Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 121 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| e8ac60ae-f67e-4d62-a3a7-fb2e9b334ec9 | HIGH | 8.8 | The TuriTop Booking System plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, … | — | wordfence | |
| e89fc348-1146-4593-8bf5-127f783ab786 | < 8.1 |
HIGH | 8.8 | The WP Ultimate CSV Importer β WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Re… | — | wordfence |
| e89d912d-fa7a-4fb1-8872-95fa861c21ca | < 1.0.3 |
HIGH | 8.8 | The WP User Switch plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.2. … | — | wordfence |
| e865324e-a2a2-40fb-8c6a-a89317b59c8c | < 6.2.1 |
HIGH | 8.8 | The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| e84b1f01-1c3b-4498-aea9-02ced5f1109e | < 2.1.8 |
HIGH | 8.8 | An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php. | — | wordfence |
| e8336c89-44ac-4e41-bc81-7dae9599c050 | HIGH | 8.8 | The Widgets for WooCommerce Products on Elementor plugin for WordPress is vulnerable to Local File Inclusion in all vers… | — | wordfence | |
| e8263908-95b3-4b72-a9de-a982618eba2c | HIGH | 8.8 | The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc… | — | wordfence | |
| e7fcda2b-d679-44af-9592-4a96a0115a08 | < 19.1.5.1 |
HIGH | 8.8 | The Contest Gallery (Pro) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 d… | — | wordfence |
| e7fb6233-3f58-4237-aaaf-4bc60c5cc8ca | < 3.5 |
HIGH | 8.8 | The Erident Custom Login and Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-… | — | wordfence |
| e7ecd712-a7b3-40e2-b982-be8b58e9b8c3 | < 2.1.1 |
HIGH | 8.8 | The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the 'search[order_column][0]' POST parame… | — | wordfence |
| e7e83cee-f2c6-4de0-8801-fb63398f98fc | HIGH | 8.8 | The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter wh… | — | wordfence | |
| e7d7ec5b-0616-4895-b5bf-be25ac37fb17 | < 1.8 |
HIGH | 8.8 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer … | — | wordfence |
| e78f4832-6d14-4eef-8e4b-f4136b0c1902 | < 3.26.7 |
HIGH | 8.8 | The Wishlist Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and excluding, 3.2… | — | wordfence |
| e78097a6-6828-4d62-abf0-995a906ad68b | < 2.3.3 |
HIGH | 8.8 | The Button Generator WordPress plugin before 2.3.2 within the wow-company admin menu page allows to include() arbitrary … | — | wordfence |
| e73fd28f-51d0-44a3-8400-9148bb46ea18 | HIGH | 8.8 | The xSmart - App Landing Page WordPress Theme in Tech Presentation, Promo Marketing & Advertising Agency theme for WordP… | — | wordfence | |
| e70e2b73-0627-41a4-b3e8-3c23dfbc3dd5 | < 4.3.2 |
HIGH | 8.8 | The Estatik plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.3.1. This mak… | — | wordfence |
| e703d411-d608-43cc-8806-1d1e837cf797 | < 5.0.1 |
HIGH | 8.8 | The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or use… | — | wordfence |
| e702bb88-23b6-460e-829b-87f1adc1843f | HIGH | 8.8 | The I Draw plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versi… | — | wordfence | |
| e6e7889b-a1e2-439f-891d-c7c9a052cafc | HIGH | 8.8 | The Bulk Change Role plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the… | — | wordfence | |
| e6e114a3-8a17-4c79-9829-374646b53ed4 | < 5.0 |
HIGH | 8.8 | A SQL injection vulnerability in the Xpert Solution "Server Status by Hostname/IP" plugin 4.6 for WordPress allows an au… | — | wordfence |
| e6ac52eb-ced6-4888-becf-1294d34d3e88 | < 2.2.5 |
HIGH | 8.8 | The Rankology SEO β On-site SEO plugin for WordPress is vulnerable to unauthorized modification of data that can lead … | — | wordfence |
| e647d1ff-2d2c-43e4-b723-28ed410c4b3a | < 2.6.4 |
HIGH | 8.8 | The Classic Editor Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
| e62ad97d-2f66-4ee9-9062-4cdb74f76a3a | < 0.5.5 |
HIGH | 8.8 | The Kids Gift Shop theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in al… | — | wordfence |
| e620328e-f4f4-4f3a-8767-efbc676f72a4 | < 3.7.17 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authenti… | — | wordfence |
| e61f1835-2e56-40c8-b4b9-b3b9766d7e46 | HIGH | 8.8 | The Homepage PopUp plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →