Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1618 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2021-24255 | < 4.5.4 |
LOW | N/A | Essential Addons for Elementor < 4.5.4 - Contributor+ Stored Cross-Site Scripting (XSS) | — | wpscan |
| CVE-2021-24242 | < 1.8.8 |
LOW | N/A | Tutor LMS < 1.8.8 - Authenticated Local File Inclusion | — | wpscan |
| CVE-2021-24216 | < 7.41 |
LOW | N/A | All-in-One WP Migration < 7.41 - Admin+ Arbitrary File Upload to RCE | — | wpscan |
| CVE-2021-24209 | < 1.7.2 |
LOW | N/A | WP Super Cache < 1.7.2 - Authenticated Remote Code Execution (RCE) | — | wpscan |
| CVE-2021-24206 | < 3.1.4 |
LOW | N/A | Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Image Box Widget | — | wpscan |
| CVE-2021-24205 | < 3.1.4 |
LOW | N/A | Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Icon Box Widget | — | wpscan |
| CVE-2021-24204 | < 3.1.4 |
LOW | N/A | Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Accordion Widget | — | wpscan |
| CVE-2021-24203 | < 3.1.4 |
LOW | N/A | Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Divider Widget | — | wpscan |
| CVE-2021-24202 | < 3.1.4 |
LOW | N/A | Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Heading Widget | — | wpscan |
| CVE-2021-24201 | < 3.1.4 |
LOW | N/A | Elementor < 3.1.4 - Authenticated Stored Cross-Site Scripting (XSS) in Column Element | — | wpscan |
| CVE-2021-24186 | < 1.8.3 |
LOW | N/A | Tutor LMS < 1.8.3 - SQL Injection via tutor_answering_quiz_question/get_answer_by_id | — | wpscan |
| CVE-2021-24185 | < 1.7.7 |
LOW | N/A | Tutor LMS < 1.7.7 - SQL Injection via tutor_place_rating | — | wpscan |
| CVE-2021-24184 | < 1.7.7 |
LOW | N/A | Tutor LMS < 1.7.7 - Unprotected AJAX including Privilege Escalation | — | wpscan |
| CVE-2021-24183 | < 1.8.3 |
LOW | N/A | Tutor LMS < 1.8.3 - SQL Injection via tutor_quiz_builder_get_question_form | — | wpscan |
| CVE-2021-24182 | < 1.8.3 |
LOW | N/A | Tutor LMS < 1.8.3 - SQL Injection via tutor_quiz_builder_get_answers_by_question | — | wpscan |
| CVE-2021-24181 | < 1.7.7 |
LOW | N/A | Tutor LMS < 1.7.7 - SQL Injection via tutor_mark_answer_as_correct | — | wpscan |
| CVE-2021-24177 | < 7.1 |
LOW | N/A | WP File Manager < 7.1 - Reflected Cross-Site Scripting (XSS) | — | wpscan |
| CVE-2021-24166 | < 3.4.34 |
LOW | N/A | Ninja Forms < 3.4.34 - CSRF to OAuth Service Disconnection | — | wpscan |
| CVE-2021-24165 | < 3.4.34 |
LOW | N/A | Ninja Forms < 3.4.34 - Administrator Open Redirect | — | wpscan |
| CVE-2021-24164 | < 3.4.34.1 |
LOW | N/A | Ninja Forms < 3.4.34.1 - Authenticated OAuth Connection Key Disclosure | — | wpscan |
| CVE-2021-24163 | < 3.4.34 |
LOW | N/A | Ninja Forms < 3.4.34 - Authenticated SendWP Plugin Installation and Client Secret Key Disclosure | — | wpscan |
| CVE-2021-24153 | < 3.4.1 |
LOW | N/A | Yoast SEO < 3.4.1 - Authenticated Stored Cross-Site Scripting (XSS) | — | wpscan |
| CVE-2021-20865 | < 5.11 |
LOW | N/A | Advanced Custom Fields < 5.11 - Subscriber+ Arbitrary ACF Data/Field Groups View and Fields Move | — | wpscan |
| CVE-2020-8934 | < 1.8.0 |
LOW | N/A | Site Kit by Google < 1.8.0 - Privilege Escalation to gain Search Console Access | — | wpscan |
| CVE-2020-8615 | < 1.5.3 |
LOW | N/A | Tutor LMS < 1.5.3 - Cross-Site Request Forgery (CSRF) | — | wpscan |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →