Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1267 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| e55ba61d-6fd0-4269-8ee9-3b8645d52e1d | < 4.6.3 |
MEDIUM | 4.7 | The Poll Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 4.6.2… | — | wordfence |
| e52c53c1-4f04-4075-9329-d93fabf5a6ce | < 2.0.9 |
MEDIUM | 4.7 | The WPCode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.8. Thi… | — | wordfence |
| dede9cfc-61f1-4df1-bd40-e5ae73199575 | < 3.2.0 |
MEDIUM | 4.7 | The OneLogin SAML SSO plugin for WordPress is vulnerable to open redirection in versions up to, and including, 3.1.2. T… | — | wordfence |
| dd27aeb9-4257-4b15-8f14-8a8c89522c32 | < 1.1.6 |
MEDIUM | 4.7 | The QuBotChat plugin for WordPress is vulnerable to Self-Based Cross-Site Scripting in versions up to, and including, 1.… | — | wordfence |
| daf8e0ca-abe7-4243-8921-ff5a6f88cfcf | < 1.7.29 |
MEDIUM | 4.7 | The WP YouTube Lyte plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.7.28. Th… | — | wordfence |
| d93a4901-3fbd-40b2-af0b-501fa837424a | < 2.0.1 |
MEDIUM | 4.7 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized access in versions up to, and inclu… | — | wordfence |
| d7dcc31c-9255-4bd2-92b4-ce9a1df5f24c | < 3.6.1 |
MEDIUM | 4.7 | The AI Engine β The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalati… | — | wordfence |
| CVE-2026-1277 | < 1.12.2 |
MEDIUM | 4.7 | The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to… | — | nvd |
| caf0d33d-4bfd-460f-b21c-df36b1452b2e | < 2.14.4 |
MEDIUM | 4.7 | Reflected Cross-Site Scripting (XSS) vulnerability in Code Snippets plugin <= 2.14.3 at WordPress via &orderby vulnerabl… | — | wordfence |
| cabe5d20-710c-47d7-a5a3-562287ab5706 | < 3.0.0 |
MEDIUM | 4.7 | Cross-Site Scripting (XSS) vulnerability discovered in Yasr β Yet Another Stars Rating WordPress plugin (versions <= 2… | — | wordfence |
| ca12d05f-23f4-44e4-b513-a0452a170130 | < 7.0.00 |
MEDIUM | 4.7 | The WP Ghost (Hide My WP Ghost) β Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all versi… | — | wordfence |
| c997dfc8-7cec-4636-9fe4-df1fb6436082 | < 5.0.0 |
MEDIUM | 4.7 | The Guest posting / Frontend Posting / Front Editor β WP Front User Submit plugin for WordPress is vulnerable to Open … | — | wordfence |
| c7c1dc51-47ca-4b2f-9ff9-275bd8b1c106 | < 1.12.2 |
MEDIUM | 4.7 | The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to… | — | wordfence |
| c37d8218-6059-46f2-a5d9-d7c22486211e | < 4.1.5 |
MEDIUM | 4.7 | The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SHORTPIXEL_DEBUG p… | — | wordfence |
| c10286fe-2fdf-4946-b7bb-a2b16f93abb0 | < 2.5.7 |
MEDIUM | 4.7 | The CM Registration β Tailored tool for seamless login and invitation-based registrations plugin for WordPress is vuln… | — | wordfence |
| bccceb2d-2087-4ee6-8118-eb3fb53654dc | < 1.3.3 |
MEDIUM | 4.7 | The Integrate Google Drive β Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files… | — | wordfence |
| bc112db6-fb80-4edd-be36-4aae81a656e4 | MEDIUM | 4.7 | The GlobalQuran plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. … | — | wordfence | |
| b926243c-ed12-4afe-ac72-932d4d871019 | MEDIUM | 4.7 | The Short URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.8. … | — | wordfence | |
| b6db6736-4629-47b7-976a-f81335430119 | < 2.0.1 |
MEDIUM | 4.7 | The Page Builder: Pagelayer β Drag and Drop website builder plugin for WordPress is vulnerable to Reflected Cross-Site… | — | wordfence |
| b3ea5e75-9b6a-4710-bb2c-458c2a924bb0 | < 0.3 |
MEDIUM | 4.7 | The ThinkIT WP Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 0.3. Thi… | — | wordfence |
| b1791d41-cdfe-4918-8351-2108302241c1 | < 2.3.3 |
MEDIUM | 4.7 | SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to… | — | wordfence |
| b15b08e1-0aa7-49a3-9a08-bbc48f13260c | < 1.3.5 |
MEDIUM | 4.7 | The Wp Edit Password Protected β Create Password Protect Pages & Design Password Protected Form plugin for WordPress i… | — | wordfence |
| b0ab311f-26c1-4165-80bc-512348fcc0c0 | MEDIUM | 4.7 | The FL3R FeelBox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.1.… | — | wordfence | |
| ae13e0eb-b77c-4e9f-a5aa-caf2c67db7bc | < 1.0.23 |
MEDIUM | 4.7 | The Responsive Filterable Portfolio plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up… | — | wordfence |
| abe6366a-3729-474f-8920-b5ed2eeab906 | < 6.11.2 |
MEDIUM | 4.7 | The Smash Balloon Social Photo Feed β Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Reques… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →