Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1250 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 8e0e6fdd-49d2-404a-83e8-c4884bbe7088 | < 4.6.4.3 |
MEDIUM | 4.9 | The Newsletters plugin for WordPress is vulnerable to directory traversal due to insufficient validation on the data sup… | — | wordfence |
| 8ddfafbf-3489-4d41-9ca7-d9757fd8cb04 | < 2.6.5 |
MEDIUM | 4.9 | The YaySMTP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.6.4 due to insuffici… | — | wordfence |
| 8d81c8d5-3862-4401-9226-9c7380f364a7 | < 3.6.32 |
MEDIUM | 4.9 | The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up… | — | wordfence |
| 8c881211-9f5f-4f93-8608-d91cf58f0f6d | < 1.5.1 |
MEDIUM | 4.9 | The SMTP for SendGrid β YaySMTP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … | — | wordfence |
| 8c046bf6-bc0d-45b1-9424-316ae6a01a3d | < 1.6.33 |
MEDIUM | 4.9 | The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… | — | wordfence |
| 8b9debd8-bb92-4966-a0b9-7920a447a313 | < 2.4.3 |
MEDIUM | 4.9 | The Import and export users and customers plugin for WordPress is vulnerable to Path Traversal in all versions up to 2.4… | — | wordfence |
| 8ae360d3-bd38-40f5-ac0f-7cb4f685fcbe | MEDIUM | 4.9 | The JiangQie Official Website Mini Program plugin for WordPress is vulnerable to SQL Injection in versions up to, and in… | — | wordfence | |
| 8a73b4c1-f5a8-44fc-9136-368b88468711 | < 3.0.3 |
MEDIUM | 4.9 | The Ϊ―Ψ±ΩΫΨͺΫ ΩΨ±Ω ΩΨ§Ψ±Ψ³Ϋ plugin for WordPress is vulnerable to SQL Injection in versions up to, and including,… | — | wordfence |
| 89a98053-33c7-4e75-87a1-0f483a990641 | < 3.3.1 |
MEDIUM | 4.9 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'fname' attr… | — | wordfence |
| 896384a7-0868-45b3-9ea6-20ff12169b58 | MEDIUM | 4.9 | The WP-PManager plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and in… | — | wordfence | |
| 8957413c-95e0-49c8-ba8a-02b9b5141e08 | < 5.5.4 |
MEDIUM | 4.9 | The WordPress Infinite Scroll β Ajax Load More plugin for WordPress is vulnerable to Directory Traversal in versions u… | — | wordfence |
| 8953c08c-78fd-415a-899d-99eba7ea1517 | MEDIUM | 4.9 | The SM Page Duplicator plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.0 due t… | — | wordfence | |
| 890aeff2-47f2-4377-879e-2254d45312dd | < 1.0.1 |
MEDIUM | 4.9 | The ZIP Code Based Content Protection plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… | — | wordfence |
| 8798e16d-84dd-40bb-b4ff-db800e850b0e | < 5.4.7 |
MEDIUM | 4.9 | The Poll Maker β Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injectio… | — | wordfence |
| 86dd9106-880d-49db-8021-4fac71ae865f | < 3.2.0 |
MEDIUM | 4.9 | The Automation By Autonami plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.2 d… | — | wordfence |
| 8698255b-6c03-464b-8cb5-191d3e77009f | < 2.1.13 |
MEDIUM | 4.9 | The SuperSaaS β online appointment scheduling plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… | — | wordfence |
| 867a0742-4fa9-4473-8d51-9abb6ec353a8 | < 4.11.85 |
MEDIUM | 4.9 | The Premium Addons for Elementor β Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored… | — | wordfence |
| 86090ab4-9f1d-4a92-a302-118524a5ffaa | < 7.1.0 |
MEDIUM | 4.9 | The WordPress Infinite Scroll β Ajax Load More plugin for WordPress is vulnerable to Path Traversal in all versions up… | — | wordfence |
| 85e70be3-3ed7-4ce1-a20c-046fb7c4ec31 | < 1.0.7 |
MEDIUM | 4.9 | The video carousel slider with lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in al… | — | wordfence |
| 84bad995-e653-46d6-96ff-e41cbac29b01 | < 1.6.9 |
MEDIUM | 4.9 | The Agile Store Locator plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 1.6.… | — | wordfence |
| 848cfa72-4211-4576-91c2-4f643e3161c3 | < 6.11.2 |
MEDIUM | 4.9 | The Formidable Forms β Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for Wo… | — | wordfence |
| 83c97e9b-a5bc-4059-8355-f93a7a36037c | < 4.3.4 |
MEDIUM | 4.9 | The YayMail plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.3.3 due to insuffici… | — | wordfence |
| 83455de5-4fb2-4782-8063-646d3daf29e5 | < 5.2.2 |
MEDIUM | 4.9 | The GSheetConnector β CF7 Google Sheets Connector with Real-Time Sync plugin for WordPress is vulnerable to generic SQ… | — | wordfence |
| 80fcaea8-5837-4d8c-afef-b9ed4fd31227 | < 2.2.3 |
MEDIUM | 4.9 | The WP Job Portal β A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … | — | wordfence |
| 8099e6b7-97d6-4b33-b664-d7423525094f | MEDIUM | 4.9 | The Easy Code Snippets plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.2 due t… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →