Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 199 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 23b5cc65-70d2-46b1-a37a-97af231aff51 | < 1.2.5 |
HIGH | 8.8 | The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment. | — | wordfence |
| 23a73680-ed13-4250-95e8-2933403f54e6 | HIGH | 8.8 | The Eazy Plugin Manager β Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Priv… | — | wordfence | |
| 23a20e57-0228-4e37-a105-e693c05a0a24 | < 1.6.0 |
HIGH | 8.8 | The Creative Mail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5… | — | wordfence |
| 23a1128f-b8a1-4dec-adf4-43fb96806b60 | < 2.9.3 |
HIGH | 8.8 | The Yogi - Health Beauty & Yoga WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all version… | — | wordfence |
| 235b197f-030e-4da2-8edf-e263fab6df14 | < 0.3.2 |
HIGH | 8.8 | The ExS Widgets plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.3.1. … | — | wordfence |
| 2331a587-b731-43d9-b813-9f08efc60bfc | < 5.5.21 |
HIGH | 8.8 | The GetResponse plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.5.1… | — | wordfence |
| 232f3a15-3bd3-44fa-aa07-f055e8fcda88 | < 1.7.8 |
HIGH | 8.8 | The Better Find and Replace β AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in a… | — | wordfence |
| 232a274f-c194-4c5b-a1a8-899a822e47fc | < 4.7.6 |
HIGH | 8.8 | The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import cla… | — | wordfence |
| 2318b3e1-268d-45fa-83bf-c6e88f1b9013 | < 4.6.0.1 |
HIGH | 8.8 | The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and includi… | — | wordfence |
| 22fa8290-ebab-4fa4-bcba-0053c3b79f76 | HIGH | 8.8 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Cross-Site Reques… | — | wordfence | |
| 22f79a03-9195-4d5d-a189-9b5e1d3307c8 | < 1.2.5.4 |
HIGH | 8.8 | The Contact Form 7 Database Addon plugin for WordPress is vulnerable to SQL Injection in versions up to, and including 1… | — | wordfence |
| 22d5a45b-41bd-4f65-b8b7-d7efb2b9cecf | HIGH | 8.8 | The External featured image from bing plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,… | — | wordfence | |
| 22d58028-a12c-4d72-b275-ba37a58dc10d | HIGH | 8.8 | The Dashicons + Custom Post Types plugin for WordPress is vulnerable to authorization bypass due to a missing capability… | — | wordfence | |
| 22b63369-c6ea-42e9-bea3-d15837da7732 | < 1.2.6 |
HIGH | 8.8 | The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path… | — | wordfence |
| 229c146d-3f99-4f63-9a6f-997075846815 | HIGH | 8.8 | The Postem Ipsum plugin for WordPress is vulnerable to unauthorized modification of data to Privilege Escalation due to … | — | wordfence | |
| 229235de-03c6-4560-b0ea-ab21fde256be | HIGH | 8.8 | The HTML5 SoundCloud Player with Playlist Free plugin for WordPress is vulnerable to PHP Object Injection in all version… | — | wordfence | |
| 228147c2-97c6-4910-b9b2-d6ca62fc1760 | < 3.2.49 |
HIGH | 8.8 | The Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| 22755d65-d187-438a-9a3f-e7d38497282b | < 4.1.2 |
HIGH | 8.8 | The MainWP Maintenance Extension for WordPress are vulnerable to SQL Injection via an unknown parameter due to insuffici… | — | wordfence |
| 22713937-d834-46cf-83ec-6f9f61b548e3 | < 1.6 |
HIGH | 8.8 | The Conditional Marketing Mailer for WooCommerce Plugin for WordPress is vulnerable to Cross-Site Request Forgery in ver… | — | wordfence |
| 225ea5b3-08a9-40c2-a755-7783475946c4 | HIGH | 8.8 | The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… | — | wordfence | |
| 225123aa-1ef9-4431-b4b1-b5ac5e034ef4 | HIGH | 8.8 | The Simple Quotation WordPress plugin through 1.3.2 does not have authorisation (and CSRF) checks in various of its AJAX… | — | wordfence | |
| 2238c9ba-6d00-4a21-a050-7b8a5f307964 | < 1.0.14 |
HIGH | 8.8 | The WordPress Facebook plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in versi… | — | wordfence |
| 222db62c-8ffc-4b79-8f04-101caf82186d | < 1.3.0 |
HIGH | 8.8 | The case-addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … | — | wordfence |
| 2224b17e-e327-4b86-85db-ad878f989839 | < 1.5 |
HIGH | 8.8 | The QAEngine theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.4 via the 'cl… | — | wordfence |
| 220055ff-683c-47a4-8817-b3e70bb9dc81 | < 1.3.3 |
HIGH | 8.8 | The Adapta RGPD plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →