Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,549 vulnerabilities found (page 1621 of 1622)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| CVE-2017-18596 | < 1.8.0 |
LOW | N/A | Elementor Page Builder < 1.8.0 - Authenticated Unrestricted Editing | — | wpscan |
| CVE-2017-18593 | < 1.13.5 |
LOW | N/A | Updraftplus < 1.13.5 - XSS | — | wpscan |
| CVE-2017-18577 | < 4.1.8 |
LOW | N/A | Mailchimp For WP < 4.1.8 - XSS | — | wpscan |
| CVE-2017-18574 | < 3.0.31 |
LOW | N/A | Ninja Forms < 3.0.31 - XSS | — | wpscan |
| CVE-2017-18499 | < 3.5.7 |
LOW | N/A | Simple Membership < 3.5.7 - XSS | — | wpscan |
| CVE-2017-18356 | < 3.2.4 |
LOW | N/A | WooCommerce <= 3.2.3 - Authenticated PHP Object Injection | — | wpscan |
| CVE-2017-18032 | < 2.9.52 |
LOW | N/A | Download Manager <= 2.9.51 - Authenticated Reflected Cross-Site Scripting (XSS) | — | wpscan |
| CVE-2017-16842 | < 5.8 |
LOW | N/A | Yoast SEO < 5.8 - Authenticated Cross-Site Scripting (XSS) | — | wpscan |
| CVE-2017-12651 | < 1.3.6 |
LOW | N/A | Loginizer <= 1.3.5 - Cross-Site Request Forgery (CSRF) | — | wpscan |
| CVE-2017-12650 | < 1.3.6 |
LOW | N/A | Loginizer <= 1.3.5 - Blind SQL Injection | — | wpscan |
| CVE-2016-1209 | < 2.9.43 |
LOW | N/A | Ninja Forms 2.9.36 to 2.9.42 - Multiple Vulnerabilities | — | wpscan |
| CVE-2016-10888 | < 4.0.7 |
LOW | N/A | All In One WP Security And Firewall < 4.0.7 - Multiple SQL Injections | — | wpscan |
| CVE-2016-10887 | < 4.0.9 |
LOW | N/A | All In One WP Security And Firewall < 4.0.9 - Multiple SQL Injections | — | wpscan |
| CVE-2016-10884 | < 3.3.3 |
LOW | N/A | Simple Membership < 3.3.3 - Multiple CSRF | — | wpscan |
| CVE-2016-10871 | < 4.0.11 |
LOW | N/A | MailChimp for WordPress <= 4.0.10 - Authenticated Cross-Site Scripting (XSS) | — | wpscan |
| CVE-2016-10868 | < 4.0.5 |
LOW | N/A | All In One WP Security And Firewall < 4.0.5 - XSS | — | wpscan |
| CVE-2016-10867 | < 4.0.6 |
LOW | N/A | All In One WP Security And Firewall < 4.0.6 - XSS | — | wpscan |
| CVE-2016-10866 | < 4.2.0 |
LOW | N/A | All In One WP Security & Firewall 4.1.4-4.1.9 - Authenticated Cross-Site Scripting (XSS) | — | wpscan |
| CVE-2016-10706 | < 4.0.3 |
LOW | N/A | Jetpack 2.0-4.0.2 - Shortcode Stored Cross-Site Scripting (XSS) | — | wpscan |
| CVE-2016-10705 | < 4.0.4 |
LOW | N/A | Jetpack <= 4.0.3 - Multiple Vulnerabilities | — | wpscan |
| CVE-2016-10112 | < 2.6.9 |
LOW | N/A | WooCommerce <= 2.6.8 - Authenticated Tax-Rate CSV XSS | — | wpscan |
| CVE-2015-9360 | < 1.9.64 |
LOW | N/A | Updraftplus < 1.9.64 - XSS | — | wpscan |
| CVE-2015-9359 | < 3.4.3 |
LOW | N/A | Jetpack 3.0-3.4.2 - Cross-Site Scripting (XSS) | — | wpscan |
| CVE-2015-9357 | < 3.1.5 |
LOW | N/A | Akismet 2.5.0-3.1.4 - Unauthenticated Stored Cross-Site Scripting (XSS) | — | wpscan |
| CVE-2015-9310 | < 3.9.1 |
LOW | N/A | All In One WP Security & Firewall <= 3.9.0 - Blind SQL Injection | — | wpscan |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →