Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1245 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d524b859-b61c-4c52-b4b3-76f2983c085a | < 4.2.0 |
MEDIUM | 4.9 | The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPre… | — | wordfence |
| d4ec4480-ed4a-4a8b-b19a-2b60e7fba0c7 | < 2.2.2 |
MEDIUM | 4.9 | The EKC Tournament Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includin… | — | wordfence |
| d4e04650-624a-4440-b166-8de0f24bb1dd | < 1.13.1 |
MEDIUM | 4.9 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is… | — | wordfence |
| d39a85fe-8cae-4ba1-b100-fbfa5a08df67 | < 6.18.13 |
MEDIUM | 4.9 | The SeedProd Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.18.12 due to in… | — | wordfence |
| d230b781-e208-4e66-b8ed-aba72db8d8dc | < 11.1.3 |
MEDIUM | 4.9 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind S… | — | wordfence |
| d156f277-88cb-43aa-895c-63684aa1466e | < 1.1.21 |
MEDIUM | 4.9 | The OttoKit plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.20 due to insuffic… | — | wordfence |
| d0fbf502-2dfb-49e5-94a6-1525aabc08c1 | < 1.4.7 |
MEDIUM | 4.9 | The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up t… | — | wordfence |
| d0d58775-13c1-4926-9015-554106a1d0f5 | < 2.6.5 |
MEDIUM | 4.9 | The AI Engine plugin for WordPress is vulnerable to SQL Injection via the 'value' parameter in all versions up to, and i… | — | wordfence |
| d0d4bbcc-4a91-404d-8d07-de0d552f46cd | < 2.1.1 |
MEDIUM | 4.9 | The Melapress File Monitor plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.1… | — | wordfence |
| CVE-2026-3523 | MEDIUM | 4.9 | The Apocalypse Meow plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, … | — | nvd | |
| CVE-2026-2831 | MEDIUM | 4.9 | The MailArchiver plugin for WordPress is vulnerable to SQL Injection via the ‘logid’ parameter in all versions up to… | — | nvd | |
| cfefcc38-764d-4dd9-b098-cdcad475d634 | < 1.3.9 |
MEDIUM | 4.9 | The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and … | — | wordfence |
| cec0d64e-7b31-4484-8237-2ab4d730ab86 | < 3.8.9 |
MEDIUM | 4.9 | The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in a… | — | wordfence |
| ce47c956-5b19-43e4-8e04-9e7f68aeb924 | MEDIUM | 4.9 | The Upunzipper plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 1.0.0… | — | wordfence | |
| ce1e944b-1ee9-4400-a182-d505381cb007 | < 3.3.0 |
MEDIUM | 4.9 | The Captivate Sync plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.2 due to in… | — | wordfence |
| cde440a2-55f8-406a-b81b-919028f0e887 | MEDIUM | 4.9 | The AHAthat Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions… | — | wordfence | |
| cc90d500-b338-43ff-aac7-14a42d3d16b8 | < 10.14.16 |
MEDIUM | 4.9 | The Booking Calendar plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 10.14.15 due … | — | wordfence |
| cc7c7e21-fbd7-4451-bc7d-3d11db01a443 | MEDIUM | 4.9 | The Read More & Accordion plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' paramet… | — | wordfence | |
| cc116b88-6610-4383-a6a7-5528e1a16ba9 | < 2.1.3 |
MEDIUM | 4.9 | The Hover Effects plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.2 due to ins… | — | wordfence |
| cad821ec-04f5-4cff-8846-628d183502fd | < 1.3.1 |
MEDIUM | 4.9 | The YaySMTP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3 due to insufficien… | — | wordfence |
| c6372bcd-ae01-4fe4-ac9e-4f3c34c34416 | < 16.26.12 |
MEDIUM | 4.9 | The WP-Recall plugin for WordPress is vulnerable to SQL Injection via the 'product[fields]' parameter in all versions up… | — | wordfence |
| c5cff14e-e891-4569-afd8-2885ebb26401 | < 1.9.3 |
MEDIUM | 4.9 | The Hot Random Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in a… | — | wordfence |
| c55404f8-f928-4ed8-af60-a8dec103ce78 | < 1.5.9 |
MEDIUM | 4.9 | The Product Labels For Woocommerce (Sale Badges) plugin for WordPress is vulnerable to SQL Injection in all versions up … | — | wordfence |
| c536ae81-cf30-4af4-8b79-ee5dd03a4751 | < 2.4.8 |
MEDIUM | 4.9 | The AI Engine plugin for WordPress is vulnerable to SQL Injection via the sort[accessor] parameter in all versions up to… | — | wordfence |
| c532fc06-1ddd-4472-a5aa-10d7c8688d36 | < 1.5.1 |
MEDIUM | 4.9 | The CSS JS Files plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.0 via th… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →