Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1593 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 33356b50-9c9c-4719-8321-b391fda69867 | < 1.9.13 |
LOW | 2.7 | The Pricing Table by Supsystic plugin for WordPress is vulnerable to content injection in all versions up to, and includ… | — | wordfence |
| 30beb916-764e-48fd-bcd4-f772b9d92133 | < 1.6.1 |
LOW | 2.7 | The Squeeze β Image Optimization & Compression, WebP Conversion plugin for WordPress is vulnerable to Full Path Disclo… | — | wordfence |
| 2d8b816f-815a-4109-b34b-06e806c765e8 | < 4.8.4 |
LOW | 2.7 | The ShopEngine Elementor WooCommerce Builder Addon β All in One WooCommerce Solution plugin for WordPress is vulnerabl… | — | wordfence |
| 2d4e9daf-d414-4ace-9efd-4c3e16deeb8f | < 4.1.0 |
LOW | 2.7 | The WP Mail SMTP plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 4.0.1.… | — | wordfence |
| 2d443c70-6537-4c6d-a282-12d392f0f558 | < 2.6.3 |
LOW | 2.7 | The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici… | — | wordfence |
| 181403fe-42be-4136-8ff5-5ef40904124b | < 1.3.7 |
LOW | 2.7 | The WP Directory Kit plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.3.6. T… | — | wordfence |
| 1405d8e3-3aa8-4a32-ac55-a260eda3d68c | < 2.0.5 |
LOW | 2.7 | The Academy LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on t… | — | wordfence |
| 11c9124d-80e0-435d-9eb4-901c4f481a6f | < 1.0.4 |
LOW | 2.7 | The FileOrganizer plugin for WordPress is vulnerable to unauthorized access of data due to missing controls throughout t… | — | wordfence |
| 0bb96da1-9c17-4264-ac29-b5ff8dec745d | < 1.69.1 |
LOW | 2.7 | The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 v… | — | wordfence |
| 06f4b68c-eb17-470a-a119-5143eff7117e | LOW | 2.7 | The Traveler Option Tree plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and… | — | wordfence | |
| 045e3aba-16b6-46f1-8c57-dd54e1e0e950 | < 1.0.8.4 |
LOW | 2.7 | The WOLF β WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to PathTraversal in… | — | wordfence |
| 027fa70f-8777-4a0b-b2aa-18bcdcd99cbf | < 8.7.4 |
LOW | 2.7 | The Import feature of the RSVPMaker WordPress plugin before 8.7.4 (/wp-admin/tools.php?page=rsvpmaker_export_screen) tak… | — | wordfence |
| 01984754-e332-4500-99a2-10a7b79967f5 | < 2.1.3 |
LOW | 2.7 | The Keep Backup Daily plugin for WordPress is vulnerable to Limited Path Traversal in all versions up to, and including,… | — | wordfence |
| d5c48de7-20f6-408e-b4fb-f3d5d7ab272f | < 1.3.24 |
LOW | 2.4 | The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less … | — | wordfence |
| 92895f8e-59c9-4988-9d7a-2601880d71a2 | < 3.7.34 |
LOW | 2.4 | In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that coul… | — | wordfence |
| f029bd86-d979-45d1-97fe-75c43fb71148 | < 2.7.5 |
LOW | 2.2 | The Modula plugin for WordPress is vulnerable to unauthorized modification of data due to an incomplete capability check… | — | wordfence |
| 77227fc5-7c38-476d-af4c-4b2ad3dd8420 | < 5.0.29 |
LOW | 2.2 | The Church Admin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,… | — | wordfence |
| 73980a90-bb17-46e4-a0ea-691f80500fe3 | < 4.5.1.3 |
LOW | 2.2 | The MainWP Dashboard β WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to CSS … | — | wordfence |
| 640b1800-3b59-4b06-a803-08cb76d62d99 | < 6.3 |
LOW | 2.2 | The File Manager β 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager plugin for WordPress i… | — | wordfence |
| 4bce4f04-e622-468a-ac7e-5903ad50cc13 | < 4.0.3 |
LOW | 2.2 | The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up t… | — | wordfence |
| 1ea40b96-4693-4f98-8e6e-2ed8186cedd8 | < 1.3 |
LOW | 2.2 | The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in vers… | — | wordfence |
| 0585969d-dd08-4058-9d72-138a55a2cdf1 | < 4.2 |
LOW | 2.2 | The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up t… | — | wordfence |
| CVE-2026-8832 | < 2.3.6 |
LOW | N/A | WPCode < 2.3.6 - Author+ Remote Code Execution via XML-RPC wp.newPost | — | wpscan |
| CVE-2026-8825 | < 4.1.4 |
LOW | N/A | Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API | — | wpscan |
| CVE-2026-8438 | < 5.4.8 |
LOW | N/A | All-In-One Security (AIOS) < 5.4.8 - Unauthenticated Stored Cross-Site Scripting via REST API Request Path | — | wpscan |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →