Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1244 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| e424d27b-f719-4fbf-b4eb-83b42130666c | MEDIUM | 4.9 | The ProjectList plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up… | — | wordfence | |
| e3d231e1-a63e-4b41-a6b7-91e6dfc33600 | < 4.2.7 |
MEDIUM | 4.9 | The Groundhogg β CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to SQL Injection via th… | — | wordfence |
| e289988c-8bc1-4b2a-87a2-c94758d10e88 | MEDIUM | 4.9 | The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injection via the βpathβ parameter in all ve… | — | wordfence | |
| e1531898-c6f6-4841-a03b-bbcd841b76cc | < 4.29.1 |
MEDIUM | 4.9 | The YITH WooCommerce Product Add-Ons plugin for WordPress is vulnerable to SQL Injection in versions up to, and includin… | — | wordfence |
| e1089e3e-9d81-4e4b-9703-403029f5265c | < 2.5.7 |
MEDIUM | 4.9 | The WC Vendors Marketplace plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5.6 d… | — | wordfence |
| e049e3d4-5168-4e1b-8128-8d42df1db2fd | < 1.0.17 |
MEDIUM | 4.9 | The Cart tracking for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … | — | wordfence |
| dfd969b8-b88e-4d75-9d69-5f290b111fc7 | < 3.8.9 |
MEDIUM | 4.9 | The affiliate-toolkit β Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-ba… | — | wordfence |
| dfb59bca-0653-4e75-8da1-e78e5d659422 | < 1.19.3 |
MEDIUM | 4.9 | The Mail Mint plugin for WordPress is vulnerable to blind SQL Injection via the 'forms', 'automation', 'email/templates'… | — | wordfence |
| df790bbc-7427-4f7e-9aa2-e137c9fceffd | < 2.7.1 |
MEDIUM | 4.9 | The WC Vendors β WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable … | — | wordfence |
| df67e870-d600-46d3-88cc-058d8b9d30c9 | < 2.10.23 |
MEDIUM | 4.9 | The Sender β Newsletter, SMS and Email Marketing Automation for WooCommerce plugin for WordPress is vulnerable to SQL … | — | wordfence |
| df5fc86f-e4ba-424b-bece-79abd763cf74 | < 2.1.3 |
MEDIUM | 4.9 | The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in impor… | — | wordfence |
| deb912f0-bfba-470f-9a18-47c3d65905dc | < 1.0.9.2 |
MEDIUM | 4.9 | The Transposh WordPress Translation plugin for WordPress is vulnerable to SQL Injection via the 'order' and 'orderby' pa… | — | wordfence |
| ddd2c5d9-6489-4154-a494-20392f435bc6 | < 0.9.5 |
MEDIUM | 4.9 | The W3 Total Cache plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 0.9.4… | — | wordfence |
| ddbd4940-fe1c-46f0-9148-53c5a4095785 | MEDIUM | 4.9 | The ResAds plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.5 due to insufficie… | — | wordfence | |
| dbfb3895-6826-4c2d-9959-b3a9d3f175f5 | MEDIUM | 4.9 | The WP Profitshare plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.9 due to in… | — | wordfence | |
| dba84eb3-f48a-4175-a652-7c11b12c9afc | < 2.6.1 |
MEDIUM | 4.9 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all version… | — | wordfence |
| db14e2b8-3217-4f81-a44e-e50734ef304c | < 9.2.04.003 |
MEDIUM | 4.9 | The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all ver… | — | wordfence |
| d9938c7d-ef0d-45a2-900f-ac8bda9ce75a | < 2.4.1 |
MEDIUM | 4.9 | The Booking Calendar | Appointment Booking | BookIt plugin for WordPress is vulnerable to Price Bypass in versions up to… | — | wordfence |
| d8ecb2c6-c2d0-44b0-b9c2-4fcbc0f97632 | < 6.2.0 |
MEDIUM | 4.9 | The Kirki β Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traver… | — | wordfence |
| d8c11ebc-5c83-46a2-a8dd-b838cd50ddc6 | < 1.6.4 |
MEDIUM | 4.9 | The EmailKit β Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to arbitrary file read via pat… | — | wordfence |
| d81b2927-f855-48f2-b7ae-f1411bee0040 | < 2.6 |
MEDIUM | 4.9 | The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_f… | — | wordfence |
| d7dc74e2-fa6d-4d4c-b27c-d77c3688ed15 | < 3.0.13 |
MEDIUM | 4.9 | The License Manager for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including… | — | wordfence |
| d7d08144-82b8-4f2e-8410-41bae20da00f | MEDIUM | 4.9 | The Nearby Locations plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.1 due to … | — | wordfence | |
| d774bd22-4d4e-42d4-b4ae-c833dd36aa79 | < 4.44.4 |
MEDIUM | 4.9 | The PagBank / PagSeguro Connect para WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'status' pa… | — | wordfence |
| d6eba6da-ac14-4914-a807-6e234b80ee71 | < 2.5.1 |
MEDIUM | 4.9 | The ClickWhale β Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →