Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1611 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2024-0761 | < 7.2.2 |
LOW | N/A | File Manager < 7.2.2 - Sensitive Information Exposure via Backup Filenames | — | wpscan |
| CVE-2024-0685 | < 3.7.2 |
LOW | N/A | Ninja Forms Contact Form < 3.7.2 - Unauthenticated Second Order SQL Injection | — | wpscan |
| CVE-2024-0586 | < 5.9.5 |
LOW | N/A | Essential Addons for Elementor < 5.9.5 - Contributor+ Stored Cross-Site Scritping | — | wpscan |
| CVE-2024-0585 | < 5.9.5 |
LOW | N/A | Essential Addons for Elementor < 5.9.5 - Contributor+ Stored Cross-Site Scripting via Image URl | — | wpscan |
| CVE-2024-0509 | < 1.0.4 |
LOW | N/A | WP 404 Auto Redirect to Similar Post < 1.0.4 - Reflected Cross-Site Scripting via request | — | wpscan |
| CVE-2024-0506 | < 3.19.0 |
LOW | N/A | Elementor Website Builder β More than Just a Page Builder < 3.19.0 - Authenticated (Contributor+) Stored Cross-Site Sc… | — | wpscan |
| CVE-2023-7044 | < 5.9.3 |
LOW | N/A | Essential Addons for Elementor < 5.9.3 - Contributor+ Stored XSS | — | wpscan |
| CVE-2023-6954 | < 3.2.86 |
LOW | N/A | Download Manager < 3.2.86 - Contributor+ Stored XSS | — | wpscan |
| CVE-2023-6882 | < 4.3.9 |
LOW | N/A | Simple Membership < 4.3.9 - Reflected Cross-Site Scripting Vulnerability via environment_mode | — | wpscan |
| CVE-2023-6825 | < 7.2.2 |
LOW | N/A | File Manager And File Manager Pro (Multiple Versions) - Directory Traversal | — | wpscan |
| CVE-2023-6785 | < 3.2.85 |
LOW | N/A | Download Manager < 3.2.85 - Unauthenticated File Download | — | wpscan |
| CVE-2023-6751 | < 1.9.8 |
LOW | N/A | Hostinger < 1.9.8 - Unauthenticated Maintenance Mode Toggle | — | wpscan |
| CVE-2023-6737 | < 4.1.5 |
LOW | N/A | Enable Media Replace < 4.1.5 - Reflected Cross-Site Scripting | — | wpscan |
| CVE-2023-6701 | < 6.2.5 |
LOW | N/A | Advanced Custom Fields < 6.2.5 - Contributor+ Stored Cross-Site Scripting via Custom Field | — | wpscan |
| CVE-2023-6557 | < 6.2.9 |
LOW | N/A | The Events Calendar < 6.2.9 - Unauthenticated Sensitive Information Exposure | — | wpscan |
| CVE-2023-6449 | < 5.8.4 |
LOW | N/A | Contact Form 7 < 5.8.4 - Authenticated (Editor+) Arbitrary File Upload | — | wpscan |
| CVE-2023-6421 | < 3.2.83 |
LOW | N/A | Download Manager < 3.2.83 - Unauthenticated Protected File Download Password Leak | — | wpscan |
| CVE-2023-6203 | < 6.2.8.1 |
LOW | N/A | The Events Calendar < 6.2.8.1 - Unauthenticated Arbitrary Password Protected Post Read | — | wpscan |
| CVE-2023-5982 | < 1.23.11 |
LOW | N/A | UpdraftPlus: WordPress Backup & Migration < 1.23.11 - Google Drive Storage Update via CSRF | — | wpscan |
| CVE-2023-5605 | < 1.7.9.1 |
LOW | N/A | URL Shortify < 1.7.9.1 - Admin+ Stored XSS | — | wpscan |
| CVE-2023-5530 | < 3.6.34 |
LOW | N/A | Ninja Forms < 3.6.34 - Admin+ Stored XSS | — | wpscan |
| CVE-2023-5381 | < 1.12.8 |
LOW | N/A | Elementor Addon Elements < 1.12.8 - Admin+ Stored XSS | — | wpscan |
| CVE-2023-52222 | < 8.3.0 |
LOW | N/A | WooCommerce < 8.3.0 - Cross-Site Request Forgery | — | wpscan |
| CVE-2023-52147 | < 5.2.5 |
LOW | N/A | All In One WP Security < 5.2.5 - Protection Bypass of Renamed Login Page via URL Encoding | — | wpscan |
| CVE-2023-51682 | < 4.9.10 |
LOW | N/A | MC4WP < 4.9.10 - Unauthenticated Unpublished Form Preview | — | wpscan |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →