Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1601 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2025-15033 | < 8.1.3 |
LOW | N/A | WooCommerce - Subscriber/Customer+ Order Data Disclosure | — | wpscan |
| CVE-2025-14947 | < 4.7.1 |
LOW | N/A | All-in-One Video Gallery < 4.7.1 - Missing Authorization to Unauthenticated Bunny Stream Video Creation/Deletion | — | wpscan |
| CVE-2025-14732 | < 3.35.6 |
LOW | N/A | Elementor Website Builder < 3.35.6 - Contributor+ Stored XSS via REST API | — | wpscan |
| CVE-2025-14481 | < 26.6 |
LOW | N/A | Yoast SEO < 26.6 - Contributor+ IDOR to Sensitive Information Exposure via post_id Parameter | — | wpscan |
| CVE-2025-14384 | < 4.9.3 |
LOW | N/A | All in One SEO < 4.9.3 - Contributor+ AI Access Token and Credit Disclosure | — | wpscan |
| CVE-2025-14072 | < 3.13.3 |
LOW | N/A | Ninja Forms < 3.13.3 - Unauthenticated Token Generation and Submission Disclosure | — | wpscan |
| CVE-2025-14061 | < 4.0.8 |
LOW | N/A | Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Conse… | — | wpscan |
| CVE-2025-13977 | < 6.5.4 |
LOW | N/A | Essential Addons for Elementor < 6.5.4 - Contributor+ Stored XSS | — | wpscan |
| CVE-2025-13950 | < 3.6.2 |
LOW | N/A | OneSignal β Web Push Notifications < 3.6.2 - Missing Authorization to Unauthenticated Plugin Settings Update | — | wpscan |
| CVE-2025-13935 | < 3.9.4 |
LOW | N/A | Tutor LMS β eLearning and online course solution < 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Arbitr… | — | wpscan |
| CVE-2025-13934 | < 3.9.4 |
LOW | N/A | Tutor LMS β eLearning and online course solution < 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Course… | — | wpscan |
| CVE-2025-13732 | < 260101 |
LOW | N/A | s2Member < 260101 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | — | wpscan |
| CVE-2025-13679 | < 3.9.4 |
LOW | N/A | Tutor LMS < 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via tutor_order_… | — | wpscan |
| CVE-2025-13673 | < 3.9.7 |
LOW | N/A | Tutor LMS < 3.9.7 - Unauthenticated SQL Injection via coupon_code | — | wpscan |
| CVE-2025-13628 | < 3.9.4 |
LOW | N/A | Tutor LMS β eLearning and online course solution < 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Arbitr… | — | wpscan |
| CVE-2025-13498 | < 3.3.33 |
LOW | N/A | Download Manager < 3.3.33 - Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure | — | wpscan |
| CVE-2025-13355 | < 1.11.4 |
LOW | N/A | URL Shortify < 1.11.4 - Reflected XSS | — | wpscan |
| CVE-2025-12966 | < 4.6.4 |
LOW | N/A | All-in-One Video Gallery 4.5.4 - 4.5.7 β Authenticated (Author+) Arbitrary File Upload via Import ZIP | — | wpscan |
| CVE-2025-12957 | < 4.6.4 |
LOW | N/A | All-in-One Video Gallery < 4.6.4 - Authenticated (Author+) Arbitrary File Upload via VTT Upload Bypass | — | wpscan |
| CVE-2025-12847 | < 4.9.0 |
LOW | N/A | All in One SEO < 4.9.0 - Contributor+ Arbitrary Media Deletion | — | wpscan |
| CVE-2025-12714 | < 1.0.271.1 |
LOW | N/A | Rank Math SEO < 1.0.271.1 - Unauthenticated Homepage SEO Settings Modification | — | wpscan |
| CVE-2025-12684 | < 1.11.3 |
LOW | N/A | URL Shortify < 1.11.3 - Reflected XSS | — | wpscan |
| CVE-2025-12537 | < 1.14.4 |
LOW | N/A | Addon Elements for Elementor < 1.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting | — | wpscan |
| CVE-2025-12450 | < 7.6 |
LOW | N/A | LiteSpeed Cache < 7.6 - Reflected XSS | — | wpscan |
| CVE-2025-12197 | < 6.15.10 |
LOW | N/A | The Events Calendar 6.15.1.1 - 6.15.9 - Unauthenticated SQL Injection via s | — | wpscan |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →