Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1259 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 0a5a547c-6b24-4cb6-ad0e-b12a8f37472a | MEDIUM | 4.9 | The Contact Forms - Drag & Drop Contact Form Builder WordPress plugin through 1.0.5 allows high privilege users to downl… | — | wordfence | |
| 07dc60e0-a0b4-4db6-8033-ebd01fb697d0 | < 3.0.0 |
MEDIUM | 4.9 | The Mailing Group Listserv plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.9 d… | — | wordfence |
| 0747c996-982c-42a9-942e-2fa7056127f8 | < 5.2.5 |
MEDIUM | 4.9 | The AutomatorWP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.2.4 due to insuf… | — | wordfence |
| 05ff1b1e-f7ba-485d-9421-9bb38f6831ef | < 1.0.4 |
MEDIUM | 4.9 | The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to SQL Injection via the 'id' par… | — | wordfence |
| 059e358d-422d-48e8-a11e-fed52770f4d9 | MEDIUM | 4.9 | The Contact Form 7 Database – CFDB7 plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… | — | wordfence | |
| 059c2d6d-1296-4463-96ae-a95ba7dad70a | < 3.5.1.37 |
MEDIUM | 4.9 | The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1… | — | wordfence |
| 0540f70d-009a-4776-8717-f096e30a11d3 | < 3.1.3 |
MEDIUM | 4.9 | The Post SMTP plugin for WordPress is vulnerable to generic SQL Injection via the ‘columns’ parameter in all version… | — | wordfence |
| 04bc4a20-0136-4fb4-9489-07140b2b86aa | < 2.2.24 |
MEDIUM | 4.9 | The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'SCodes' para… | — | wordfence |
| 04641506-5b0e-48bc-ad50-c81dda996ecf | < 1.5.1 |
MEDIUM | 4.9 | The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_input’ and '… | — | wordfence |
| 0424e4af-5225-45ed-8bc6-40654851e44f | MEDIUM | 4.9 | The Pay with Contact Form 7 plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.4 … | — | wordfence | |
| 03cb41d2-67c8-457f-8d85-7aede8e12d44 | < 6.4.3 |
MEDIUM | 4.9 | The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'load… | — | wordfence |
| 03bf84e2-c101-416d-a953-c63ecd1dba7d | < 5.1.5 |
MEDIUM | 4.9 | The All-In-One Security (AIOS) plugin for WordPress is vulnerable to directory traversal in versions up to, and includin… | — | wordfence |
| 03258713-0a63-4469-ba44-b25998d2411f | < 1.4.3 |
MEDIUM | 4.9 | The Integration for Contact Form 7 HubSpot plugin for WordPress is vulnerable to SQL Injection in versions up to, and in… | — | wordfence |
| 01a52285-2d0c-4b29-8dab-18a3e3640e5c | < 6.0.14 |
MEDIUM | 4.9 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traver… | — | wordfence |
| 013f6ad0-6ef1-44a1-9925-c60c61314f70 | MEDIUM | 4.9 | The WPMU Prefill Post plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.02 due to … | — | wordfence | |
| 0101113b-70c2-4db4-b6b1-b2412f6e1214 | < 6.2.2 |
MEDIUM | 4.9 | The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This i… | — | wordfence |
| fe708e03-334f-4c72-ace9-b5d065ee8c9d | MEDIUM | 4.8 | Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Pricing Table (WordPress p… | — | wordfence | |
| fd67e334-88fd-49c7-a20c-9c2f95e9950c | < 3.5.6 |
MEDIUM | 4.8 | The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege use… | — | wordfence |
| fb6719d8-18d2-4fa3-9b52-ba11cf567bb2 | < 2.5.1.9 |
MEDIUM | 4.8 | These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:4… | — | wordfence |
| fa63a325-9e0e-4ce2-996d-37a0637b0471 | MEDIUM | 4.8 | Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Floating … | — | wordfence | |
| f9ae88f8-88c1-4bb0-af9f-330f9760de1f | < 5.22.2 |
MEDIUM | 4.8 | The Modern Events Calendar Lite WordPress plugin before 5.22.2 does not escape some of its settings before outputting th… | — | wordfence |
| f85f2fbb-5bd5-4508-abb0-36543b8ddaa2 | < 7.0 |
MEDIUM | 4.8 | The Custom Dashboard & Login Page WordPress plugin before 7.0 does not sanitise some of its settings, allowing high priv… | — | wordfence |
| f4198c51-4a26-4a50-b2c5-0467f8008b5b | < 2.2 |
MEDIUM | 4.8 | The WP Social Buttons WordPress plugin through 2.1 does not sanitise and escape its settings, allowing high privilege us… | — | wordfence |
| f371feb6-93ae-4759-ab44-d58106093290 | < 1.0.14 |
MEDIUM | 4.8 | The Sign-up Sheets WordPress plugin before 1.0.14 did not sanitise or escape some of its fields when creating a new shee… | — | wordfence |
| f3543ce7-328e-4db8-8993-8cd78af997de | < 1.7.0 |
MEDIUM | 4.8 | The SEUR Oficial WordPress plugin before 1.7.0 does not sanitize and escape some of its settings allowing high privilege… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →