Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1591 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 112ece28-27ac-4d3c-b302-7acab43390fb | LOW | 3.1 | The Spacer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the mo… | — | wordfence | |
| 0d3010a9-10fa-40ec-9791-3ac993123f93 | < 3.9.0 |
LOW | 3.1 | Cross-site request forgery (CSRF) vulnerability in the All In One WP Security & Firewall plugin before 3.9.0 for WordPre… | — | wordfence |
| 0ac6603f-7eed-424e-a56b-f45d4a7f7b2a | < 1.1.31 |
LOW | 3.1 | Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPr… | — | wordfence |
| 07904ed6-ff3c-41b6-a0ee-87fdbfd14bea | < 0.3.6 |
LOW | 3.1 | The FV Thoughtful Comments plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… | — | wordfence |
| 4f9bd960-01ef-41dd-ab05-0a5f734484a2 | < 2.2 |
LOW | 3.0 | The EventON plugin for WordPress is vulnerable to HTML Injection via admin settings in all versions up to, and including… | — | wordfence |
| ee8436c2-3dda-481c-92b3-cc2ba8fc1993 | < 9.0.0 |
LOW | 2.7 | The WooCommerce plugin for WordPress is vulnerable to content injection in all versions up to, and including, 8.9.2. Thi… | — | wordfence |
| eb3a26c7-8693-4a1d-a2b9-c548ef3c0ee0 | < 1.10.5 |
LOW | 2.7 | The Barcode Scanner (+Mobile App) β Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPr… | — | wordfence |
| e05d9aec-5b17-4af8-8985-d4bb003f2d6f | < 5.2.10 |
LOW | 2.7 | The B2BKing β Ultimate WooCommerce B2B and Wholesale Plugin β Wholesale Prices, Bulk Order Form & More plugin for Wo… | — | wordfence |
| db25e8f7-07f2-470e-850e-b8cd3388baea | < 4.16 |
LOW | 2.7 | The Car Dealer (Dealership) and Vehicle sales plugin for WordPress is vulnerable to unauthorized content injection due t… | — | wordfence |
| d222ef6d-cdec-482e-92ba-65eeabbcdeae | < 2.5.1 |
LOW | 2.7 | The Product Import Export for WooCommerce β Import Export Product CSV Suite plugin for WordPress is vulnerable to arbi… | — | wordfence |
| CVE-2026-2419 | LOW | 2.7 | The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 v… | — | nvd | |
| CVE-2026-1831 | LOW | 2.7 | The YayMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized plugin installation and ac… | — | nvd | |
| CVE-2025-14270 | LOW | 2.7 | The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, … | — | nvd | |
| c97a341c-23f5-49a9-ad05-1fb387047e3b | < 2.5 |
LOW | 2.7 | The Rankology SEO and Analytics Tool plugin for WordPress is vulnerable to unauthorized modification of data due to an i… | — | wordfence |
| c6ae2f0d-a0c2-4f4a-bb1b-f6419aa2e155 | LOW | 2.7 | The Foxit eSign for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to… | — | wordfence | |
| c2805cb0-8913-4487-8445-031b7d920e2d | < 3.14 |
LOW | 2.7 | The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13… | — | wordfence |
| c0c293db-5526-4600-838a-6e88586926c4 | < 2.7.2 |
LOW | 2.7 | The Tutor LMS β eLearning and online course solution plugin for WordPress is vulnerable to Path Traversal in all versi… | — | wordfence |
| bbd5e24f-2934-422e-a3bd-452e916c2ffb | < 2.2.12 |
LOW | 2.7 | The GPX Viewer plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.2.11. This m… | — | wordfence |
| b9002f6e-4345-4908-9cb8-9841a2458eb7 | < 1.11.12 |
LOW | 2.7 | The CartFlows plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1… | — | wordfence |
| b871883c-509b-4776-b550-349b3f5aa365 | LOW | 2.7 | The WordPress Gallery Exporter β Export your NextGen, Envira and FooGallery galleries to your computer plugin for Word… | — | wordfence | |
| b4b5cc5e-af82-49e0-a0b5-d27c3631a102 | < 1.1.0 |
LOW | 2.7 | The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, … | — | wordfence |
| b043197c-4477-4663-abb8-5840173c574d | < 2.3.1 |
LOW | 2.7 | The Easy WP SMTP by SendLayer β WordPress SMTP and Email Log Plugin plugin for WordPress is vulnerable to information … | — | wordfence |
| ad382ec2-55c8-4d6c-b318-db199f812493 | < 1.176.0 |
LOW | 2.7 | The Site Kit by Google β Analytics, Search Console, AdSense, Speed plugin for WordPress is vulnerable to unauthorized … | — | wordfence |
| a821d61c-e3c8-4a1b-8a52-a63adcb6c127 | < 1.0.8.6 |
LOW | 2.7 | The WOLF β WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to Path Traversal i… | — | wordfence |
| a568162a-5a2d-47ab-9dfe-2f2f5f324f0d | < 4.3.3 |
LOW | 2.7 | The YayMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized plugin installation and ac… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →