Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,369 vulnerabilities found (page 1063 of 1615)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2026-5077 | MEDIUM | 5.4 | The Total theme for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and includ… | — | nvd | |
| CVE-2026-2732 | < 4.1.8 |
MEDIUM | 5.4 | The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capa… | — | nvd |
| CVE-2026-2694 | < 6.15.16.1 |
MEDIUM | 5.4 | The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to … | — | nvd |
| CVE-2026-2284 | MEDIUM | 5.4 | The News Element Elementor Blog Magazine plugin for WordPress is vulnerable to Missing Authorization in all versions up … | — | nvd | |
| CVE-2026-2127 | MEDIUM | 5.4 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to unauthorized arbitrary shortcode execution in all ve… | — | nvd | |
| cf96887c-6e0d-43d9-a3f2-88981adb4c98 | < 1.3.2.5 |
MEDIUM | 5.4 | The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.… | — | wordfence |
| ceeefc3f-1cb7-48df-9978-258f015d93c7 | < 1.13.6 |
MEDIUM | 5.4 | The Easy Image Collage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check… | — | wordfence |
| ceb25902-9dcb-4aba-bee2-893f5cdadebc | MEDIUM | 5.4 | The The xsmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, … | — | wordfence | |
| ceb08ca9-e512-4a97-b323-cd9447b8bcac | < 1.9.17 |
MEDIUM | 5.4 | The Academy LMS plugin for WordPress is vulnerable to unauthorized access due to insufficient validation on the enroll_c… | — | wordfence |
| ce8e5635-a343-40b4-838c-21b942af5242 | < 1.2.13 |
MEDIUM | 5.4 | Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allo… | — | wordfence |
| ce5f4960-e47c-4926-97f2-8c94c438a4e0 | < 3.3.12 |
MEDIUM | 5.4 | The “Sina Extension for Elementor” WordPress Plugin before 3.3.12 has several widgets that are vulnerable to stored … | — | wordfence |
| ce4ca9c6-7ffd-4170-9004-f7bc3ad15df0 | < 2.6.2 |
MEDIUM | 5.4 | Stored XSS in the IMPress for IDX Broker WordPress plugin before 2.6.2 allows authenticated attackers with minimal (subs… | — | wordfence |
| ce3a3802-ea03-4840-8da2-fd292a0c4099 | MEDIUM | 5.4 | The WP Nice Loader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… | — | wordfence | |
| ce2edda2-7707-415e-9493-e1067a421f54 | MEDIUM | 5.4 | The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_… | — | wordfence | |
| ce060989-ce70-49ac-921c-a687bc944090 | < 4.0.0 |
MEDIUM | 5.4 | The Mass Delete Taxonomies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| cdee0cd8-b83b-4436-aebe-533f5af03ef1 | < 1.13.5 |
MEDIUM | 5.4 | The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Req… | — | wordfence |
| cde8c669-c9bb-4ecc-b589-3cda8757dfc6 | MEDIUM | 5.4 | The Logaster Logo Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence | |
| cdd464ad-24bc-4922-8bfa-ac42fbe60b52 | < 1.3.60 |
MEDIUM | 5.4 | The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_requir… | — | wordfence |
| cd4d67cd-5fb0-425d-8b22-c69ebb0ffa72 | < 1.3.53 |
MEDIUM | 5.4 | The Falang multilanguage for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a … | — | wordfence |
| cd4c2c11-2d73-48b4-8e7e-e281451973a2 | < 5.0 |
MEDIUM | 5.4 | The The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Cu… | — | wordfence |
| ccee37f3-4120-46fb-a201-346994d4d55b | < 1.4.1 |
MEDIUM | 5.4 | The Simple Photo Feed plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… | — | wordfence |
| cca2bd96-ac3c-480c-8fe7-fb5227a093ae | < 5.10.3 |
MEDIUM | 5.4 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W… | — | wordfence |
| cbb31cc2-d221-4e2c-a4de-e954d3c9069d | < 1.4.0 |
MEDIUM | 5.4 | The Kenta Blocks – Responsive Blocks and block templates library plugin for WordPress is vulnerable to Stored Cross-Si… | — | wordfence |
| cb7335c0-b6ed-43bb-91b7-870093d14cb8 | < 7.2.0 |
MEDIUM | 5.4 | The Image Regenerate & Select Crop plugin for WordPress is vulnerable to unauthorized modification of data due to a miss… | — | wordfence |
| cb7316cd-8a15-4b81-b57c-b8e4adcaf1ef | MEDIUM | 5.4 | The WHA Crossword plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →