Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1612 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2023-50837 | < 2.07 |
LOW | N/A | Login Lockdown < 2.07 - Admin+ SQLi | — | wpscan |
| CVE-2023-49829 | < 2.3.0 |
LOW | N/A | Tutor LMS < 2.3.0 - Admin+ Stored XSS | — | wpscan |
| CVE-2023-48777 | < 3.18.2 |
LOW | N/A | Elementor < 3.18.2 - Contributor+ Arbitrary File Upload to RCE via Template Import | — | wpscan |
| CVE-2023-4805 | < 2.3.0 |
LOW | N/A | Tutor LMS < 2.3.0 - Subscriber+ Stored Cross-Site Scripting | — | wpscan |
| CVE-2023-47788 | < 12.7 |
LOW | N/A | Jetpack < 12.7 - Improper Authorization via WPCom External Media REST endpoints | — | wpscan |
| CVE-2023-47777 | < 8.2.0 |
LOW | N/A | WooCommerce <= 8.1.1 & WooCommerce Blocks <= 11.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Featu… | — | wpscan |
| CVE-2023-47774 | < 12.7 |
LOW | N/A | Jetpack < 12.7 - Authenticated(Contributor+) Clickjacking via Iframe Injection | — | wpscan |
| CVE-2023-47505 | < 3.16.5 |
LOW | N/A | Elementor Website Builder < 3.16.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_inline_svg() | — | wpscan |
| CVE-2023-47504 | < 3.16.5 |
LOW | N/A | Elementor Website Builder < 3.16.5 - Missing Authorization to Arbitrary Attachment Read | — | wpscan |
| CVE-2023-4723 | < 1.12.8 |
LOW | N/A | Elementor Addon Elements < 1.12.8 - Unauthenticated Post ID/Tile Disclosure | — | wpscan |
| CVE-2023-4719 | < 4.3.6 |
LOW | N/A | Simple Membership < 4.3.6 - Reflected XSS | — | wpscan |
| CVE-2023-4690 | < 1.12.8 |
LOW | N/A | Elementor Addon Elements < 1.12.8 - Settings Update via CSRF | — | wpscan |
| CVE-2023-4689 | < 1.12.8 |
LOW | N/A | Elementor Addon Elements < 1.12.8 - Elementor Addon Element Enabling/Disabling via CSRF | — | wpscan |
| CVE-2023-4643 | < 4.1.3 |
LOW | N/A | Enable Media Replace < 4.1.3 - Author+ PHP Object Injection | — | wpscan |
| CVE-2023-45050 | < 12.8-a.3 |
LOW | N/A | Jetpack < 12.8-a.3 - Contributor+ Stored XSS via block attribute | — | wpscan |
| CVE-2023-45000 | < 5.7.0.1 |
LOW | N/A | LiteSpeed Cache < 5.7.0.1 - Unauthenticated CDN Status Update | — | wpscan |
| CVE-2023-44983 | < 2.0.7 |
LOW | N/A | Aruba HiSpeed Cache < 2.0.7 - Unauthenticated Log File Access | — | wpscan |
| CVE-2023-4372 | < 5.7 |
LOW | N/A | LiteSpeed Cache < 5.7 - Contributor+ Stored XSS | — | wpscan |
| CVE-2023-4294 | < 1.7.6 |
LOW | N/A | URL Shortify < 1.7.6 - Unauthenticated Stored XSS via referer header | — | wpscan |
| CVE-2023-41957 | < 4.3.5 |
LOW | N/A | Simple Membership < 4.3.5 - Privilege escalation via Registration | — | wpscan |
| CVE-2023-41956 | < 4.3.5 |
LOW | N/A | Simple Membership < 4.3.5 - Account Takeover via Password Reset | — | wpscan |
| CVE-2023-41955 | < 5.8.9 |
LOW | N/A | Essential Addons for Elementor < 5.8.9 - Authenticated (Contributor+) Privilege Escalation | — | wpscan |
| CVE-2023-4109 | < 3.6.26 |
LOW | N/A | Ninja Forms < 3.6.26 - Admin+ Stored HTML Injection | — | wpscan |
| CVE-2023-40680 | < 21.1 |
LOW | N/A | Yoast SEO < 21.1 - Authenticated (Seo Manager+) Stored Cross-Site Scripting | — | wpscan |
| CVE-2023-40206 | < 1.0.4 |
LOW | N/A | WP 404 Auto Redirect to Similar Post < 1.0.4 - Admin+ Stored XSS | — | wpscan |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →