Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1620 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2019-9168 | < 3.5.5 |
LOW | N/A | WooCommerce <= 3.5.4 - Stored Cross-Site Scripting (XSS) | — | wpscan |
| CVE-2019-25314 | < 3.2.4 |
LOW | N/A | Duplicate Post < 3.2.4 - Admin+ Stored XSS | — | wpscan |
| CVE-2019-16520 | < 3.2.7 |
LOW | N/A | All In One SEO Pack < 3.2.7 - Stored Cross-Site Scripting (XSS) | — | wpscan |
| CVE-2019-15889 | < 2.9.94 |
LOW | N/A | Download Manager <= 2.9.93 - Authenticated Cross-Site Scripting (XSS) | — | wpscan |
| CVE-2019-15827 | < 1.17.8 |
LOW | N/A | OneSignal Web Push Notifications - Stored XSS | — | wpscan |
| CVE-2019-15109 | < 4.8.2 |
LOW | N/A | The Events Calendar < 4.8.2 - XSS | — | wpscan |
| CVE-2019-15025 | < 3.3.21.2 |
LOW | N/A | Ninja Forms < 3.3.21.2 - SQL Injection | — | wpscan |
| CVE-2019-14786 | < 1.0.27.1 |
LOW | N/A | Seo By Rank Math <= 1.0.27 - Authenticated Settings Reset | — | wpscan |
| CVE-2019-14328 | < 3.8.5 |
LOW | N/A | Simple Membership <= 3.8.4 - Cross-Site Request Forgery (CSRF) | — | wpscan |
| CVE-2019-13478 | < 11.6 |
LOW | N/A | Yoast SEO 1.2.0-11.5 - Admin+ Stored XSS | — | wpscan |
| CVE-2018-7280 | < 3.2.14 |
LOW | N/A | Ninja Forms <= 3.2.13 - Cross-Site Scripting (XSS) | — | wpscan |
| CVE-2018-20986 | < 5.7.8 |
LOW | N/A | Advanced Custom Fields <= 5.7.7 - Authenticated Cross-Site Scripting (XSS) | — | wpscan |
| CVE-2018-20981 | < 3.3.9 |
LOW | N/A | Ninja Forms < 3.3.9 - Insufficient Restrictions during Export Personal Data requests | — | wpscan |
| CVE-2018-20980 | < 3.2.15 |
LOW | N/A | Ninja Forms < 3.2.15 - Parameter Tampering | — | wpscan |
| CVE-2018-20979 | < 5.0.4 |
LOW | N/A | Contact Form 7 <= 5.0.3 - register_post_type() Privilege Escalation | — | wpscan |
| CVE-2018-20714 | < 3.4.6 |
LOW | N/A | WooCommerce <= 3.4.5 - Authenticated File Deletion to Privilege Escalation | — | wpscan |
| CVE-2018-19796 | < 3.3.19.1 |
LOW | N/A | Ninja Forms <= 3.3.19 - Authenticated Open Redirect | — | wpscan |
| CVE-2018-19370 | < 9.2 |
LOW | N/A | Yoast SEO <= 9.1 - Authenticated Race Condition | — | wpscan |
| CVE-2018-19287 | < 3.3.18 |
LOW | N/A | Ninja Forms <= 3.3.17 - Unauthenticated Cross-Site Scripting (XSS) | — | wpscan |
| CVE-2018-16966 | < 3.1 |
LOW | N/A | File Manager < 3.1 - CSRF to Stored Cross-Site Scripting | — | wpscan |
| CVE-2018-16363 | < 3.0 |
LOW | N/A | File Manager < 3.0 - Authenticated Reflected Cross-Site Scripting (XSS) | — | wpscan |
| CVE-2018-16308 | < 3.3.14 |
LOW | N/A | Ninja Forms <= 3.3.13 - CSV Injection | — | wpscan |
| CVE-2018-11366 | < 1.4.0 |
LOW | N/A | Loginizer 1.3.8-1.3.9 - Unauthenticated Stored Cross-Site Scripting (XSS) | — | wpscan |
| CVE-2017-2217 | < 2.9.51 |
LOW | N/A | Download Manager <= 2.9.50 - Open Redirect | — | wpscan |
| CVE-2017-2216 | < 2.9.50 |
LOW | N/A | Download Manager <= 2.9.49 - Cross-Site Scripting (XSS) | — | wpscan |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →