugin through 1.2.3 does not sanitise and escape its API Key settings before outputting it in an at… | — | wordfence | |
| fa995fa9-5fb1-434a-bf88-c60e986c45eb | < 6.7.1.30 |
MEDIUM | 5.8 | The Quiz Maker by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rate_reason' parameter … | — | wordfence |
| dcbd6f84-06b5-4430-94b0-68471ca47fc0 | < 1.4.1 |
MEDIUM | 5.8 | The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Unauthenticated Arbitrary Email Sending in… | — | wordfence |
| dc7ba538-a7ee-48c8-996c-b8db1934fdeb | < 8.2.7 |
MEDIUM | 5.8 | The Quick Contact Form plugin for WordPress is vulnerable to Open Mail Relay in all versions up to, and including, 8.2.6… | — | wordfence |
| d9f1719c-ef66-4c68-b25c-175c99938e7a | MEDIUM | 5.8 | The Telefication WordPress plugin is vulnerable to Open Proxy and Server-Side Request Forgery via the ~/bypass.php file … | — | wordfence | |
| d89918e1-b525-4d32-9b11-5e014eb02c16 | < 6.4.2.8 |
MEDIUM | 5.8 | The Auto Affiliate Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… | — | wordfence |
| d6ae7c9f-852d-428f-a469-6bfeead53db5 | < 2.8.65 |
MEDIUM | 5.8 | In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of al… | — | wordfence |
| d31d0553-9378-4c7e-a258-12562aa6b388 | < 6.9.4 |
MEDIUM | 5.8 | The Super Store Finder plugin for WordPress is vulnerable to unauthenticated arbitrary email creation and relay in versi… | — | wordfence |
| cddbb0f8-fc73-46d7-80af-edb69227084f | < 4.7.34 |
MEDIUM | 5.8 | WordPress Core is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 7.0.2 due to ins… | — | wordfence |
| c96175ef-03a5-43cb-adec-1b3c9fb8b1eb | < 2.0.1 |
MEDIUM | 5.8 | The Give β Divi Donation Modules plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions … | — | wordfence |
| c77b0d79-5738-4ce2-b219-cb557216890f | < 4.2.3 |
MEDIUM | 5.8 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file downloa… | — | wordfence |
| c434e6b8-0dd5-4ffe-93b1-1af614c08f85 | < 18.3 |
MEDIUM | 5.8 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and… | — | wordfence |
| c17b03b4-d503-4bee-a1cd-4d66d27f6f9e | < 8.6.7 |
MEDIUM | 5.8 | The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →