Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1088 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 499483a0-957b-459e-b2f5-fc39c4f86c9e | < 4.16.3 |
MEDIUM | 5.4 | The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does … | — | wordfence |
| 498f539a-f824-42fb-9df8-c1f82c4b3947 | < 1.2.0 |
MEDIUM | 5.4 | The Pootle Button plugin before 1.2.0 for WordPress has XSS via the assets_url parameter in assets/dialog.php, exploitab… | — | wordfence |
| 497c2f5f-ed7d-486e-baf2-aefbe3dc412f | < 1.8.0 |
MEDIUM | 5.4 | The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting… | — | wordfence |
| 49333c6b-58f6-4d5a-a605-46484160175a | < 1.3.2.5 |
MEDIUM | 5.4 | The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.… | — | wordfence |
| 490f5939-a990-4fb7-9515-f8dcee53d75a | < 3.1.9.1 |
MEDIUM | 5.4 | The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote a… | — | wordfence |
| 482c4986-3677-4754-992b-ea9be7573d2e | < 2.0.2 |
MEDIUM | 5.4 | The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Border He… | — | wordfence |
| 47cb48aa-b556-4f25-ac68-ff0a812972c1 | < 2.2.0 |
MEDIUM | 5.4 | The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to unauthorized access of data and modification… | — | wordfence |
| 479f7e9c-8918-4b87-b33d-a396276fb637 | < 1.1.45 |
MEDIUM | 5.4 | The OOPSpam Anti-Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence |
| 474494ad-6713-4167-b40d-c29c533f169e | < 3.0.4 |
MEDIUM | 5.4 | The Etsy Shop plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.3. … | — | wordfence |
| 4736d139-814e-4eeb-91e8-5ee41fc35a8f | < 4.16.8 |
MEDIUM | 5.4 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… | — | wordfence |
| 472cdbc4-3bfa-4254-b35a-be7ae10782e6 | < 1.12.8 |
MEDIUM | 5.4 | The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… | — | wordfence |
| 4688c1ee-335c-4adb-bd68-894ff34d001d | < 3.10.5 |
MEDIUM | 5.4 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in … | — | wordfence |
| 46828b2a-ed76-4074-9fb4-c36bf0fd012c | < 3.4.2 |
MEDIUM | 5.4 | The Logo Carousel WordPress plugin before 3.4.2 does not validate and escape the "Logo Margin" carousel option, which co… | — | wordfence |
| 462fcf4d-3ece-48d7-b06f-9a5de9372f5c | < 1.8.0 |
MEDIUM | 5.4 | The Cooked – Recipe Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… | — | wordfence |
| 46271ab0-5f24-4cdb-9e1f-12db7bcbea6c | < 1.6 |
MEDIUM | 5.4 | The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an… | — | wordfence |
| 4625072b-815d-41d2-bf8f-ac290efde369 | < 3.6.17 |
MEDIUM | 5.4 | The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to Stored Cross-S… | — | wordfence |
| 45f32160-36eb-4d66-a6a6-a3d6f2f7bf1a | < 2.4.1 |
MEDIUM | 5.4 | The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘website’ parameter in… | — | wordfence |
| 45d3f82b-9e19-4678-8995-7fe265606fd2 | MEDIUM | 5.4 | The IP Blocker Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… | — | wordfence | |
| 45adeeba-22b0-4758-bc21-afc019653ce8 | < 3.6.1 |
MEDIUM | 5.4 | WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to … | — | wordfence |
| 45a49dca-2ed2-44cf-a0fe-0f1440a78cc2 | < 4.4.0 |
MEDIUM | 5.4 | The package loader-utils before 1.4.1, from 2.0.0 and before 2.0.3 is vulnerable to prototype pollution via the function… | — | wordfence |
| 45851efe-2584-4b5e-8e4c-24f289d3bc32 | < 1.2.5 |
MEDIUM | 5.4 | The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.4… | — | wordfence |
| 457c4e56-c2a0-451f-a4a6-e7fb7bf7b0e0 | < 9.1.1 |
MEDIUM | 5.4 | The WP Recipe Maker plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 9.1.… | — | wordfence |
| 453c656a-c26d-44c3-bc7d-7fc502a00b03 | < 2.4 |
MEDIUM | 5.4 | The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output … | — | wordfence |
| 45180c8e-0625-4a21-b3a1-673abe52d78f | < 1.3.0 |
MEDIUM | 5.4 | The ARI Stream Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… | — | wordfence |
| 44e70eb9-f411-49da-b169-a5af8a9ace0c | < 5.11.2 |
MEDIUM | 5.4 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from la… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →