Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 198 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2547ec16-76c8-4cc2-b10b-d321324d9363 | HIGH | 8.8 | The Celestial Aura theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in al… | — | wordfence | |
| 250202d5-3a0d-494c-8386-1f4cd015ad7e | < 9.2.0 |
HIGH | 8.8 | The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege es… | — | wordfence |
| 24f23230-7012-48c0-85e7-71518340cf95 | < 1.3.1 |
HIGH | 8.8 | The Consulting Elementor Widgets plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i… | — | wordfence |
| 24e00c0d-08ff-4c68-a1dd-77b513545efd | < 5.3.15 |
HIGH | 8.8 | The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence |
| 24b4eace-7672-4dae-9c0c-bbd1d79765a9 | < 2.2.3 |
HIGH | 8.8 | The WPAdverts plugin for WordPress is vulnerable to Local File Inclusion via several render() functions in versions up t… | — | wordfence |
| 24aa005f-30c2-4708-bbbe-8eece2cd19cc | < 24.0.1 |
HIGH | 8.8 | The WPSolr plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 24.0. This… | — | wordfence |
| 249ccc77-0daf-41bc-b5c5-991bf17d645d | < 2.10.18 |
HIGH | 8.8 | The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and in… | — | wordfence |
| 249ac834-e7de-42cc-9ac1-82e7c18eac31 | < 3.2.8.1 |
HIGH | 8.8 | The wp-members plugin before 3.2.8.1 for WordPress has CSRF. | — | wordfence |
| 24889552-0db6-44e6-9b12-f31b5e92a42e | HIGH | 8.8 | The JobCareer | Job Board Responsive WordPress Theme theme for WordPress is vulnerable to unauthorized access, modificat… | — | wordfence | |
| 2483875a-84de-4a40-a69e-aee68da1ce3b | HIGH | 8.8 | The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and … | — | wordfence | |
| 2471d06b-7d9a-41b9-b38c-3f40322d8a5b | < 1.5.4 |
HIGH | 8.8 | The Bricks theme for WordPress is vulnerable to remote code execution due to the theme allowing site editors to include … | — | wordfence |
| 24697253-62b9-45ff-8427-ee437e0d271f | < 2.9.4 |
HIGH | 8.8 | The Product XML Feed Manager for WooCommerce β Google Shopping, Social Sites, Skroutz & More plugin for WordPress is v… | — | wordfence |
| 24666f75-9179-4043-841b-4dd83be078e8 | < 5.0.3 |
HIGH | 8.8 | The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This i… | — | wordfence |
| 2460e7c4-76dc-4bc3-bc06-b52df64f5353 | HIGH | 8.8 | The Mementor Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.5… | — | wordfence | |
| 245fade9-ecbb-4d41-ae2a-07331f6c25ba | HIGH | 8.8 | The Service plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.4 due to insuffici… | — | wordfence | |
| 245f8eec-d496-4298-800d-ea1120640e2d | < 2.5 |
HIGH | 8.8 | The Captchinoo, admin login page protection with Google recaptcha plugin for WordPress is vulnerable to Cross-Site Reque… | — | wordfence |
| 245e43e0-3391-486d-9ecf-3e745bceaa1f | < 2.5 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in Personalized WooCommerce Cart Page 2.4 and earlier allows remote atta… | — | wordfence |
| 244f087a-ddc6-4f48-812d-3fed9e1536a0 | < 3.3.2.1 |
HIGH | 8.8 | The Mixed Media Gallery Blocks plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and in… | — | wordfence |
| 241d7a82-5fa5-40e3-9336-823644ca17f0 | < 2.8.6 |
HIGH | 8.8 | The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… | — | wordfence |
| 24123a4f-da33-4d50-9e82-18f910de6619 | < 1.1.8 |
HIGH | 8.8 | The get_portfolios() and get_portfolio_attributes() functions in the class-portfolio-responsive-gallery-list-table.php a… | — | wordfence |
| 241073e4-b8f2-4dd3-ad66-6dda8c61b42c | < 4.0 |
HIGH | 8.8 | Multiple cross-site request forgery (CSRF) vulnerabilities in the AB Google Map Travel (AB-MAP) plugin before 4.0 for Wo… | — | wordfence |
| 23f0315f-5523-4e16-8adf-f9fe9254032a | < 6.2 |
HIGH | 8.8 | The Super Store Finder, Super Interactive Maps, and Super Logo Showcase plugins for WordPress are vulnerable to arbitrar… | — | wordfence |
| 23d8c56b-01f1-48b4-a58d-958457be738f | < 1.1.4 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the SEO Plugin LiveOptim plugin before 1.1.4-free for WordPress allow… | — | wordfence |
| 23bfcdd1-b99d-47eb-9f88-96f9ecc53b32 | < 5.7.20 |
HIGH | 8.8 | The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to unauthorized access of data, modification… | — | wordfence |
| 23b6e418-5560-4543-9042-5f338df315e5 | < 2.1.13 |
HIGH | 8.8 | The ShopBuilder β Elementor WooCommerce Builder Addons plugin for WordPress is vulnerable to Local File Inclusion in a… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →