Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1592 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a38a58de-5f7d-4033-9a65-41b590b7d510 | < 6.1.1 |
LOW | 2.7 | The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check … | — | wordfence |
| a1ee5b10-1694-4991-b3fb-4b3b365fbca6 | < 2025.03.30 |
LOW | 2.7 | The Administrator Z plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2025… | — | wordfence |
| 9f58a5eb-53cb-4a25-b693-bcd2b7a1cd00 | < 1.0.27 |
LOW | 2.7 | The Image Optimizer by 10web plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including,… | — | wordfence |
| 94f0041d-eed6-4980-a7b8-f7410ca68e67 | < 1.5.2 |
LOW | 2.7 | The Easy WP SMTP plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.5.1 possi… | — | wordfence |
| 941aef7f-435b-4e59-8d55-f95800233c80 | LOW | 2.7 | The Health Check & Troubleshooting plugin for WordPress is vulnerable to Path Traversal in all versions up to, and inclu… | — | wordfence | |
| 8c21de03-4d62-4ecf-a2f1-57e0e416792b | < 4.0.3 |
LOW | 2.7 | The Multiple Page Generator Plugin β MPG plugin for WordPress is vulnerable to arbitrary file deletion due to insuffic… | — | wordfence |
| 890dadec-b60c-4f4c-8644-1a0d1eecc74d | < 2.0.9 |
LOW | 2.7 | The Search with Typesense plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.0… | — | wordfence |
| 84683caa-8bc7-4adf-ad64-249f988047bf | < 1.4.8 |
LOW | 2.7 | The Mobile Events Manager plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.7. T… | — | wordfence |
| 7bdadc84-0cfb-4bec-aeb9-f59f205d269b | < 4.8.5 |
LOW | 2.7 | The ShopEngine Elementor WooCommerce Builder Addon β All in One WooCommerce Solution plugin for WordPress is vulnerabl… | — | wordfence |
| 7a20b65a-6d3a-41fc-80c5-94cce0459a6b | < 7.3.16 |
LOW | 2.7 | The Product Feed Manager β WooCommerce to Google Shopping, Social Catalogs, and 170+ Popular Marketplaces plugin for W… | — | wordfence |
| 7303c2d0-f3b0-41b2-9786-acbe181ccb2e | < 5.1.6 |
LOW | 2.7 | The Bold Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 5.1.5. … | — | wordfence |
| 7115756e-69fa-42fe-bde3-a36e34d4bae3 | < 1.2.64 |
LOW | 2.7 | The UsersWP β Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordP… | — | wordfence |
| 6a8d0f86-73fe-43a6-a03a-38bf815dd30b | < 2.5.3 |
LOW | 2.7 | The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, an… | — | wordfence |
| 662aa8dd-69b7-49e3-811c-04329544e106 | < 0.9.121 |
LOW | 2.7 | The Migration, Backup, Staging β WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory … | — | wordfence |
| 640dafa4-c4b8-4f22-ab3b-441667c03428 | < 1.9.9 |
LOW | 2.7 | The Klarna Order Management for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all … | — | wordfence |
| 607d85a5-afad-49ac-9982-d3da0becc052 | < 3.6.4 |
LOW | 2.7 | The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.6… | — | wordfence |
| 5d4c92dd-a605-42b5-af10-0a0e25461dde | < 3.17.1 |
LOW | 2.7 | The Smush Image Optimization β Optimize Images | Compress & Lazy Load Images | Convert WebP & AVIF | Image CDN plugin … | — | wordfence |
| 5c3862db-d04b-40e2-8b5e-99cd3153d654 | < 1.0.277 |
LOW | 2.7 | The Rank Math SEO β AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access in… | — | wordfence |
| 5a62e8b2-7606-4842-8be5-dff8634539d0 | < 1.2.6 |
LOW | 2.7 | The Orders Tracking for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in versions up to, and inc… | — | wordfence |
| 4eb8f85f-656a-4e5a-a57d-7289da2cd951 | < 2.6.1 |
LOW | 2.7 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to ins… | — | wordfence |
| 4b78e38b-d16a-4891-96ae-6f6f7138dcc5 | LOW | 2.7 | The Site Info plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… | — | wordfence | |
| 4b389604-a999-45a1-a32f-7f8c951cb94c | < 3.7.4 |
LOW | 2.7 | The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, per… | — | wordfence |
| 4613f4d5-8c13-4007-8be0-40568d94fffe | < 1.5.1 |
LOW | 2.7 | The Auto Ad Inserter β Increase Google Adsense and Ad Manager Revenue plugin for WordPress is vulnerable to unauthoriz… | — | wordfence |
| 3c1a773f-6908-48fc-99d9-a718ee120855 | < 2.0.98 |
LOW | 2.7 | The Blocksy theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax_bl… | — | wordfence |
| 359c573f-7031-4f56-b66f-c37339667aca | < 7.6.4 |
LOW | 2.7 | The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization chec… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →