Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1603 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2024-8902 | < 1.13.9 |
LOW | N/A | Elementor Addon Elements < 1.13.9 - Authenticated (Contributor+) Sensitive Information Exposure via table_saved_sections | — | wpscan |
| CVE-2024-8852 | < 7.87 |
LOW | N/A | All-in-One WP Migration and Backup < 7.87 - Unauthenticated Information Disclosure via Error Logs | — | wpscan |
| CVE-2024-8850 | < 4.9.17 |
LOW | N/A | MC4WP: Mailchimp for WordPress 4.9.9 - 4.9.16 - Reflected Cross-Site Scripting | — | wpscan |
| CVE-2024-8742 | < 6.0.4 |
LOW | N/A | Essential Addons for Elementor < 6.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery… | — | wpscan |
| CVE-2024-8680 | < 4.9.17 |
LOW | N/A | MailChimp for Wordpress < 4.9.17 - Authenticated (Administrator+) Stored Cross-Site Scripting | — | wpscan |
| CVE-2024-8493 | < 6.6.4 |
LOW | N/A | The Events Calendar < 6.6.4 - Admin+ Stored XSS | — | wpscan |
| CVE-2024-8444 | < 3.3.00 |
LOW | N/A | Download Manager < 3.3.00 - Contributor+ Stored XSS | — | wpscan |
| CVE-2024-8440 | < 6.0.4 |
LOW | N/A | Essential Addons for Elementor -- Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 6.0.4 - Authenticated… | — | wpscan |
| CVE-2024-8326 | < 241216 |
LOW | N/A | s2Member β Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions < 241216… | — | wpscan |
| CVE-2024-8284 | < 3.2.99 |
LOW | N/A | Download Manager <= 3.2.98 - Admin+ Stored XSS | — | wpscan |
| CVE-2024-8275 | < 6.6.4.1 |
LOW | N/A | The Events Calendar < 6.6.4.1 - Unauthenticated SQL Injection | — | wpscan |
| CVE-2024-8236 | < 3.25.8 |
LOW | N/A | Elementor Website Builder < 3.25.8 - Contributor+ Stored XSS | — | wpscan |
| CVE-2024-7354 | < 3.8.11 |
LOW | N/A | Ninja Forms 3.8.6-3.8.10 - Reflected XSS | — | wpscan |
| CVE-2024-7122 | < 1.13.7 |
LOW | N/A | Elementor Addon Elements < 1.13.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets | — | wpscan |
| CVE-2024-7092 | < 6.0.0 |
LOW | N/A | Essential Addons for Elementor β Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 6.0.0 - Authenticate… | — | wpscan |
| CVE-2024-7082 | < 2.0.68 |
LOW | N/A | easy-table-of-contents < 2.0.68 - Editor+ Stored XSS | — | wpscan |
| CVE-2024-7056 | < 1.9.1.6 |
LOW | N/A | WPForms < 1.9.1.6 - Admin+ Stored XSS | — | wpscan |
| CVE-2024-6931 | < 6.5.2 |
LOW | N/A | The Events Calendar < 6.5.2 - Unauthenticated Stored Cross-Site Scripting | — | wpscan |
| CVE-2024-6757 | < 3.24.6 |
LOW | N/A | Elementor < 3.24.6 - Contributor+ Information Exposure via get_image_alt | — | wpscan |
| CVE-2024-6694 | < 4.1.0 |
LOW | N/A | WP Mail SMTP < 4.1.0 - Admin+ SMTP Password Exposure | — | wpscan |
| CVE-2024-6629 | < 3.8.3 |
LOW | N/A | All-in-One Video Gallery < 3.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Shortcode | — | wpscan |
| CVE-2024-6334 | < 2.0.67.1 |
LOW | N/A | Easy Table of Contents < 2.0.67 - Editor+ Stored XSS | — | wpscan |
| CVE-2024-6208 | < 3.2.98 |
LOW | N/A | Download Manager < 3.2.98 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | — | wpscan |
| CVE-2024-5647 | < 6.0.5 |
LOW | N/A | Magnific Popups JavaScript Library < 1.2.0 - Contributor+ Stored XSS | — | wpscan |
| CVE-2024-56276 | < 1.9.2.3 |
LOW | N/A | Contact Form by WPForms < 1.9.2.3 - Contributor+ Custom Form Theme Creation | — | wpscan |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →