Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 217 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ac45d8fe-4b79-4b2c-998e-e51da7a37e40 | < 2.0.25 |
HIGH | 8.3 | The Custom Community theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘settings[custom_css]’… | — | wordfence |
| aa735320-f7fe-4e51-9f9a-f4c8f3ddc2e7 | < 3.3.14 |
HIGH | 8.3 | The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cros… | — | wordfence |
| 9e6a1af3-d53c-4e23-95d2-3b799bc10827 | < 4.3.13 |
HIGH | 8.3 | The Contact Form Plugin by FluentForm plugin for WordPress is vulnerable to CSV Injection in versions up to, and includi… | — | wordfence |
| 9132a605-7bed-4741-83f9-dfe8cbaf36cd | < 2.9.5 |
HIGH | 8.3 | The ListingPro Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2… | — | wordfence |
| 904e407c-5ec7-433f-9161-eb4d6d263a97 | < 2.0.1 |
HIGH | 8.3 | The Canto plugin 2.1.1 for WordPress allows includes/lib/download.php?subdomain= SSRF. | — | wordfence |
| 900fcaab-2424-4ae8-af18-95659db0dbe3 | < 2.05.03 |
HIGH | 8.3 | The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters su… | — | wordfence |
| 8a3da2af-2273-44ff-addd-1ac8a75e1c3d | HIGH | 8.3 | The All in One Social Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and incl… | — | wordfence | |
| 83bd221e-7d01-4cba-8577-ce0a69e4a75c | HIGH | 8.3 | The WPsc MijnPress plugin for WordPress is vulnerable to Cross-Site Scripting via the 'rwflush' parameter in versions up… | — | wordfence | |
| 80e85c7e-41e5-4b21-aa99-aa2097dfc4a9 | < 1.4 |
HIGH | 8.3 | Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an … | — | wordfence |
| 7b035d17-303b-4a8b-a15e-615df6b605d1 | < 3.3.0 |
HIGH | 8.3 | The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in… | — | wordfence |
| 78fedd41-f0ab-4148-a798-88de62f27008 | < 2.1.79 |
HIGH | 8.3 | The NextGen Gallery plugin for WordPress is vulnerable to SQL Injection via the ‘$container_ids’ string in versions … | — | wordfence |
| 6c3032ae-eb86-47d0-b160-320a67a380e1 | < 1.2.9 |
HIGH | 8.3 | The WooCommerce Reviews Plugin with Multi-criteria Rating by ReviewX plugin for WordPress is vulnerable to Cross-Site Re… | — | wordfence |
| 69ec31f3-8ec8-40ad-ba7f-77f9132ad51f | < 3.0.8 |
HIGH | 8.3 | The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Server-S… | — | wordfence |
| 6368c397-0570-4304-a764-869bacc526c7 | < 2.25.2 |
HIGH | 8.3 | The GiveWP plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.25.1 via the 'print_c… | — | wordfence |
| 6299876c-9db4-4f8d-897d-9a013a67238c | < 1.8.1 |
HIGH | 8.3 | The Register IPs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ip_address’ parameter th… | — | wordfence |
| 5f7014fc-a502-4f72-899f-c21d3ca5e5b3 | < 3.6.4 |
HIGH | 8.3 | The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘license’ parameter i… | — | wordfence |
| 5aacabb5-94af-485a-af24-e84db3e3726f | < 1.0.1 |
HIGH | 8.3 | The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and … | — | wordfence |
| 57caddaa-c548-4f07-ab34-327df62951b5 | < 1.7.5.9 |
HIGH | 8.3 | The Zoho CRM Lead Magnet plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on… | — | wordfence |
| 5781420d-b1e0-435f-8bf2-193cc7b095ed | < 2.0.1 |
HIGH | 8.3 | The Canto plugin 1.9.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make… | — | wordfence |
| 5574f8ab-74b7-4f6c-b8db-901cb6e45cfb | < 1.2.2 |
HIGH | 8.3 | A stored Cross-Site Scripting (XSS) vulnerability in the TC Custom JavaScript plugin before 1.2.2 for WordPress allows u… | — | wordfence |
| 5494cac6-1b52-43a3-995d-fc2a150edfdb | < 4.15 |
HIGH | 8.3 | The Reviews and Rating – Google My Business plugin for WordPress is vulnerable to authorization bypass due to missing … | — | wordfence |
| 5097da41-b5e9-4e07-a135-83a7d889fe9b | < 2.5.13 |
HIGH | 8.3 | The bbPress plugin for WordPress is vulnerable to blind SQL Injection via the ‘anonymous_data’ parameter in versions… | — | wordfence |
| 506e4f47-e292-4d19-a7bb-b87d752f4007 | < 2.8.4 |
HIGH | 8.3 | The Activity Log plugins for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.8.3. This allo… | — | wordfence |
| 5017c81f-91ee-421b-96db-c96eae56d032 | < 2.0.22 |
HIGH | 8.3 | The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Remote Code Execution in all versions u… | — | wordfence |
| 4fd6fa4f-8f4d-4d2f-ac67-98124cfa9592 | < 3.24.0 |
HIGH | 8.3 | The Thrive Theme Builder theme for WordPress is vulnerable to unauthorized use of functionality due to missing capabilit… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →