Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1253 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 6222d255-47cc-469a-850d-fc11d7860d75 | < 3.11.0 |
MEDIUM | 4.9 | The Funnel Builder by FunnelKit plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.… | — | wordfence |
| 61bac919-90be-4fb5-859a-d135e87fe0bb | < 4.10.19 |
MEDIUM | 4.9 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's onCl… | — | wordfence |
| 61b28b8c-4588-4b4e-85e8-d3d37b791f3d | < 4.5.1 |
MEDIUM | 4.9 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & News… | — | wordfence |
| 6186fe48-fc5c-44e3-b998-7d84acb1869e | MEDIUM | 4.9 | The WP Employee Attendance System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … | — | wordfence | |
| 60d7a5c1-7006-412d-897f-16c3105c20c4 | MEDIUM | 4.9 | The MindValley Super PageMash plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1 … | — | wordfence | |
| 604e81a2-62ba-49c6-81f4-bab2ad8419c2 | < 4.7.4 |
MEDIUM | 4.9 | The PublishPress Authors plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.7.3 due… | — | wordfence |
| 602bf9b1-17a9-441a-b12d-15412df2deb4 | < 2.33 |
MEDIUM | 4.9 | The WordPress Report Brute Force Attacks and Login Protection ReportAttacks Plugins plugin for WordPress is vulnerable t… | — | wordfence |
| 5f7b15ba-5d7b-448d-ae95-b7d3ae7ff1c0 | < 2.11.2 |
MEDIUM | 4.9 | The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.11.1 … | — | wordfence |
| 5f5a1eb3-3fda-49de-aefb-2205c9ca3520 | < 1.45.1 |
MEDIUM | 4.9 | The Forminator Forms β Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-bas… | — | wordfence |
| 5f4e6daf-9f89-4f34-ad07-82f63fd730da | < 2.1.8 |
MEDIUM | 4.9 | The BetterLinks plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.7 due to insuf… | — | wordfence |
| 5f0406ad-8f4e-49a2-87dd-a6e319904652 | < 8.7.9 |
MEDIUM | 4.9 | The NEX-Forms β Ultimate Form Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and inclu… | — | wordfence |
| 5edd7fba-77d1-4a13-ad31-0135ec83c2a1 | MEDIUM | 4.9 | The Link to URL / Post plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.3 due… | — | wordfence | |
| 5e4ab6c3-fa9a-4643-aaf5-eabbdf909f9f | < 1.2.24 |
MEDIUM | 4.9 | The Email Subscription Popup plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.2… | — | wordfence |
| 5e383b8a-27e5-4b35-8d11-6e4102255d44 | < 1.15.41 |
MEDIUM | 4.9 | The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate',… | — | wordfence |
| 5e16a3e2-79db-4647-9712-03ae666feac4 | MEDIUM | 4.9 | The WP Post Corrector plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.2 due to… | — | wordfence | |
| 5cb80db2-753c-40fa-aee4-7d8c1749d037 | < 3.3.20 |
MEDIUM | 4.9 | The LWS Optimize β All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in… | — | wordfence |
| 5bd95df9-4355-4d57-ba44-59280463e284 | < 1.0.8 |
MEDIUM | 4.9 | The BFG Tools β Extension Zipper plugin for WordPress is vulnerable to Path Traversal in all versions up to, and inclu… | — | wordfence |
| 5bc8da1b-8095-46b5-8268-63bdddb4e629 | < 4.5.1 |
MEDIUM | 4.9 | The MailArchiver plugin for WordPress is vulnerable to SQL Injection via the βlogidβ parameter in all versions up to… | — | wordfence |
| 5a7e8284-d70f-4448-8f0d-99c23b8eda79 | < 5.4.7 |
MEDIUM | 4.9 | The Poll Maker β Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to time-based SQL Injec… | — | wordfence |
| 5a6cda1f-8af9-44b1-98e2-619d29c28a88 | < 4.1.9 |
MEDIUM | 4.9 | The CAOS | Host Google Analytics Locally WordPress plugin before 4.1.9 does not validate the cache directory setting, al… | — | wordfence |
| 59f622ee-eccf-4b5b-8fa0-93a4405eb1e9 | < 7.3.2 |
MEDIUM | 4.9 | The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versio… | — | wordfence |
| 590720a3-1881-4a5d-b004-ad92d386afe6 | < 13.7.4 |
MEDIUM | 4.9 | The Quick Featured Images plugin for WordPress is vulnerable to SQL Injection via the 'delete_orphaned' function in all … | — | wordfence |
| 58e1a5a1-800f-45e8-a356-759ba568d7c5 | < 1.7.2 |
MEDIUM | 4.9 | The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is u… | — | wordfence |
| 575870b0-269e-4651-9e0f-0a178266a02e | < 1.9.1 |
MEDIUM | 4.9 | The Barcode Scanner (+Mobile App) β Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPr… | — | wordfence |
| 572bfa82-92f5-4801-8710-0626ca563a6c | < 4.3.6 |
MEDIUM | 4.9 | The Cookie Banner for GDPR / CCPA β WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection vi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →