Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1604 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2024-56217 | < 3.3.04 |
LOW | N/A | Download Manager < 3.3.04 - Missing Authorization | — | wpscan |
| CVE-2024-56063 | < 6.0.8 |
LOW | N/A | Essential Addons for Elementor < 6.0.8 - Contributor+ Stored XSS | — | wpscan |
| CVE-2024-5573 | < 2.0.66 |
LOW | N/A | Easy Table of Contents < 2.0.66 - Admin+ Stored XSS | — | wpscan |
| CVE-2024-54444 | < 3.25.11 |
LOW | N/A | Elementor Website Builder < 3.25.11 - Contributor+ Stored XSS | — | wpscan |
| CVE-2024-5438 | < 2.7.2 |
LOW | N/A | Tutor LMS β eLearning and online course solution < 2.7.2 - Authenticated (Instructor+) Insecure Direct Object Referenc… | — | wpscan |
| CVE-2024-5416 | < 3.24.0 |
LOW | N/A | Elementor Website Builder β More than Just a Page Builder < 3.24.0 - Authenticated (Contributor+) Stored Cross-Site Sc… | — | wpscan |
| CVE-2024-5333 | < 6.8.2.1 |
LOW | N/A | The Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosure | — | wpscan |
| CVE-2024-5266 | < 3.2.94 |
LOW | N/A | Download Manager < 3.2.94 - Authenticated (Author+) Stored Cross-Site Scripting via Multiple Shortcodes | — | wpscan |
| CVE-2024-51915 | < 6.5.3 |
LOW | N/A | LiteSpeed Cache < 6.5.3 - Contributor+ Stored XSS | — | wpscan |
| CVE-2024-5189 | < 5.9.24 |
LOW | N/A | Essential Addons for Elementor β Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 5.9.24 - Authenticat… | — | wpscan |
| CVE-2024-5188 | < 5.9.23 |
LOW | N/A | Essential Addons for Elementor β Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 5.9.23 - Authenticat… | — | wpscan |
| CVE-2024-51815 | < 241216 |
LOW | N/A | s2Member (Pro) < 241216 - Unauthenticated Remote Code Execution | — | wpscan |
| CVE-2024-5073 | < 5.9.22 |
LOW | N/A | Essential Addons for Elementor < 5.9.22 - Contributor+ Stored Cross-Site Scripting via Twitter Feed | — | wpscan |
| CVE-2024-50555 | < 3.29.1 |
LOW | N/A | Elementor Website Builder < 3.29.1 - Contributor+ Stored XSS | — | wpscan |
| CVE-2024-50550 | < 6.5.2 |
LOW | N/A | LiteSpeed Cache < 6.5.2 - Unauthenticated Privilege Escalation | — | wpscan |
| CVE-2024-50515 | < 3.8.18 |
LOW | N/A | Ninja Forms < 3.8.18 - Admin+ Stored XSS | — | wpscan |
| CVE-2024-50514 | < 3.8.18 |
LOW | N/A | Ninja Forms < 3.8.18 - Admin+ Stored XSS | — | wpscan |
| CVE-2024-4984 | < 22.7 |
LOW | N/A | Yoast SEO < 22.7 - Authenticated (Contributor+) Stored Cross-Site Scripting | — | wpscan |
| CVE-2024-49682 | < 4.5.4 |
LOW | N/A | Simple Membership < 4.5.4 - Unauthenticated Open Redirect | — | wpscan |
| CVE-2024-49593 | < 6.3.6.3 |
LOW | N/A | Secure Custom Fields < 6.3.6.3 - Admin+ Stored XSS | — | wpscan |
| CVE-2024-4902 | < 2.7.2 |
LOW | N/A | Tutor LMS β eLearning and online course solution < 2.7.2 -Authenticated (Administrator+) SQL Injection | — | wpscan |
| CVE-2024-4869 | < 3.3.0 |
LOW | N/A | WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) < 3.3.0 - Unauthenticated Stored Cross-Site Scripting via Client-IP head… | — | wpscan |
| CVE-2024-47637 | < 6.5.1 |
LOW | N/A | LiteSpeed Cache < 6.5.1 - Author+ Path Traversal | — | wpscan |
| CVE-2024-47622 | < 2.02 |
LOW | N/A | Advanced Woo Labels < 2.02 - Authenticated (Contributor+) Stored Cross-Site Scripting | — | wpscan |
| CVE-2024-47374 | < 6.5.1 |
LOW | N/A | LiteSpeed Cache < 6.5.1 - Unauthenticated Stored Cross-Site Scripting | — | wpscan |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →