Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1021 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2214264d-0f3e-455b-9420-c6a1e0d7562c | < 2.10.6 |
MEDIUM | 5.8 | The Simple Job Board plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fu… | — | wordfence |
| 1f2cfb14-1076-492f-8a1b-ae04b47dc6fa | < 2.4.6 |
MEDIUM | 5.8 | The Chatbot with ChatGPT WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca… | — | wordfence |
| 149eb7ef-be96-442e-925e-01d8d76e3a1a | < 3.7.32 |
MEDIUM | 5.8 | In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in t… | — | wordfence |
| 10b9d703-de9d-472a-bdfb-bc9a41bf375e | < 6.30.16 |
MEDIUM | 5.8 | The WP Compress β Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Server-Side Request F… | — | wordfence |
| 046f1f8d-9e87-4ede-bcb8-56614a1f3235 | < 1.5.5 |
MEDIUM | 5.8 | … | — | wordfence |
| 035ada56-541d-47b3-8348-3401d94bb509 | < 3.1.76 |
MEDIUM | 5.8 | The Cost Calculator Builder PRO for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, … | — | wordfence |
| 009a9210-531c-4b6c-83b6-8c97a4f492bd | < 2.5 |
MEDIUM | 5.8 | The Contact Form 7 plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.4. This i… | — | wordfence |
| e9caf6a8-d7f6-4686-889a-79ba9cf911c4 | MEDIUM | 5.7 | The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admi… | — | wordfence | |
| bc6a8c0e-1136-41ff-bfc2-450434aa6326 | < 3.7.34 |
MEDIUM | 5.7 | In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external… | — | wordfence |
| baae8fb9-b87c-4f61-88da-871c4c83615b | < 6.0.10 |
MEDIUM | 5.7 | The Essential Addons for Elementor β Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for … | — | wordfence |
| a68f024d-b80d-4e6c-8420-5e0dde87d8f0 | < 2.7.0 |
MEDIUM | 5.7 | The ALO EasyMail Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
| 80b3c2d3-b8dc-429f-b2d7-6a697ad47a9a | < 2.1.2 |
MEDIUM | 5.7 | The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq … | — | wordfence |
| 659ef2e8-589c-4901-88ce-1d674c056ece | < 1.6.9 |
MEDIUM | 5.7 | The Responsive Addons for Elementor β Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vul… | — | wordfence |
| 585a7332-b063-463c-8077-68a860e14df2 | < 1.6.1 |
MEDIUM | 5.7 | The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate … | — | wordfence |
| 19e6bd3b-8d03-4617-8be2-3cdaeb85fac0 | < 1.8.1 |
MEDIUM | 5.7 | The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most … | — | wordfence |
| c929a742-6481-40a0-94b5-76ddb8494896 | < 3.8.3 |
MEDIUM | 5.6 | The Clerk plugin for WordPress is vulnerable to Authorization Bypass via Insufficient Validation in versions up to, and … | — | wordfence |
| bf04f458-7900-4dd3-84fb-169b74db97ab | < 2.1.6.3 |
MEDIUM | 5.6 | The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass… | — | wordfence |
| b43371a6-bcb5-4418-b5a5-85879775010c | < 4.3.4 |
MEDIUM | 5.6 | The App Builder β Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to limited SQL Inj… | — | wordfence |
| 8e38553d-5dba-4c84-95f7-43420245c770 | < 5.0.19 |
MEDIUM | 5.6 | The Ninja Tables β Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions … | — | wordfence |
| 8b4a47f7-0161-4a57-994f-c48795810ea3 | < 1.7.5 |
MEDIUM | 5.6 | The The Contact Form, Survey, Quiz & Popup Form Builder β ARForms plugin for WordPress is vulnerable to arbitrary shor… | — | wordfence |
| 3faf976d-0763-4e47-9bc3-18c791ec4487 | MEDIUM | 5.6 | The UltimateAI plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.8.3. … | — | wordfence | |
| 1d2da608-81a4-47b5-b23d-d18ab7bc2aa9 | < 3.6.5.6 |
MEDIUM | 5.6 | The AI WP Writer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several … | — | wordfence |
| 11d45287-f875-4cc9-aaf6-47158fe32858 | < 1.9.8 |
MEDIUM | 5.6 | The Everest Forms (Pro) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,… | — | wordfence |
| ff656409-2344-4190-a731-5a282e21375c | < 2.7 |
MEDIUM | 5.5 | The Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to… | — | wordfence |
| ff1f81e8-64ed-4330-9c76-1a8d2e2d307d | < 2.11.23 |
MEDIUM | 5.5 | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'order_mail' setting in… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →