Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1613 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2023-40000 | < 5.7.0.1 |
LOW | N/A | LiteSpeed Cache < 5.7.0.1 - Unauthenticated Stored XSS | — | wpscan |
| CVE-2023-38393 | < 3.6.26 |
LOW | N/A | Ninja Forms < 3.6.26 - Subscriber+ Form Entries Export | — | wpscan |
| CVE-2023-38386 | < 3.6.26 |
LOW | N/A | Ninja Forms < 3.6.26 - Contributor+ Form Entries Export | — | wpscan |
| CVE-2023-37979 | < 3.6.26 |
LOW | N/A | Ninja Forms < 3.6.26 - Reflected Cross-Site Scripting | — | wpscan |
| CVE-2023-3779 | < 5.8.2 |
LOW | N/A | Essential Addons For Elementor < 5.8.2 - Unauthenticated MailChimp API Key Disclosure | — | wpscan |
| CVE-2023-36505 | < 3.6.25 |
LOW | N/A | Ninja Forms < 3.6.25 - Admin+ Arbitrary File Deletion | — | wpscan |
| CVE-2023-3524 | < 2.0.13.1 |
LOW | N/A | WPCode < 2.0.13.1 - Reflected XSS | — | wpscan |
| CVE-2023-33999 | < 6.1.0 |
LOW | N/A | Freemius SDK < 2.5.10 - Reflected Cross-Site Scripting | — | wpscan |
| CVE-2023-32960 | < 1.23.4 |
LOW | N/A | UpdraftPlus < 1.23.4 - CSRF | — | wpscan |
| CVE-2023-32600 | < 1.0.119.1 |
LOW | N/A | Rank Math SEO < 1.0.119.1 - Contributor+ Stored XSS | — | wpscan |
| CVE-2023-32243 | < 5.7.2 |
LOW | N/A | Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation | — | wpscan |
| CVE-2023-3133 | < 2.2.1 |
LOW | N/A | Tutor LMS < 2.2.1 - Unauthenticated Access to Tutor LMS Lesson Resources via REST API | — | wpscan |
| CVE-2023-3129 | < 1.7.0 |
LOW | N/A | URL Shortify < 1.7.0 - Admin+ Cross Site Scripting | — | wpscan |
| CVE-2023-30777 | < 6.1.6 |
LOW | N/A | Advanced Custom Fields < 6.1.6 - Reflected XSS | — | wpscan |
| CVE-2023-30500 | < 1.8.1.3 |
LOW | N/A | Contact Form by WPForms < 1.8.1.3 - Reflected XSS | — | wpscan |
| CVE-2023-2996 | < 12.1.1 |
LOW | N/A | Jetpack < 12.1.1 - Author+ Arbitrary File Manipulation via API | — | wpscan |
| CVE-2023-2919 | < 2.7.5 |
LOW | N/A | Tutor LMS < 2.7.5 - Cross-Site Request Forgery via 'addon_enable_disable' | — | wpscan |
| CVE-2023-27923 | < 9.88.2 |
LOW | N/A | VK All in One Expansion Unit < 9.88.2 - Multiple Stored XSS | — | wpscan |
| CVE-2023-25990 | < 2.2.0 |
LOW | N/A | Tutor LMS < 2.2.0 - Instructor+ SQL Injection | — | wpscan |
| CVE-2023-25800 | < 2.2.1 |
LOW | N/A | Tutor LMS < 2.2.1 - Student+ SQL Injection | — | wpscan |
| CVE-2023-25700 | < 2.2.0 |
LOW | N/A | Tutor LMS < 2.2.0 - Unauthenticate SQL Injection | — | wpscan |
| CVE-2023-23888 | < 1.0.107.3 |
LOW | N/A | Rank Math SEO < 1.0.107.3 - Contributor+ LFI | — | wpscan |
| CVE-2023-2305 | < 3.2.71 |
LOW | N/A | Download Manager < 3.2.71 - Contributor+ Stored Cross-Site Scripting | — | wpscan |
| CVE-2023-2296 | < 1.7.9 |
LOW | N/A | Loginizer 1.7.8 - Reflected XSS | — | wpscan |
| CVE-2023-1835 | < 3.6.22 |
LOW | N/A | Ninja Forms < 3.6.22 - Reflected XSS | — | wpscan |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →