Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1248 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ab807beb-0e20-47e4-be3e-9e8f50b84c7b | < 8.7.16 |
MEDIUM | 4.9 | The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to SQL Inject… | — | wordfence |
| aa6874e5-d99d-4d20-aaf7-897fe8f05292 | < 2.21.11 |
MEDIUM | 4.9 | The Bit Form plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.21.10 due to insuff… | — | wordfence |
| aa5b6311-d9ca-4736-a6e3-56c6746b2470 | < 1.4.6 |
MEDIUM | 4.9 | The FOX plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.5 due to insufficient … | — | wordfence |
| aa46842f-ed07-4f72-aedb-aa27baecd79c | < 2.15.3 |
MEDIUM | 4.9 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil… | — | wordfence |
| a9bffba4-5bcd-4ef7-a8d8-84ba452827ab | < 3.1.2 |
MEDIUM | 4.9 | Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administ… | — | wordfence |
| a919c252-c468-48be-a4e4-f5524419d8f9 | < 1.5.6 |
MEDIUM | 4.9 | The YayExtra plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.5 due to insuffic… | — | wordfence |
| a7ef66cf-ddf1-42be-82b1-cb6edcbf253c | MEDIUM | 4.9 | The WP Online Users Stats plugin for WordPress is vulnerable to time-based SQL Injection via the ‘table_name’ parame… | — | wordfence | |
| a7aa2246-aee9-4992-b030-97e78e3b7d22 | < 2.4.6 |
MEDIUM | 4.9 | The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to time-based blind SQL Injection v… | — | wordfence |
| a6e513cc-5008-4f59-87c1-2a1b42d98850 | < 1.9.2 |
MEDIUM | 4.9 | The TrackShip for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9.… | — | wordfence |
| a55af7fd-5f45-4978-b2b9-636b33297deb | < 6.0.6 |
MEDIUM | 4.9 | The Premium Packages plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.0.5 due to … | — | wordfence |
| a43dd1a8-4710-4cbc-920b-582e29d7ce98 | MEDIUM | 4.9 | The SC filechecker plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 0… | — | wordfence | |
| a3bb387c-3f4c-450e-bc3f-4524378bac93 | < 1.1.15 |
MEDIUM | 4.9 | The Kargo Entegratör plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.14 due t… | — | wordfence |
| a3779501-4ac7-4b76-8b2b-9852c6467f16 | < 3.7.19 |
MEDIUM | 4.9 | In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin del… | — | wordfence |
| a2399535-c293-4b06-8ef4-1706bbe12bf7 | < 3.6.21 |
MEDIUM | 4.9 | The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordP… | — | wordfence |
| a1af9757-23e9-41d2-bbcd-15b0610b6538 | < 23.0.0 |
MEDIUM | 4.9 | The Apocalypse Meow plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, … | — | wordfence |
| a0f55f3e-9a9a-42a7-91b5-0d515519d545 | < 1.8.15 |
MEDIUM | 4.9 | The Photo Gallery plugin by 10Web for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1… | — | wordfence |
| a0e9e803-8f52-4210-9c28-fe0438487a4b | MEDIUM | 4.9 | The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Directory Traversal in all ve… | — | wordfence | |
| a0d38788-5f90-4ab1-8df1-1c67c1052e6d | < 14.7 |
MEDIUM | 4.9 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' para… | — | wordfence |
| a0289458-7ffb-4e9c-a685-7d38664fe701 | MEDIUM | 4.9 | The iCafe Library plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.8.3 due to ins… | — | wordfence | |
| 9ef89bd0-e1f6-4818-a5e6-857fae7cf231 | < 1.5.7 |
MEDIUM | 4.9 | The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection in all versions up to 1.5.7. This is due to ins… | — | wordfence |
| 9e4cff1c-6a01-4725-9e37-f48b5de16d9b | < 1.0.13 |
MEDIUM | 4.9 | The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and… | — | wordfence |
| 9e21d279-aa83-42ff-9906-bc61dc4aba52 | < 2.10 |
MEDIUM | 4.9 | The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to arbitrary… | — | wordfence |
| 9d637d7b-7a47-40db-a931-ec7ca723dfab | < 4.0.2 |
MEDIUM | 4.9 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via t… | — | wordfence |
| 9c7aeef5-b87e-4cd0-9374-93b7f67a9187 | < 3.0.5 |
MEDIUM | 4.9 | The Taskbuilder – WordPress Project & Task Management plugin plugin for WordPress is vulnerable to SQL Injection via t… | — | wordfence |
| 9bdfa6e8-0bf6-4ca5-b145-af66d99dbf6c | < 14.4 |
MEDIUM | 4.9 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Paramete… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →