Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1588 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 40957153-45f1-40c9-91ce-f3491ca7eee5 | < 3.5.2.1 |
LOW | 3.8 | The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to,… | — | wordfence |
| 3dfba044-42f8-44a2-be62-99af9d9094c3 | < 3.5.2 |
LOW | 3.8 | Advanced Custom Fields up to 3.5.1 is vulnerable to Remote Code Execution. The vulnerability allows for remote file incl… | — | wordfence |
| 369cd6ca-bb36-479e-b342-36d2ca778ce1 | LOW | 3.8 | The Post Affiliate Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and incl… | — | wordfence | |
| 342370a0-9364-40cd-9556-e53312e67548 | < 3.4.2 |
LOW | 3.8 | wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-admini… | — | wordfence |
| 2f5962e5-3dc7-4f93-889c-d5e3530c7dba | < 0.9.129 |
LOW | 3.8 | The Migration, Backup, Staging β WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory … | — | wordfence |
| 2a7f64e1-c815-426b-99cc-03ab62aaf9de | LOW | 3.8 | The wp2syslog plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.5 … | — | wordfence | |
| 28d3fe13-20f8-48af-9476-98d2bef467e5 | < 1.7.16 |
LOW | 3.8 | The WP YouTube Lyte WordPress plugin before 1.7.16 did not sanitise or escape its lyte_yt_api_key and lyte_notification … | — | wordfence |
| 2760ee88-b8fc-4390-a92a-829e3e9401d8 | < 1.4.37 |
LOW | 3.8 | The CP Multi View Event Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability … | — | wordfence |
| 2154383e-eabb-4964-8991-423dd68d5efb | < 4.23.6 |
LOW | 3.8 | The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu… | — | wordfence |
| 1ead1a18-9429-472e-9e88-e792eaa23ae9 | < 6.8.1 |
LOW | 3.8 | The Simple:Press plugin for WordPress is vulnerable to arbitrary file modifications in versions up to, and including, 6.… | — | wordfence |
| 13d0eb8a-5b63-460e-b4ba-a3ed80c84fc2 | < 1.4.15 |
LOW | 3.8 | The CP Multi View Event Calendar plugin for WordPress is vulnerable to Insufficient Authorization in versions up to, and… | — | wordfence |
| f1c08c10-7358-4618-b892-7d222ba460de | < 1.2.0 |
LOW | 3.7 | The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (Re… | — | wordfence |
| e5dc87cd-4f45-4faf-b1e2-64e94eacb180 | < 6.8 |
LOW | 3.7 | Versions of WordPress core older than version 6.8 use a weak MD5-based password hashing algorithm, which makes it easier… | — | wordfence |
| d88a5dfc-4654-4299-b5a5-2a48b3823e37 | < 2.0.9 |
LOW | 3.7 | Multiple plugins for WordPress utilize a vulnerable dependency (PHPExcel) in various versions. No vulnerabilities have b… | — | wordfence |
| d72cc420-1ff5-403b-b4ea-7c820fdebcf3 | < 4.1.1 |
LOW | 3.7 | The MetForm β Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Se… | — | wordfence |
| d3f4de75-abf5-46e8-854d-be91ed74a5f3 | < 3.3.5 |
LOW | 3.7 | The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. T… | — | wordfence |
| CVE-2026-1582 | LOW | 3.7 | The WP All Export plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… | — | nvd | |
| c66bc0b1-c157-4c05-ae9d-0927863c6b95 | < 1.4.4 |
LOW | 3.7 | The Job Manager & Career β Manage job board listings, and recruitments plugin for WordPress is vulnerable to Sensitive… | — | wordfence |
| bb81e90f-8da4-483c-9bc1-18b6c016df5e | < 1.9.12 |
LOW | 3.7 | The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in all versions up to, and including, 1.9… | — | wordfence |
| ba2515d9-ced0-4b49-87c4-04c8391c2608 | < 4.2.2 |
LOW | 3.7 | The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded e… | — | wordfence |
| ae342dd9-2f5f-4356-8fb4-9a3e5f4f8316 | < 2.4.19 |
LOW | 3.7 | The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.1… | — | wordfence |
| a07bc541-2113-43db-acdf-9ecb00dd50e9 | < 0.9.5 |
LOW | 3.7 | The W3 Total Cache plugin for WordPress is vulnerable to authorization bypass due to the use of loose comparison on the … | — | wordfence |
| 9a92c682-b8b3-4d23-bd84-97d7440ee525 | < 1.4.15 |
LOW | 3.7 | The WP All Export plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… | — | wordfence |
| 8b507369-49f7-4a1d-900b-c7bef40aec96 | < 7.4 |
LOW | 3.7 | The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file upload due to a missing ca… | — | wordfence |
| 78203b98-15bc-4d8e-9278-c472b518be07 | < 2.38 |
LOW | 3.7 | The Minimal Coming Soon β Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and informati… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →