Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1598 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2026-10795 | < 1.26.5 |
LOW | N/A | UpdraftPlus < 1.26.5 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc | — | wpscan |
| CVE-2026-10755 | < 4.9.9 |
LOW | N/A | All in One SEO < 4.9.9 β Contributor+ Incorrect Authorization via AI Integration | — | wpscan |
| CVE-2026-10753 | < 1.176.0 |
LOW | N/A | Site Kit by Google < 1.176.0 - Editor+ Email Reporting Settings Update | — | wpscan |
| CVE-2026-10736 | < 3.9.12 |
LOW | N/A | Tutor LMS < 3.9.12 - Authenticated (Administrator+) SQL Injection via 'data' Parameter | — | wpscan |
| CVE-2026-1004 | < 6.5.6 |
LOW | N/A | Essential Addons for Elementor < 6.5.6 - Unauthenticated Sensitive Information Exposure | — | wpscan |
| CVE-2026-0548 | < 3.9.5 |
LOW | N/A | Tutor LMS β eLearning and online course solution < 3.9.5 - Missing Authorization to Authenticated (Subscriber+) Limite… | — | wpscan |
| CVE-2025-9808 | < 6.15.3 |
LOW | N/A | The Events Calendar < 6.15.3 - Unauthenticated Password-Protected Information Disclosure | — | wpscan |
| CVE-2025-9807 | < 6.15.1.1 |
LOW | N/A | The Events Calendar < 6.15.1.1 - Unauthenticated SQL Injection | — | wpscan |
| CVE-2025-9496 | < 4.1.7 |
LOW | N/A | Enable Media Replace < 4.1.7 - Contributor+ Stored XSS | — | wpscan |
| CVE-2025-9083 | < 3.11.1 |
LOW | N/A | Ninja-forms < 3.11.1 - Unauthenticated PHP Object Injection | — | wpscan |
| CVE-2025-8490 | < 7.98 |
LOW | N/A | All-in-One WP Migration and Backup < 7.98 - Admin+ Stored XSS | — | wpscan |
| CVE-2025-8451 | < 6.2.3 |
LOW | N/A | Essential Addons for Elementor < 6.2.3 - Contributor+ DOM-Based Stored XSS | — | wpscan |
| CVE-2025-8081 | < 3.30.3 |
LOW | N/A | Elementor < 3.30.3 - Admin+ Arbitrary File Read via Image Import | — | wpscan |
| CVE-2025-69352 | < 6.15.13 |
LOW | N/A | The Events Calendar < 6.15.13 - Missing Authorization | — | wpscan |
| CVE-2025-69092 | < 6.5.4 |
LOW | N/A | Essential Addons for Elementor < 6.5.4 - Contributor+ Stored XSS | — | wpscan |
| CVE-2025-67950 | < 4.9.1.1 |
LOW | N/A | All In One SEO Pack < 4.9.1.1 - Contributor+ SQL Injection | — | wpscan |
| CVE-2025-67913 | < 3.0.3 |
LOW | N/A | Aruba HiSpeed Cache < 3.0.3 - Missing Authorization | — | wpscan |
| CVE-2025-67588 | < 3.33.1 |
LOW | N/A | Elementor Website Builder < 3.33.1 - Missing Authorization | — | wpscan |
| CVE-2025-6680 | < 3.9.0 |
LOW | N/A | Tutor LMS < 3.9.0 - Missing Authorization to Sensitive Information Exposure | — | wpscan |
| CVE-2025-66133 | < 4.0.8 |
LOW | N/A | Cookie Notice for GDPR, CCPA & ePrivacy Consent < 4.0.8 - Missing Authorization | — | wpscan |
| CVE-2025-66080 | < 4.0.4 |
LOW | N/A | Cookie Notice for GDPR, CCPA & ePrivacy Consent < 4.0.4 - Missing Authorization | — | wpscan |
| CVE-2025-66075 | < 4.0.4 |
LOW | N/A | Cookie Notice for GDPR, CCPA & ePrivacy Consent < 4.0.4 - Missing Authorization | — | wpscan |
| CVE-2025-64352 | < 6.3.0 |
LOW | N/A | Essential Addons for Elementor < 6.3.0 - Missing Authorization | — | wpscan |
| CVE-2025-64351 | < 1.0.253 |
LOW | N/A | Rank Math SEO < 1.0.253 - Subscriber+ Information Exposure | — | wpscan |
| CVE-2025-64350 | < 1.0.253 |
LOW | N/A | Rank Math SEO < 1.0.253 - Missing Authorization | — | wpscan |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →