Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 122 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| e61396d0-9396-449c-b8c4-53fc4e2c57bb | < 3.3.0 |
HIGH | 8.8 | The Post SMTP β WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications β Gmail SMTP, Office 365, Br… | — | wordfence |
| e5ce4685-547c-40d2-9498-e50f390deeea | < 2.8.1 |
HIGH | 8.8 | The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Privilege Escalation in all versions up… | — | wordfence |
| e5ca3c84-9d3d-4bbe-90f7-44c9d77a6690 | < 2.2.3 |
HIGH | 8.8 | The Plugin for Google Reviews for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence |
| e5b01e96-63e6-4ba0-8c83-f9b05e4050b3 | < 4.0.9 |
HIGH | 8.8 | The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.7. This mak… | — | wordfence |
| e5aa9b71-67e4-4049-8dd4-23b76dbd87bb | < 3.29.10 |
HIGH | 8.8 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i… | — | wordfence |
| e597b677-e298-4507-86a5-70a93a9afd6e | < 1.4.14 |
HIGH | 8.8 | The SpiderCalendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… | — | wordfence |
| e579b7fd-141f-4d5f-9e0e-a1e6b985f0b9 | < 1.31 |
HIGH | 8.8 | The ClickBank Affiliate Ads WordPress plugin before 1.31 does not have CSRF check when saving its settings, allowing att… | — | wordfence |
| e55b86e2-b42e-483d-93cd-2f09af64dbc7 | < 2.2 |
HIGH | 8.8 | The Elements For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includi… | — | wordfence |
| e556d8c9-3ca5-4bec-a840-7a6d67532e59 | < 2.0.40 |
HIGH | 8.8 | An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.0.39 for WordPress. It is possible (due… | — | wordfence |
| e54f98bc-c538-4f3c-b24a-6e778a3748ef | < 2.2.17 |
HIGH | 8.8 | The School Management System β WPSchoolPress plugin for WordPress is vulnerable to Privilege Escalation due to a missi… | — | wordfence |
| e53bb240-8784-4d34-8d3f-4a7af917f3f4 | < 4.3.5 |
HIGH | 8.8 | The Simple Membership plugin for WordPress is vulnerable to account takeover due to missing input validation on the proc… | — | wordfence |
| e52c95b3-0126-4139-9944-6becef4c4d53 | HIGH | 8.8 | The Widget Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.… | — | wordfence | |
| e5240171-6051-455c-b6df-630e2cd8308d | < 1.2.5 |
HIGH | 8.8 | The Testimonial Slider plugin through 1.2.4 for WordPress has SQL Injection via settings\sliders.php (current_slider_id … | — | wordfence |
| e4e6e410-5778-41f7-a259-daa506bfb161 | HIGH | 8.8 | The Media File Manager Advanced plugin for WordPress is vulnerable to Local File Disclosure, SQL Injection, Cross-Site S… | — | wordfence | |
| e4b16cf2-7e29-47c5-921e-188e2db33084 | < 1.7.2 |
HIGH | 8.8 | The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, a… | — | wordfence |
| e4966f96-713c-471f-8f36-55977a547f12 | < 3.1.0.2 |
HIGH | 8.8 | The Easy Digital Downloads plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 3.1.0.1… | — | wordfence |
| e4930b03-9142-464e-98ae-a910dfa46f2a | < 1.6.7.9 |
HIGH | 8.8 | The Appointment Booking Calendar β Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to S… | — | wordfence |
| e491cdac-4946-41aa-91c1-92e56e862090 | < 3.7 |
HIGH | 8.8 | The Hotel Booking plugin for WordPress is vulnerable to Local File Inclusion via the nd_booking_ss_rooms() function in v… | — | wordfence |
| e489a90e-f226-4900-938c-b5a7550d199c | < 4.68 |
HIGH | 8.8 | The SP Project & Document Manager plugin for WordPress is vulnerable to SQL Injection via an unknownparameter in versio… | — | wordfence |
| e489960e-254a-4b8d-85ab-0f749ff48e8c | < 7.1.2 |
HIGH | 8.8 | The Media Library Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence |
| e4632899-c3bf-48f3-8a69-8fa32bfd902d | < 3.16.3 |
HIGH | 8.8 | The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privileg… | — | wordfence |
| e4421c1b-742c-4307-9736-d6263bab4ae4 | < 1.7.9 |
HIGH | 8.8 | The WP ALL Export Pro plugin for WordPress is vulnerable to SQL Injection via the cc_sql parameter in versions up to, a… | — | wordfence |
| e437ef90-5321-4543-a4ef-716b898315eb | < 2.5 |
HIGH | 8.8 | The My wpdb plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.12. T… | — | wordfence |
| e4045a2b-2bbc-4335-b6d2-af7a046f1f92 | HIGH | 8.8 | The AP Background plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization and insuffic… | — | wordfence | |
| e3e340b8-4eed-4622-b7c4-73d5bafb7e8e | < 1.7 |
HIGH | 8.8 | The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users. | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →