Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1600 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2025-3794 | < 1.9.5.1 |
LOW | N/A | WPForms Lite < 1.9.5.1 - Contributor+ Stored XSS via 'start_timestamp' Parameter | — | wpscan |
| CVE-2025-3766 | < 2.12 |
LOW | N/A | Login Lockdown & Protection < 2.12 - Missing Authorization to Authenticated (Subscriber+) Arbitrary IP Whitelisting | — | wpscan |
| CVE-2025-3404 | < 3.3.13 |
LOW | N/A | Download Manager < 3.3.13 - Author+ Arbitrary File Deletion | — | wpscan |
| CVE-2025-3247 | < 6.0.6 |
LOW | N/A | Contact Form 7 < 6.0.6 - Order Replay Vulnerability | — | wpscan |
| CVE-2025-32230 | < 3.4.1 |
LOW | N/A | Tutor LMS < 3.4.1 - Subscriber+ HTML Injection | — | wpscan |
| CVE-2025-32223 | < 3.9.5 |
LOW | N/A | Tutor LMS β eLearning and online course solution < 3.9.5 - Authenticated (Subscriber+) Insecure Direct Object Referenc… | — | wpscan |
| CVE-2025-32188 | < 2.16 |
LOW | N/A | Advanced Woo Labels < 2.16 - Contributor+ Stored XSS | — | wpscan |
| CVE-2025-32137 | < 250424 |
LOW | N/A | s2Member < 250424 - Administrator+ Local File Inclusion | — | wpscan |
| CVE-2025-32134 | < 1.10.6 |
LOW | N/A | URL Shortify < 1.10.6 - Authenticated (Administrator+) Stored Cross-Site Scripting | — | wpscan |
| CVE-2025-31081 | < 4.1.6 |
LOW | N/A | Enable Media Replace < 4.1.6 - Reflected XSS | — | wpscan |
| CVE-2025-3075 | < 3.29.1 |
LOW | N/A | Elementor < 3.29.1 - Contributor+ Stored XSS | — | wpscan |
| CVE-2025-3056 | < 3.3.13 |
LOW | N/A | Download Manager < 3.3.13 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload | — | wpscan |
| CVE-2025-2892 | < 4.8.2 |
LOW | N/A | All in One SEO Pack < 4.8.2 - Contributor+ Stored XSS via Post Meta Description and Canonical URL | — | wpscan |
| CVE-2025-26879 | < 250214 |
LOW | N/A | s2Member Pro < 250214 - Reflected Cross-Site Scripting | — | wpscan |
| CVE-2025-26762 | < 9.7.1 |
LOW | N/A | Woocommerce < 9.7.1 - Shop Manager+ Stored XSS via New Product Form | — | wpscan |
| CVE-2025-2561 | < 3.10.1 |
LOW | N/A | Ninja Forms < 3.10.1 - Admin+ Stored XSS | — | wpscan |
| CVE-2025-2560 | < 3.10.1 |
LOW | N/A | Ninja Forms < 3.10.1 - Admin+ Stored XSS | — | wpscan |
| CVE-2025-2524 | < 3.10.1 |
LOW | N/A | Ninja Forms < 3.10.1 - Admin+ Stored XSS | — | wpscan |
| CVE-2025-24752 | < 6.0.15 |
LOW | N/A | Essential Addons for Elementor < 6.0.15 - Reflected Cross-Site Scripting | — | wpscan |
| CVE-2025-24623 | < 9.2.0 |
LOW | N/A | Really Simple SSL < 9.2.0 - Cross-Site Request Forgery | — | wpscan |
| CVE-2025-24537 | < 6.7.1 |
LOW | N/A | The Events Calendar < 6.7.1 - Trashed Events Restoration via CSRF | — | wpscan |
| CVE-2025-1785 | < 3.3.09 |
LOW | N/A | Download Manager < 3.3.09 - Authenticated (Author+) Path Traversal to Limited File Overwrite | — | wpscan |
| CVE-2025-15516 | < 4.7.1 |
LOW | N/A | All-in-One Video Gallery 4.1.0 - 4.6.4 - Missing Authorization to Authenticated (Subscriber+) Limited User Meta Update | — | wpscan |
| CVE-2025-15364 | < 3.3.41 |
LOW | N/A | Download Manager < 3.3.41 - Unauthenticated Limited Privilege Escalation | — | wpscan |
| CVE-2025-15043 | < 6.15.13.1 |
LOW | N/A | The Events Calendar < 6.15.13.1 - Subscriber+ Data Migration Control | — | wpscan |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →