Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1258 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 19cff824-7fb7-4b60-bfc4-2157c9ecb0bf | < 2.2.5 |
MEDIUM | 4.9 | The UpsellWP – WooCommerce Upsell and Related Products Offers plugin for WordPress is vulnerable to SQL Injection in v… | — | wordfence |
| 188baddc-134c-4a82-898b-9b038e795893 | < 3.5.1.29 |
MEDIUM | 4.9 | The Smart Slider 3 plugin for WordPress is vulnerable to time-based SQL Injection via the ‘sliderid’ parameter in al… | — | wordfence |
| 17fd14e7-503a-49e4-9344-5f8d51801eb3 | < 1.5.3 |
MEDIUM | 4.9 | Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the down… | — | wordfence |
| 176a2200-db90-4a16-b8bc-da85471ff8d1 | < 3.1.0 |
MEDIUM | 4.9 | The Verowa Connect plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.5 due to in… | — | wordfence |
| 174bcee9-cb2d-4181-8168-df5d28de8484 | MEDIUM | 4.9 | The WP Inquiries plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.2.1 due to insu… | — | wordfence | |
| 16c212d8-21e2-407f-b2ea-0ca519da26dd | MEDIUM | 4.9 | The donation plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and inclu… | — | wordfence | |
| 16820eda-e5ff-48d1-81bc-355ee916119b | < 3.1.3 |
MEDIUM | 4.9 | The ELEX Product Feed for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… | — | wordfence |
| 156945e1-80dc-4fb4-958f-bb87722e96fb | < 2.1.3.7 |
MEDIUM | 4.9 | The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'infill_text' parameter in all versions up … | — | wordfence |
| 156209c0-27d0-4c87-883a-bf9376f8858c | < 1.18.6 |
MEDIUM | 4.9 | The Mail Mint plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.18.5 due to insuff… | — | wordfence |
| 153647b8-c5eb-47f5-b375-0baec367287f | < 3.4.7 |
MEDIUM | 4.9 | The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to SQL Inject… | — | wordfence |
| 13fcbff8-8560-48ca-82df-8b620961d9c6 | < 3.16.1 |
MEDIUM | 4.9 | The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file read via the 'wht_download_big_object_origin' para… | — | wordfence |
| 13b7a2e4-59f4-4d61-a165-a830ccfb696a | < 2.6.3 |
MEDIUM | 4.9 | The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, an… | — | wordfence |
| 13929b51-b32e-401c-a642-49f7cd2d07bf | < 3.30.3 |
MEDIUM | 4.9 | The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via… | — | wordfence |
| 12349179-e61c-42b8-b0ff-5b49fc4906c1 | < 1.4.1 |
MEDIUM | 4.9 | The Timeline Designer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, a… | — | wordfence |
| 120f15aa-ccef-49be-8743-e77d699601e2 | < 2.7.15 |
MEDIUM | 4.9 | The RSVP and Event Management Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and includin… | — | wordfence |
| 1197a66e-4557-458f-b8fd-b7a8e7586817 | < 2.53 |
MEDIUM | 4.9 | The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to Sensitive… | — | wordfence |
| 115a63bd-65ca-4ccb-affd-c14119d6b9a3 | < 6.5.1 |
MEDIUM | 4.9 | The onOffice for WP-Websites plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.5 d… | — | wordfence |
| 10c5ed1e-1288-4b57-a26c-874c15dcef08 | MEDIUM | 4.9 | The WP Triggers Lite plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.5.3 due… | — | wordfence | |
| 109427de-3b8a-46cc-a888-6fea4f72a31a | < 2.7.2 |
MEDIUM | 4.9 | The plugin Mailchimp for WooCommerce for WordPress is vulnerable to Server-Side Request Forgery via one of its AJAX acti… | — | wordfence |
| 10543a3b-e1ac-4c6b-b511-4cbd45924f6f | < 7.4.0 |
MEDIUM | 4.9 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulne… | — | wordfence |
| 0f6d0ba7-f9e8-493b-9e6d-62f1c662e21e | < 4.1.5 |
MEDIUM | 4.9 | The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Trave… | — | wordfence |
| 0d1c85c3-2aa7-4b65-a771-a4571746bfc9 | < 4.5.5 |
MEDIUM | 4.9 | The Slim SEO plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.5.4 due to insuffic… | — | wordfence |
| 0cd62935-f865-43ff-b727-f17b6fc5976d | MEDIUM | 4.9 | The WordPress Auction Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7 d… | — | wordfence | |
| 0b395777-2e2a-4dc3-9b0c-ce4c9d22d7e9 | < 4.1.0 |
MEDIUM | 4.9 | The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_dire… | — | wordfence |
| 0afe37bb-fa8a-4e7b-93c6-c44b3fbeb904 | < 1.4.4 |
MEDIUM | 4.9 | The ELEX WooCommerce Google Shopping (Google Product Feed) plugin for WordPress is vulnerable to SQL Injection via the '… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →