Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,634 vulnerabilities found (page 1616 of 1626)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2023-45000 | < 5.7.0.1 |
LOW | N/A | LiteSpeed Cache < 5.7.0.1 - Unauthenticated CDN Status Update | — | wpscan |
| CVE-2023-44983 | < 2.0.7 |
LOW | N/A | Aruba HiSpeed Cache < 2.0.7 - Unauthenticated Log File Access | — | wpscan |
| CVE-2023-4372 | < 5.7 |
LOW | N/A | LiteSpeed Cache < 5.7 - Contributor+ Stored XSS | — | wpscan |
| CVE-2023-4294 | < 1.7.6 |
LOW | N/A | URL Shortify < 1.7.6 - Unauthenticated Stored XSS via referer header | — | wpscan |
| CVE-2023-41957 | < 4.3.5 |
LOW | N/A | Simple Membership < 4.3.5 - Privilege escalation via Registration | — | wpscan |
| CVE-2023-41956 | < 4.3.5 |
LOW | N/A | Simple Membership < 4.3.5 - Account Takeover via Password Reset | — | wpscan |
| CVE-2023-41955 | < 5.8.9 |
LOW | N/A | Essential Addons for Elementor < 5.8.9 - Authenticated (Contributor+) Privilege Escalation | — | wpscan |
| CVE-2023-4109 | < 3.6.26 |
LOW | N/A | Ninja Forms < 3.6.26 - Admin+ Stored HTML Injection | — | wpscan |
| CVE-2023-40680 | < 21.1 |
LOW | N/A | Yoast SEO < 21.1 - Authenticated (Seo Manager+) Stored Cross-Site Scripting | — | wpscan |
| CVE-2023-40206 | < 1.0.4 |
LOW | N/A | WP 404 Auto Redirect to Similar Post < 1.0.4 - Admin+ Stored XSS | — | wpscan |
| CVE-2023-40000 | < 5.7.0.1 |
LOW | N/A | LiteSpeed Cache < 5.7.0.1 - Unauthenticated Stored XSS | — | wpscan |
| CVE-2023-38393 | < 3.6.26 |
LOW | N/A | Ninja Forms < 3.6.26 - Subscriber+ Form Entries Export | — | wpscan |
| CVE-2023-38386 | < 3.6.26 |
LOW | N/A | Ninja Forms < 3.6.26 - Contributor+ Form Entries Export | — | wpscan |
| CVE-2023-37979 | < 3.6.26 |
LOW | N/A | Ninja Forms < 3.6.26 - Reflected Cross-Site Scripting | — | wpscan |
| CVE-2023-3779 | < 5.8.2 |
LOW | N/A | Essential Addons For Elementor < 5.8.2 - Unauthenticated MailChimp API Key Disclosure | — | wpscan |
| CVE-2023-36505 | < 3.6.25 |
LOW | N/A | Ninja Forms < 3.6.25 - Admin+ Arbitrary File Deletion | — | wpscan |
| CVE-2023-3524 | < 2.0.13.1 |
LOW | N/A | WPCode < 2.0.13.1 - Reflected XSS | — | wpscan |
| CVE-2023-33999 | < 6.1.0 |
LOW | N/A | Freemius SDK < 2.5.10 - Reflected Cross-Site Scripting | — | wpscan |
| CVE-2023-32960 | < 1.23.4 |
LOW | N/A | UpdraftPlus < 1.23.4 - CSRF | — | wpscan |
| CVE-2023-32600 | < 1.0.119.1 |
LOW | N/A | Rank Math SEO < 1.0.119.1 - Contributor+ Stored XSS | — | wpscan |
| CVE-2023-32243 | < 5.7.2 |
LOW | N/A | Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation | — | wpscan |
| CVE-2023-3133 | < 2.2.1 |
LOW | N/A | Tutor LMS < 2.2.1 - Unauthenticated Access to Tutor LMS Lesson Resources via REST API | — | wpscan |
| CVE-2023-3129 | < 1.7.0 |
LOW | N/A | URL Shortify < 1.7.0 - Admin+ Cross Site Scripting | — | wpscan |
| CVE-2023-30777 | < 6.1.6 |
LOW | N/A | Advanced Custom Fields < 6.1.6 - Reflected XSS | — | wpscan |
| CVE-2023-30500 | < 1.8.1.3 |
LOW | N/A | Contact Form by WPForms < 1.8.1.3 - Reflected XSS | — | wpscan |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →