Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1587 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2379a029-cc0d-4fa2-9aeb-47a4abd6b51a | < 2.25.2 |
MEDIUM | 4.1 | The GiveWP plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 2.25.1 vi… | — | wordfence |
| 0f5a48ec-da62-4a9d-a8a5-30da7b6d23f6 | < 6.4.3 |
MEDIUM | 4.1 | The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to HTML Injection in all versions up to, and inclu… | — | wordfence |
| f24b3afe-5de3-464c-92af-a654e97f0945 | < 1.1.0 |
MEDIUM | 4.0 | The Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab plugin for WordPress is vulnerable to Stored Cross-… | — | wordfence |
| ee449645-44d1-4ce7-b74b-dcf446b5a9ab | < 1.11.7 |
MEDIUM | 4.0 | The Z-Downloads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions u… | — | wordfence |
| d4cdf774-c93b-4b94-85ba-aa56bf401873 | < 21.8 |
MEDIUM | 4.0 | The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via service titles in versions up to, and i… | — | wordfence |
| ba08dbad-15f9-43cf-b0d7-a2a4604cb4af | < 1.9.1 |
MEDIUM | 4.0 | The WP Bannerize Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via banner alt data in all versio… | — | wordfence |
| 6082f25f-b060-431b-a18c-65899851bf3b | < 4.4 |
MEDIUM | 4.0 | The WP Airbnb Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … | — | wordfence |
| 5b25908a-d394-4ce8-b853-4bdf643b9b5b | < 1.7.1 |
MEDIUM | 4.0 | The YITH Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio… | — | wordfence |
| 51de575f-d458-4a7d-bc57-4a11e5124377 | < 1.1.13 |
MEDIUM | 4.0 | The Block For Mailchimp – Easy Mailchimp Form Integration plugin for WordPress is vulnerable to Blind Server-Side Requ… | — | wordfence |
| 112ed4f2-fe91-4d83-a3f7-eaf889870af4 | MEDIUM | 4.0 | WordPress Core, in all known versions is vulnerable to blind Server-Side Request Forgery in its pingback feature. This i… | — | wordfence | |
| eb0892fd-b5dd-4dc8-bc45-41c05f1c03cf | LOW | 3.8 | The Piotnet Forms plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.30. Thi… | — | wordfence | |
| e615833a-0408-4e39-b63d-075bff39a9bf | LOW | 3.8 | The DupeOff plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6 due … | — | wordfence | |
| e3dc1dd6-7f35-4771-a795-f0e37088dfda | < 1.1.3 |
LOW | 3.8 | The Image Gallery - Grid Gallery WordPress plugin through 1.1.1 does not sanitize and escape some of its Image fields, w… | — | wordfence |
| d935f4c5-5d69-42d9-be22-7a44d9aa885a | < 2.17.5 |
LOW | 3.8 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil… | — | wordfence |
| ca7f72bf-5271-42a2-99cb-3021f10ea5f3 | < 2.3.3 |
LOW | 3.8 | Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress. | — | wordfence |
| c59a4802-ce4c-4f19-be7a-848862e1d3cf | < 3.2.1 |
LOW | 3.8 | The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable … | — | wordfence |
| ab233ceb-270c-4694-9cf9-2de8ddfcbbfd | < 7.7.2 |
LOW | 3.8 | The Directorist plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 7.7.1. This allows… | — | wordfence |
| 9f47c6c4-2d74-4f37-8232-d54d5f0c24cf | < 1.0.3 |
LOW | 3.8 | The Enable SVG, WebP & ICO Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… | — | wordfence |
| 8c3e61e9-3610-41b5-9820-28012dc657fd | < 3.2.4 |
LOW | 3.8 | The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on th… | — | wordfence |
| 855f5cca-b0cc-4a1b-be33-d11776ad7c08 | < 3.7.4 |
LOW | 3.8 | Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabl… | — | wordfence |
| 803c32e9-665c-40a0-b52d-f2c0b8fbe931 | < 2.2.3 |
LOW | 3.8 | The FluentSMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sending mail (thus adding the paylo… | — | wordfence |
| 72c16a66-05fa-4d47-937d-415f18cec0ab | < 1.1.82 |
LOW | 3.8 | The WP Time Slots Booking Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in v… | — | wordfence |
| 6b6fa5c6-e9a9-45c6-a02b-3630d8ef130e | < 5.4.5 |
LOW | 3.8 | The MonsterInsights - Google Analytics Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… | — | wordfence |
| 67817d5a-2d7a-4b96-9c04-cd1ad9c90b29 | < 1.2.2 |
LOW | 3.8 | The Ni Purchase Order(PO) For WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… | — | wordfence |
| 63f38644-a021-407a-9882-2c8435849c08 | < 1.5.0 |
LOW | 3.8 | The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all version… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →