Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 130 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2026-6261 | HIGH | 8.8 | The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is d… | — | nvd | |
| CVE-2026-3772 | HIGH | 8.8 | The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2… | — | nvd | |
| CVE-2026-3132 | HIGH | 8.8 | The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up t… | — | nvd | |
| CVE-2026-2448 | HIGH | 8.8 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc… | — | nvd | |
| CVE-2026-2001 | HIGH | 8.8 | The WowRevenue plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check … | — | nvd | |
| CVE-2026-1929 | < 2.37 |
HIGH | 8.8 | The Advanced Woo Labels plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including… | — | nvd |
| CVE-2026-1750 | HIGH | 8.8 | The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versio… | — | nvd | |
| CVE-2026-1426 | HIGH | 8.8 | The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and … | — | nvd | |
| CVE-2026-1311 | HIGH | 8.8 | The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 … | — | nvd | |
| CVE-2026-0912 | HIGH | 8.8 | The Toret Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc… | — | nvd | |
| CVE-2025-13603 | HIGH | 8.8 | The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and i… | — | nvd | |
| CVE-2025-12821 | HIGH | 8.8 | The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.6.1. This is… | — | nvd | |
| CVE-2025-11993 | HIGH | 8.8 | The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all ve… | — | nvd | |
| cffa4593-bd88-4018-b801-98d9d586111a | HIGH | 8.8 | The KH Easy User Settings plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin… | — | wordfence | |
| cfd35a3c-7203-4832-8b0d-56f3e7983118 | < 2.81.1 |
HIGH | 8.8 | The Dataverse Integration plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks… | — | wordfence |
| cfc78684-fdb7-4ce1-8464-0d057b48a7fa | < 0.4 |
HIGH | 8.8 | The Custom field finder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,… | — | wordfence |
| cfc6ff21-52f5-453f-bf97-881c39be1aeb | < 2.2.10 |
HIGH | 8.8 | The GPX Viewer plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check and file … | — | wordfence |
| cfc6c595-dad2-4abc-8187-ed72355273b8 | < 2.5.3 |
HIGH | 8.8 | The Better Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5… | — | wordfence |
| cfbc7af2-1e2c-4aaf-b73c-870f7519aff1 | < 1.8 |
HIGH | 8.8 | The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| cf711c64-dd5e-4725-824c-fbe9063916d9 | < 1.2.6 |
HIGH | 8.8 | The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.6 is affected by a SQL Injection in the id parameter o… | — | wordfence |
| cf57aeaa-e37e-4b22-aeaa-f0a9f4877484 | < 4.4.3 |
HIGH | 8.8 | The RSS Aggregator by Feedzy β Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress … | — | wordfence |
| cf4efae5-d8ea-4c94-bc8a-c73615f2fe62 | < 4.11.2 |
HIGH | 8.8 | The WpStream β Live Streaming, Video on Demand, Pay Per View plugin for WordPress is vulnerable to arbitrary file uplo… | — | wordfence |
| cede8ff5-f739-4eb3-9672-5adb5d2ae0a9 | < 2.1.40 |
HIGH | 8.8 | The WP FOFT Loader plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in… | — | wordfence |
| ceb25a7b-da93-41eb-bae7-8bffa96f7a1c | < 1.0.3 |
HIGH | 8.8 | The Slivery Extender plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1… | — | wordfence |
| cea39157-94aa-4982-983e-9c3e4b1af86d | < 2.16 |
HIGH | 8.8 | The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.15. This… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →