Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 218 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4b5d1190-3c1e-4cb8-b64b-894ffb1b1f38 | < 1.6.2 |
HIGH | 8.3 | The Better Find and Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includ… | — | wordfence |
| 4a330416-f867-4a1a-a692-6003e231ed54 | < 2.0.1 |
HIGH | 8.3 | The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a… | — | wordfence |
| 432807d0-64d8-49b1-a4ab-33aa8fbc5189 | HIGH | 8.3 | The Form Builder plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.9.9.0. This all… | — | wordfence | |
| 42b24b41-c520-4bb8-ba56-6f35500ee90e | < 1.9.25 |
HIGH | 8.3 | The FooGallery plugin for WordPress is vulnerable to Cross-Site Scripting via the image title and caption parameters in … | — | wordfence |
| 40b57370-4fd7-4316-9e99-a3f1d34616e8 | < 1.9.2 |
HIGH | 8.3 | The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, … | — | wordfence |
| 3c43939f-c0c7-4388-80ae-44bdf67675c7 | < 3.11.4 |
HIGH | 8.3 | The WP eCommerce plugin for WordPress is vulnerable to SQL Injection via the ‘sessionid’ parameter in versions up to… | — | wordfence |
| 3b806e11-57ad-4976-9ece-419ad6581cc4 | < 4.5.9 |
HIGH | 8.3 | The Nelio AB Testing plugin for WordPress is vulnerable to Server Side Request Forgery in versions up to, and including,… | — | wordfence |
| 326618eb-186b-44a2-a779-00d5366bfff2 | < 3.0.19 |
HIGH | 8.3 | The Essential Grid plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capabilit… | — | wordfence |
| 2dce9e9a-a2f3-49a9-a6bc-00328632c654 | < 6.7.7 |
HIGH | 8.3 | The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up … | — | wordfence |
| 2d2380af-2ba7-4f6b-a055-52f400042be4 | < 2.0.11 |
HIGH | 8.3 | The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to Open Redire… | — | wordfence |
| 28e723ee-e99a-4ec4-b492-bfba04d27fd0 | < 0.9.91 |
HIGH | 8.3 | The WPvivid Backup Plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a m… | — | wordfence |
| 26f431e9-74e0-4920-8766-bf9703e620ee | HIGH | 8.3 | The WP Video Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… | — | wordfence | |
| 25f782c4-7ece-47cb-9e64-9c93fd8858e9 | < 1.0.3 |
HIGH | 8.3 | The WordPress fancybox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hyperlink’ paramet… | — | wordfence |
| 247e599a-74e2-41d5-a1ba-978a807e6544 | < 1.1.5 |
HIGH | 8.3 | The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to,… | — | wordfence |
| 1dccb69e-b3d8-44b5-8f5e-931e5afe2bd1 | < 3.3.5 |
HIGH | 8.3 | The JupiterX Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in version… | — | wordfence |
| 1cda31a4-4c79-4567-a527-6510c31d2843 | < 7.4.0 |
HIGH | 8.3 | The JS package webpack is vulnerable to Sandbox Bypass in versions up to, and including, 5.75.0 due to mishandling magic… | — | wordfence |
| 1c08b7a7-297b-4ad7-b829-3ccbae7b2e41 | < 1.1 |
HIGH | 8.3 | The wp-publications WordPress plugin is vulnerable to restrictive local file inclusion via the Q_FILE parameter found in… | — | wordfence |
| 0d8a8aa7-8344-4ca7-8194-9bc679d18661 | < 3.64.1 |
HIGH | 8.3 | An XSS vulnerability in the popup-builder plugin before 3.64.1 for WordPress allows remote attackers to inject arbitrary… | — | wordfence |
| 0a42449f-aef1-42b8-af58-4f4aab7008f3 | < 3.1 |
HIGH | 8.3 | The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retriev… | — | wordfence |
| 02665811-15ba-434c-a4d0-df5402a128f4 | < 2.10.0.130 |
HIGH | 8.3 | The Simple Ads Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.9.… | — | wordfence |
| 01f0f734-b22e-4cd6-be99-ce6c2cd6f2c9 | < 7.6 |
HIGH | 8.3 | The Indeed Membership Pro plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, … | — | wordfence |
| 01139cbd-1116-4cf8-bdcb-cb182588d093 | < 1.45 |
HIGH | 8.3 | The BlogVault WordPress Backup Plugin for WordPress is vulnerable to PHP Object Injection in versions 1.40 - 1.44 via de… | — | wordfence |
| 00187815-6706-4ec9-a566-4836de0d17c6 | < 4.3.1 |
HIGH | 8.3 | There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to b… | — | wordfence |
| f1e98579-6e23-4309-9db5-e47d1e77ab07 | < 2.0 |
HIGH | 8.2 | The File Download plugin for WordPress has an Open Proxy vulnerability via the 'path' parameter in versions up to, and i… | — | wordfence |
| eeef2a59-47a1-4d8d-b815-8c74cc608e6c | HIGH | 8.2 | The CommentLuv plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →