Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1602 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2025-12192 | < 6.15.10 |
LOW | N/A | The Events Calendar < 6.15.10 - Unauthenticated Sensitive Information Exposure | — | wpscan |
| CVE-2025-12177 | < 3.3.31 |
LOW | N/A | Download Manager < 3.3.31 - Unauthenticated Cron Trigger due to Hardcoded Cron Key | — | wpscan |
| CVE-2025-12175 | < 6.15.10 |
LOW | N/A | The Events Calendar < 6.15.10 - Subscriber+ Draft Event Title/QR Code Exposure | — | wpscan |
| CVE-2025-11748 | < 3.8.0 |
LOW | N/A | Groups < 3.8.0 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Group Join | — | wpscan |
| CVE-2025-11707 | < 2.15 |
LOW | N/A | Login Lockdown & Protection < 2.15 - IP Block Bypass | — | wpscan |
| CVE-2025-11564 | < 3.9.0 |
LOW | N/A | Tutor LMS β eLearning and online course solution < 3.9.0 - Missing Authorization to Unauthenticated Payment Status Upd… | — | wpscan |
| CVE-2025-11267 | < 9.112.2 |
LOW | N/A | VK All in One Expansion Unit < 9.112.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | — | wpscan |
| CVE-2025-11265 | < 9.112.2 |
LOW | N/A | VK All in One Expansion Unit < 9.112.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | — | wpscan |
| CVE-2025-11220 | < 3.33.4 |
LOW | N/A | Elementor < 3.33.4 - Contributor+ Stored DOM-Based XSS via Text Path | — | wpscan |
| CVE-2025-10499 | < 3.12.1 |
LOW | N/A | Ninja Forms < 3.12.1 - Statistics Collection Opt In via CSRF | — | wpscan |
| CVE-2025-10498 | < 3.12.1 |
LOW | N/A | Ninja Forms < 3.12.1 - Limited File Deletion via CSRF | — | wpscan |
| CVE-2025-10146 | < 3.3.24 |
LOW | N/A | Download Manager < 3.3.24 - Reflected Cross-Site Scripting via `user_ids` Parameter | — | wpscan |
| CVE-2025-0215 | < 1.25.1 |
LOW | N/A | UpdraftPlus - Backup/Restore < 1.25.1 - Reflected XSS | — | wpscan |
| CVE-2024-9994 | < 6.1.13 |
LOW | N/A | Essential Addons for Elementor < 6.1.13 - Contributor+ Stored XSS via Pricing Table Widget | — | wpscan |
| CVE-2024-9993 | < 6.1.13 |
LOW | N/A | Essential Addons for Elementor < 6.1.13 - Contributor+ Stored XSS via Event Calendar Widget | — | wpscan |
| CVE-2024-9944 | < 9.1.0 |
LOW | N/A | WooCommerce < 9.1.0 - Unauthenticated HTML Injection | — | wpscan |
| CVE-2024-9926 | < 3.9.10 |
LOW | N/A | Jetpack < 13.9.1 - Subscriber+ Arbitrary Feedback Access | — | wpscan |
| CVE-2024-9529 | < 6.3.6.3 |
LOW | N/A | Secure Custom Fields < 6.3.6.3 - Admin+ Remote Code Execution | — | wpscan |
| CVE-2024-9314 | < 1.0.229 |
LOW | N/A | Rank Math SEO < 1.0.229 - Admin+ PHP Object Injection | — | wpscan |
| CVE-2024-9169 | < 6.5 |
LOW | N/A | litespeed cache < 6.5 - Authenticated (Administrator+) Stored Cross-Site Scripting | — | wpscan |
| CVE-2024-9162 | < 7.87 |
LOW | N/A | All-in-One WP Migration and Backup < 7.87 - Authenticated (Administrator+) Arbitrary PHP Code Injection | — | wpscan |
| CVE-2024-9161 | < 1.0.229 |
LOW | N/A | Rank Math SEO < 1.0.229 - Unauthenticated User and Term Metadata Insert/Update/Deletion | — | wpscan |
| CVE-2024-8979 | < 6.0.10 |
LOW | N/A | Essential Addons for Elementor β Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders < 6.0.10 - Auth… | — | wpscan |
| CVE-2024-8978 | < 6.0.10 |
LOW | N/A | Essential Addons for Elementor β Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders < 6.0.10 - Auth… | — | wpscan |
| CVE-2024-8961 | < 6.0.8 |
LOW | N/A | Essential Addons for Elementor β Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders < 6.0.8 - Authe… | — | wpscan |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →