Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1257 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2d4a463b-e447-4fd0-a8df-284ecd6cd975 | MEDIUM | 4.9 | The Pollin plugin for WordPress is vulnerable to SQL Injection via the 'question' parameter in all versions up to, and i… | — | wordfence | |
| 2c11f469-b136-4429-87a1-083d7d5e6695 | < 1.9.0 |
MEDIUM | 4.9 | The MC Woocommerce Wishlist plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.8.9 … | — | wordfence |
| 2be23829-cbee-4e44-945d-14835dbba104 | < 2.11.32 |
MEDIUM | 4.9 | The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.11.31 due… | — | wordfence |
| 2b4b0640-d61a-4969-a5c0-d2d709fb56d0 | < 3.3.204 |
MEDIUM | 4.9 | The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includin… | — | wordfence |
| 2a59db6d-82a6-4570-bfa5-674ae4054ea7 | < 8.2.6 |
MEDIUM | 4.9 | The WP Full Stripe Free plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.2.5 due … | — | wordfence |
| 28eb6998-be54-4cf9-8bb1-454c07151748 | < 1.5 |
MEDIUM | 4.9 | The Form Vibes β Database Manager for Forms plugin for WordPress is vulnerable to SQL Injection via the 'params' param… | — | wordfence |
| 2760587c-78f5-40b1-affd-dfdfb2bc2a68 | < 0.9.71 |
MEDIUM | 4.9 | Arbitrary File Read vulnerability in WPvivid Team Migration, Backup, Staging β WPvivid (WordPress plugin) versions <= … | — | wordfence |
| 25940775-2ff9-49cf-ab24-3e87f1ca8e42 | < 1.8.0 |
MEDIUM | 4.9 | The Behance Portfolio Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.… | — | wordfence |
| 259010bd-ccb4-4907-bea8-f49e6464eaa1 | < 6.10 |
MEDIUM | 4.9 | The onOffice for WP-Websites plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versio… | — | wordfence |
| 23f8e757-a4ed-4929-9647-dfe5a21689aa | < 4.9.13 |
MEDIUM | 4.9 | The Spiffy Calendar plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.9.12 due… | — | wordfence |
| 23e0f61b-f122-46f7-83c8-7fcb022c45e9 | < 1.5.75 |
MEDIUM | 4.9 | The Photo Gallery by 10Web β Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded… | — | wordfence |
| 2328efaf-4174-48f0-b575-1939d6af9216 | < 1.09 |
MEDIUM | 4.9 | The Falling things plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.08 due to ins… | — | wordfence |
| 2242c86e-c769-4104-b266-0cdcd90ccf63 | MEDIUM | 4.9 | The Rich Snippet Site Report plugin for WordPress is vulnerable to SQL Injection via the 'last' parameter in all versio… | — | wordfence | |
| 21da92d2-c38d-4a12-b850-bd0b580aaa54 | < 1.16.9 |
MEDIUM | 4.9 | The Total Upkeep β WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Se… | — | wordfence |
| 205efe4d-45c3-4180-b839-ab2ba94ec94a | < 1.0.8 |
MEDIUM | 4.9 | The ShortLinks Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.7 due to in… | — | wordfence |
| 2000b23f-d8a2-4b83-9bf7-b90cb16718f3 | < 1.3.2 |
MEDIUM | 4.9 | The FluentCart plugin for WordPress is vulnerable to SQL Injection via the 'groupKey' parameter in all versions up to, a… | — | wordfence |
| 1fc5f0ac-3323-4e6c-8900-10e13294ff9a | < 2.2.0 |
MEDIUM | 4.9 | The Bookster β WordPress Appointment Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the βraw… | — | wordfence |
| 1f3b5d85-a8b0-43ac-b593-a61e20b9a4ca | < 2.18.4 |
MEDIUM | 4.9 | The Contact Form by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in a… | — | wordfence |
| 1e7c1eab-78d7-48f8-810b-db6cea668d92 | < 9.0.16 |
MEDIUM | 4.9 | The WP Go Maps plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 9.0.15 via th… | — | wordfence |
| 1e2dab05-97ce-4f53-8069-2577c5c25b16 | < 2.4.7 |
MEDIUM | 4.9 | The TS Poll β Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the … | — | wordfence |
| 1e193bb9-bb16-4a77-877b-fa0ab29a6c74 | < 3.9.12 |
MEDIUM | 4.9 | The Tutor LMS β eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via t… | — | wordfence |
| 1dd094b8-440a-47ae-8edc-c23f1909d607 | < 9.2.5 |
MEDIUM | 4.9 | The NEX-Forms β Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via th… | — | wordfence |
| 1d9d5afb-d38d-442c-8511-f1683739a1da | < 4.0 |
MEDIUM | 4.9 | The VR-Frases (collect & share quotes) plugin for WordPress is vulnerable to SQL Injection via several parameters in all… | — | wordfence |
| 1ce15d38-c5bc-441b-976a-60a3e90b5a30 | < 4.5.91 |
MEDIUM | 4.9 | The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog fold… | — | wordfence |
| 1a38e571-a92a-4a47-9507-8a989be4b405 | MEDIUM | 4.9 | The Plugin Inspector plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5. Thi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →