Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 214 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| e6d40b41-540d-476d-afde-970845543933 | < 7.8.4 |
HIGH | 8.6 | The Hustle β Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Informat… | — | wordfence |
| e005861c-3ca5-4cee-a84b-9ebc095f4a1f | < 1.8.6 |
HIGH | 8.6 | WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot … | — | wordfence |
| cf326914-6a38-4984-a2a7-66e05f41a96b | < 3.3.3 |
HIGH | 8.6 | The ShopLentor β WooCommerce Builder for Elementor & Gutenberg +21 Modules β All in One Solution plugin for WordPres… | — | wordfence |
| c9955d65-afb3-4d28-abd2-9f2fec92d013 | < 2.5.7 |
HIGH | 8.6 | The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the… | — | wordfence |
| c694f5e5-43eb-453c-98d7-0d575d53df1a | < 2.10.36 |
HIGH | 8.6 | CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPr… | — | wordfence |
| bb1742fd-7f0c-4a14-aa9c-f2863fcccd17 | < 8.0.0 |
HIGH | 8.6 | The Revive Old Posts β Social Media Auto Post and Scheduling Plugin for WordPress is vulnerable to Authorization Bypas… | — | wordfence |
| b988a8bb-0def-4469-8f97-d329967cb11b | HIGH | 8.6 | The FAT Services Booking plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 5.6 d… | — | wordfence | |
| b71e6219-09cc-484e-8c48-536797d974ce | < 3.3.4 |
HIGH | 8.6 | The WordPress WP-Advanced-Search plugin for WordPress is vulnerable to unauthenticated database export in versions up to… | — | wordfence |
| b5b5d36d-02de-4569-b2cf-addc122ebe34 | < 1.5.1 |
HIGH | 8.6 | Directory traversal vulnerability in download.php in the Zip Attachments plugin before 1.5.1 for WordPress allows remote… | — | wordfence |
| b2fe5315-37b7-4009-b2e5-909e6b5ed1da | HIGH | 8.6 | The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when incl… | — | wordfence | |
| b09c6da0-14d8-4e44-95bd-b5b6b0df97e9 | < 0.9.5 |
HIGH | 8.6 | The W3 Total Cache plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 0… | — | wordfence |
| afd9046c-5b6a-411e-8e66-ff1ba60d7f9d | < 4.0.26 |
HIGH | 8.6 | The MultiVendorX plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of da… | — | wordfence |
| a438d058-ccca-4a36-a2e6-40c2b33f2389 | HIGH | 8.6 | The Product Catalog β Catalog for WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to,… | — | wordfence | |
| 92644676-add4-415c-9a1a-c6616108688d | < 2.1.2 |
HIGH | 8.6 | The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and incl… | — | wordfence |
| 89f6f1cd-91ab-416b-b76b-162b3b29d752 | < 2.7.2 |
HIGH | 8.6 | The JS Help Desk plugin for WordPress is vulnerable to generic SQL Injection via an unknown parameter in versions up to,… | — | wordfence |
| 88d27385-9b92-419c-9e03-687d7192bbb5 | HIGH | 8.6 | The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check wh… | — | wordfence | |
| 7fc72cff-b708-4fa2-a734-481446641a61 | HIGH | 8.6 | The Export Users to CSV plugin through 1.1.1 for WordPress allows CSV injection. | — | wordfence | |
| 77db827d-9afd-4b59-b0ad-1ad562634c52 | < 2.14.0 |
HIGH | 8.6 | The MoneySpace plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including… | — | wordfence |
| 62687f24-4be2-49de-9a7d-265325b0f72b | HIGH | 8.6 | The Dewplayer plugin <= 1.2 and Advanced Dewplayer plugin < 1.5 for WordPress are vulnerable to Content Spoofing/Injecti… | — | wordfence | |
| 5782439f-a546-45f6-aec7-e600442d3c41 | < 1.2.8 |
HIGH | 8.6 | The AnyWhere Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and inclu… | — | wordfence |
| 577de987-b526-4d7a-8163-683ec3b77bec | < 2.9.5 |
HIGH | 8.6 | The ListingPro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.4 due to insuff… | — | wordfence |
| 53bffb82-b9df-40a0-947b-ecae512f363a | < 1.4.8 |
HIGH | 8.6 | WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry. | — | wordfence |
| 4e835b97-c066-4e8f-b99f-1a930105af0c | < 5.7.10 |
HIGH | 8.6 | The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modificat… | — | wordfence |
| 44158748-798e-4b17-9deb-f54520779c62 | < 3.3.14 |
HIGH | 8.6 | The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection. | — | wordfence |
| 3a47cdeb-bd05-4e7e-99dc-dca67064182a | < 1.9.31 |
HIGH | 8.6 | The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and includi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →