Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1606 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2024-4279 | < 2.7.1 |
LOW | N/A | Tutor LMS β eLearning and online course solution < 2.7.1 - Authenticated (Instructor+) Insecure Direct Object Referenc… | — | wpscan |
| CVE-2024-4275 | < 5.9.20 |
LOW | N/A | Essential Addons for Elementor β Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 5.9.20 - Contributor… | — | wpscan |
| CVE-2024-4223 | < 2.7.1 |
LOW | N/A | Tutor LMS < 2.7.1 - Missing Authorization | — | wpscan |
| CVE-2024-4180 | < 6.4.0.1 |
LOW | N/A | The Events Calendar < 6.4.0.1 - Reflected XSS | — | wpscan |
| CVE-2024-4160 | < 3.2.91 |
LOW | N/A | Download Manager < 3.2.91 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm-all-packages Shortcode | — | wpscan |
| CVE-2024-4156 | < 5.9.18 |
LOW | N/A | Essential Addons for Elementor β Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 5.9.18 - Contributor… | — | wpscan |
| CVE-2024-4041 | < 22.6 |
LOW | N/A | Yoast SEO < 22.6 - Reflected Cross-Site Scripting | — | wpscan |
| CVE-2024-4033 | < 3.6.5 |
LOW | N/A | All-in-One Video Gallery < 3.6.5 - Contributor+ Arbitrary File Upload via featured image | — | wpscan |
| CVE-2024-4003 | < 5.9.16 |
LOW | N/A | Essential Addons for Elementor β Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 5.9.16 - Contributor… | — | wpscan |
| CVE-2024-4001 | < 3.2.94 |
LOW | N/A | Download Manager < 3.2.94 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm_modal_login_form Shortcode | — | wpscan |
| CVE-2024-3994 | < 2.7.0 |
LOW | N/A | Tutor LMS β eLearning and online course solution < 2.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting vi… | — | wpscan |
| CVE-2024-39666 | < 9.1.4 |
LOW | N/A | WooCommerce < 9.1.4 - Stored XSS | — | wpscan |
| CVE-2024-39649 | < 5.9.27 |
LOW | N/A | Essential Addons for Elementor < 5.9.27 - Contributor+ Stored Cross-Site Scripting | — | wpscan |
| CVE-2024-39645 | < 2.7.3 |
LOW | N/A | Tutor LMS < 2.7.3 - Cross-Site Request Forgery | — | wpscan |
| CVE-2024-39628 | < 3.8.7 |
LOW | N/A | Ninja Forms < 3.8.7 - Cross-Site Request Forgery | — | wpscan |
| CVE-2024-3866 | < 3.8.16 |
LOW | N/A | Ninja Forms Contact Form < 3.8.16 - Reflected Self-Based Cross-Site Scripting via Referer | — | wpscan |
| CVE-2024-37956 | < 9.99.2.0 |
LOW | N/A | VK All in One Expansion Unit < 9.99.2.0 - Contributor+ Stored XSS | — | wpscan |
| CVE-2024-37947 | < 2.7.3 |
LOW | N/A | Tutor LMS < 2.7.3 - Authenticated (Tutor Instructor+) Stored Cross-Site Scripting | — | wpscan |
| CVE-2024-37934 | < 3.8.5 |
LOW | N/A | Ninja Forms < 3.8.5 - Authenticated (Subscriber+) Arbitrary Shortcode Execution | — | wpscan |
| CVE-2024-37518 | < 6.5.1.5 |
LOW | N/A | The Events Calendar < 6.5.1.5 - Cross-Site Request Forgery via action_restore_events | — | wpscan |
| CVE-2024-37437 | < 3.22.2 |
LOW | N/A | Elementor Website Builder < 3.22.2 - Contributor+ Arbitrary SVG Download | — | wpscan |
| CVE-2024-3743 | < 1.13.4 |
LOW | N/A | Elementor Addon Elements < 1.13.4 - Contributor+ Stored XSS | — | wpscan |
| CVE-2024-3733 | < 5.9.16 |
LOW | N/A | Essential Addons for Elementor < 5.9.16 - Information Exposure | — | wpscan |
| CVE-2024-3730 | < 4.4.4 |
LOW | N/A | Simple Membership < 4.4.4 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode | — | wpscan |
| CVE-2024-37297 | < 8.9.3 |
LOW | N/A | WooCommerce 8.8.0 - 8.9.2 - Reflected XSS | — | wpscan |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →