Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1599 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2025-64295 | < 4.8.7 |
LOW | N/A | All In One SEO Pack < 4.8.7 - Subscriber+ Information Exposure | — | wpscan |
| CVE-2025-63070 | < 3.3.33 |
LOW | N/A | Download Manager < 3.3.33 - Authenticated (Subscriber+) Information Exposure | — | wpscan |
| CVE-2025-6244 | < 6.1.20 |
LOW | N/A | Essential Addons for Elementor β Popular Elementor Templates and Widgets < 6.1.20 - Authenticated (Contributor+) Store… | — | wpscan |
| CVE-2025-62023 | < 251005 |
LOW | N/A | s2Member < 251005 - Unauthenticated Remote Code Execution | — | wpscan |
| CVE-2025-60093 | < 3.3.25 |
LOW | N/A | Download Manager < 3.3.25 - Cross-Site Request Forgery | — | wpscan |
| CVE-2025-60092 | < 3.3.26 |
LOW | N/A | Download Manager < 3.3.26 - Unauthenticated Sensitive Information Exposure | — | wpscan |
| CVE-2025-58998 | < 250905 |
LOW | N/A | s2Member < 250905 - Unauthenticated PHP Object Injection | — | wpscan |
| CVE-2025-58993 | < 3.8.0 |
LOW | N/A | Tutor LMS < 3.8.0 - Authenticated (Administrator+) SQL Injection | — | wpscan |
| CVE-2025-58650 | < 4.8.7.2 |
LOW | N/A | All In One SEO Pack < 4.8.7.2 - Missing Authorization | — | wpscan |
| CVE-2025-58649 | < 4.8.7.2 |
LOW | N/A | All In One SEO Pack < 4.8.7.2 - Contributor+ Sensitive Information Exposure | — | wpscan |
| CVE-2025-54940 | < 6.4.3 |
LOW | N/A | Advanced Custom Fields < 6.4.3 - HTML Injection | — | wpscan |
| CVE-2025-5398 | < 3.10.2.2 |
LOW | N/A | Ninja Forms < 3.10.2.2 - Contributor+ Stored XSS via CSTI | — | wpscan |
| CVE-2025-5144 | < 6.13.2.1 |
LOW | N/A | The Events Calendar < 6.13.2.1 - Contributor+ DOM-Based Stored XSS | — | wpscan |
| CVE-2025-5062 | < 9.4.3 |
LOW | N/A | WooCommerce < 9.4.3 - Reflected XSS | — | wpscan |
| CVE-2025-49333 | < 4.6.4 |
LOW | N/A | Simple Membership < 4.6.4 - Authenticated (Administrator+) Stored Cross-Site Scripting | — | wpscan |
| CVE-2025-49285 | < 3.8.1 |
LOW | N/A | WP Cookie Notice for GDPR, CCPA & ePrivacy Consent < 3.8.1 - Cross-Site Request Forgery | — | wpscan |
| CVE-2025-49042 | < 10.0.3 |
LOW | N/A | WooCommerce < 10.0.3 - Shop manager+ Stored XSS | — | wpscan |
| CVE-2025-48246 | < 6.12.0 |
LOW | N/A | The Events Calendar < 6.12.0 - Subscriber+ Import Creation | — | wpscan |
| CVE-2025-47555 | < 3.9.5 |
LOW | N/A | Tutor LMS < 3.9.5 - Authenticated (Instructor+) Insecure Direct Object Reference | — | wpscan |
| CVE-2025-47437 | < 7.1 |
LOW | N/A | LiteSpeed Cache < 7.1 - Editor+ Server-Side Request Forgery | — | wpscan |
| CVE-2025-4566 | < 3.30.3 |
LOW | N/A | Elementor < 3.30.3 - Contributor+ Stored XSS via Text Path Widget | — | wpscan |
| CVE-2025-4367 | < 3.3.19 |
LOW | N/A | Download Manager < 3.3.19 - Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode | — | wpscan |
| CVE-2025-39590 | < 6.1.10 |
LOW | N/A | Essential Addons for Elementor < 6.1.10 - Contributor+ Stored XSS | — | wpscan |
| CVE-2025-39589 | < 6.1.10 |
LOW | N/A | Essential Addons for Elementor < 6.1.10 - Contributor+ Information Disclosure | — | wpscan |
| CVE-2025-3951 | < 4.2.0 |
LOW | N/A | WP-Optimize < 4.2.0 - Admin+ SQLi | — | wpscan |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →