Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 184 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 47e53fd3-4e3f-433a-8e70-3a58c864184a | HIGH | 8.8 | The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and… | — | wordfence | |
| 47ccda70-8c89-4e0f-a7fa-5b80515e60dc | < 1.1 |
HIGH | 8.8 | The WOWRestro β Online Ordering System For WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forger… | — | wordfence |
| 47b75e7f-87d3-40d5-b3c4-998d3164d48a | < 2.6.0.0 |
HIGH | 8.8 | The SP Project & Document Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… | — | wordfence |
| 47a67db6-cc0d-47d2-a2c2-11b8c410f2fb | < 1.5.0 |
HIGH | 8.8 | The Designer plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.1. This ma… | — | wordfence |
| 473ba791-af99-4aae-99cb-ccf220e443e7 | < 5.5.2 |
HIGH | 8.8 | The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… | — | wordfence |
| 4729ed37-96b2-4717-8a72-89b9a21ec058 | < 1.24.12 |
HIGH | 8.8 | The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions… | — | wordfence |
| 471957f6-54c1-4268-b2e1-8efa391dcaec | < 3.2.50 |
HIGH | 8.8 | The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]… | — | wordfence |
| 46c40aed-1df9-4c20-9058-1ae62864fc9d | HIGH | 8.8 | The Advanced Booking Calendar for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence | |
| 46c0fa1e-f400-435c-b781-23919a192e89 | < 1.9.9.5 |
HIGH | 8.8 | The WPLMS plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 1.9.9.5 (exclusive). This ma… | — | wordfence |
| 469a702f-033a-40de-b725-b0ad4f8e92e8 | < 1.0.2 |
HIGH | 8.8 | The Ship To eCourier plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| 468fc0c3-288d-4d9c-a27a-68470f220c39 | HIGH | 8.8 | The Image Gallery Box by CRUDLab plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inclu… | — | wordfence | |
| 4681e56f-1dad-46a7-8ac7-1f543a383433 | < 1.0.16 |
HIGH | 8.8 | The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu… | — | wordfence |
| 4678d2a3-8f8d-488a-8d2b-6c321b96eb36 | HIGH | 8.8 | The WP Quick Setup plugin for WordPress is vulnerable to unauthorized plugin and theme installation due to a missing cap… | — | wordfence | |
| 4654609e-ed3e-4268-a9a4-80bc563e0a64 | < 3.2.49 |
HIGH | 8.8 | The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| 46226921-a445-4fb7-9c90-bd2d6841dec7 | HIGH | 8.8 | The Tracked Tweets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.… | — | wordfence | |
| 46039930-377e-4adb-8d96-09ebf220b4a6 | HIGH | 8.8 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Sliding Social Icons plugin 1.61 for WordPress allow r… | — | wordfence | |
| 45eda79d-f999-413e-88ce-b7d06f09f191 | HIGH | 8.8 | The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request F… | — | wordfence | |
| 45eac3e1-db31-4d3d-844f-ae106b9eee7a | < 1.1.5 |
HIGH | 8.8 | The MetalpriceAPI plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.1.… | — | wordfence |
| 45d7732f-cdcd-4cef-a01e-22e06566e8a1 | HIGH | 8.8 | The PowerFormBuilder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.6 due to … | — | wordfence | |
| 45a62dd0-386c-41b3-b8dd-ced443da9f92 | < 2.9.4 |
HIGH | 8.8 | The Page Builder: KingComposer plugin for WordPress is vulnerable to Arbitrary File Uploads in versions up to, and inclu… | — | wordfence |
| 45a42f20-a4d7-4c8e-a144-505a6723a2a0 | < 2.1.1 |
HIGH | 8.8 | The WP Datepicker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… | — | wordfence |
| 45816c45-42bc-4163-b700-a1e913f32c97 | < 3.6.6 |
HIGH | 8.8 | The AI Engine β The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request… | — | wordfence |
| 45668368-5846-41bb-b862-dfeb283e83cf | < 7.6.7 |
HIGH | 8.8 | The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to privi… | — | wordfence |
| 455b9695-e140-4bdb-b626-5c1695518563 | < 4.1.3 |
HIGH | 8.8 | The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File… | — | wordfence |
| 452e9acc-4029-4f43-9941-c1aa2a413e34 | HIGH | 8.8 | The Lean WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.0. Th… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →