Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 119 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ececa0ea-3d44-4b1b-b962-809a8b24c890 | < 4.7.9 |
HIGH | 8.8 | The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| ecdfb19e-ef3a-4c5a-96a5-4c9ce3dca3a6 | HIGH | 8.8 | The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow a… | — | wordfence | |
| ec83bf1f-a2da-4ecf-8d82-9a555c751073 | < 1.8.3 |
HIGH | 8.8 | The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solu… | — | wordfence |
| ec7b77d8-490e-4eaf-a9df-54de63f128d4 | HIGH | 8.8 | The E Unlocked - Student Result plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … | — | wordfence | |
| ec6331e1-7a7c-486d-873b-02b3af38387c | < 2.4.1 |
HIGH | 8.8 | The wp-d3 plugin before 2.4.1 for WordPress has CSRF. | — | wordfence |
| ec5fa360-6fff-46f5-8221-4b28a6db3e73 | < 1.1.1 |
HIGH | 8.8 | The JSON REST API plugin for WordPress is possibly vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| ec281e0d-0217-4cdd-af31-71158bb3a25d | < 2.1 |
HIGH | 8.8 | The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plug… | — | wordfence |
| ec20d5c4-4c41-4ec9-8d0a-ec8f03634f7d | < 4.2.6.6 |
HIGH | 8.8 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file… | — | wordfence |
| ec162cdc-d4cd-47d9-b941-24bfee6c48fd | < 3.2.29 |
HIGH | 8.8 | The Front End Users plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all … | — | wordfence |
| ebd6acc9-b7df-4cf8-a211-1e39f3abcf79 | < 1.2.0 |
HIGH | 8.8 | The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and… | — | wordfence |
| ebc0c8e6-a365-4ef7-9c1a-41454855096c | < 1.5.105 |
HIGH | 8.8 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based … | — | wordfence |
| eb89a16c-fae0-4d36-85aa-79beab753cba | < 1.9.9.41 |
HIGH | 8.8 | The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_bett… | — | wordfence |
| eb85faa4-0261-4fb0-a70d-9fb03170e032 | HIGH | 8.8 | The QRMenu Restaurant QR Menu Lite plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inc… | — | wordfence | |
| eb85ed32-c391-45d2-9e86-cb97009210cd | HIGH | 8.8 | The Integração entre Eduzz e Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due t… | — | wordfence | |
| eb6ac547-59fd-4d51-a140-06f7f70a43ab | < 4.5 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows r… | — | wordfence |
| eb3aa518-ef12-4168-a524-ad36397f67cb | < 1.2.3 |
HIGH | 8.8 | The Dbox 3D Slider Lite plugin through 1.2.2 for WordPress has SQL Injection via settings\sliders.php (current_slider_id… | — | wordfence |
| eb32a095-7d2b-4a57-9d91-f79fb3486f9a | < 1.0.1 |
HIGH | 8.8 | The Copy or Move Comments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in… | — | wordfence |
| eb23c4d7-d9be-4162-bb7b-8a74f3c339eb | < 2.2.36 |
HIGH | 8.8 | The Events Made Easy WordPress plugin before 2.2.36 does not sanitise and escape the search_text parameter before using … | — | wordfence |
| eb06c43c-bf8c-412b-8b1d-fee004d728d2 | < 0.0.8 |
HIGH | 8.8 | The PlugVersions – Easily rollback to previous versions of your plugins plugin for WordPress is vulnerable to arbitrar… | — | wordfence |
| eb022e51-32fd-403e-a9b3-34114e957020 | < 4.6.16 |
HIGH | 8.8 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to arbitrary file uploads due to mi… | — | wordfence |
| eade6ab0-ff79-4107-83ce-e85b37d97442 | < 5.25.10 |
HIGH | 8.8 | The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in ve… | — | wordfence |
| eac9d9b5-6812-4fe2-9427-500d4bb2ea09 | HIGH | 8.8 | The WP Opt-in plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1. … | — | wordfence | |
| ea99795f-45fa-4d4c-a6bd-2197b58efcb2 | < 3.0 |
HIGH | 8.8 | The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| ea6c7b63-00da-4476-a024-97fe99af643d | < 0.1.0.84 |
HIGH | 8.8 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery … | — | wordfence |
| ea615395-2c63-415d-b0bf-6bd2489ad540 | < 1.0.1 |
HIGH | 8.8 | The RealHomes CRM plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in al… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →