Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 183 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4a6e5f89-ebc0-413a-a76e-3cf4339430ba | HIGH | 8.8 | The TerraClassifieds plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence | |
| 4a64f840-8570-4f98-8b72-27bee1607fc2 | HIGH | 8.8 | The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5… | — | wordfence | |
| 4a56a838-5dfa-477a-92b2-fdac3d1ab2af | < 1.1.7 |
HIGH | 8.8 | The Currency Switcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence |
| 4a4f0909-76f6-4d27-87b1-f6cd5f5cbbb7 | HIGH | 8.8 | The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.… | — | wordfence | |
| 4a4c085a-1601-4c1a-ac17-0f2cf5d02489 | < 1.4.3 |
HIGH | 8.8 | The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers… | — | wordfence |
| 4a40ddbc-0b9a-40bd-bf68-9e63723acb1c | < 1.1.8 |
HIGH | 8.8 | The XT Event Widget for Social Events plugin for WordPress is vulnerable to Local File Inclusion via the render_facebook… | — | wordfence |
| 4a2ca2f0-1d4a-4614-86ba-a46e765f4a9f | < 1.7.6 |
HIGH | 8.8 | The ImageMagick Engine plugin for WordPress is vulnerable to deserialization of untrusted input via the 'cli_path' param… | — | wordfence |
| 4a249c93-c029-44c1-8563-8adf1e2e3062 | < 1.11.13 |
HIGH | 8.8 | The immonex Kickstart plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.11.… | — | wordfence |
| 49eaee21-15c0-4c43-857d-05f0993509ea | < 1.1.1 |
HIGH | 8.8 | The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, an… | — | wordfence |
| 49b296a5-8721-4835-b2c1-ab45045be595 | < 2.3.6 |
HIGH | 8.8 | The animate-it plugin before 2.3.6 for WordPress has CSRF in edsanimate.php. | — | wordfence |
| 499059b9-44c0-40da-bc45-5280ea84f016 | < 6.5.2 |
HIGH | 8.8 | The WP Travel Engine plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.5.1.… | — | wordfence |
| 49754f41-b809-4a97-ab8f-233f51dc058f | < 1.5.64 |
HIGH | 8.8 | The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via ajax actions, by exploiting following WP ajax a… | — | wordfence |
| 49209249-11c7-4839-9fa4-423f09008bdc | < 8.5.27 |
HIGH | 8.8 | The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to arbitrary f… | — | wordfence |
| 4915b769-9499-40ac-835e-279e3a910558 | < 3.19.1 |
HIGH | 8.8 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to arbitrary file del… | — | wordfence |
| 48f5aba0-42a0-4b63-8195-29103576a794 | HIGH | 8.8 | The RS-Members plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.3. T… | — | wordfence | |
| 48c6efc9-6c53-4ac9-8f99-62fbab0599ce | < 3.0.330 |
HIGH | 8.8 | The Gallery Bank – WordPress Photo Gallery plugin for WordPress is vulnerable to blind SQL Injection via the ‘delete… | — | wordfence |
| 4891fd3f-563b-497a-a5d9-617f4862298b | < 1.8.7 |
HIGH | 8.8 | The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_… | — | wordfence |
| 488970f0-3120-4f4a-9915-2ae1708bd86a | < 3.6.10 |
HIGH | 8.8 | The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cros… | — | wordfence |
| 487d4175-97bf-4c65-9d7d-b83974e9fda9 | < 5.3.0 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote at… | — | wordfence |
| 486fa1a6-aa47-4bf9-b1da-582e316f6bcb | < 26.5 |
HIGH | 8.8 | The Woocommerce Customers Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability… | — | wordfence |
| 48658b33-ae53-4919-8180-1188f72553f7 | < 1.0.16 |
HIGH | 8.8 | The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both t… | — | wordfence |
| 482bae65-5493-4de5-9d5f-479d0968cd4a | HIGH | 8.8 | The Launchapd plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.13.… | — | wordfence | |
| 4824be4c-eec0-4979-85e1-6c692b3a8243 | < 2.0.4 |
HIGH | 8.8 | The Post/Page Copying Tool to Export and Import post/page for Cross site Migration plugin for WordPress is vulnerable t… | — | wordfence |
| 48069ad5-0779-444b-8215-d1f08b493108 | < 9.1 |
HIGH | 8.8 | The SEO Redirection Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| 47fb0513-bebe-4e09-9402-d7e174ee92ce | < 2.0.66 |
HIGH | 8.8 | The NextGen Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →