Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 272 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 39f12ff1-63ee-4131-a708-49633f22ccd4 | HIGH | 8.0 | The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat… | — | wordfence | |
| 34d09086-be33-40cf-b5bf-d6c03cf0b68a | < 6.0.10 |
HIGH | 8.0 | The Essential Addons for Elementor β Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for … | — | wordfence |
| 2f0e19bc-cc1f-4804-ae81-8aa7905ce037 | < 1.0.14 |
HIGH | 8.0 | The Sign-up Sheets WordPress plugin before 1.0.14 does not not sanitise or validate the Sheet title when generating the … | — | wordfence |
| 24d14261-e295-4397-bad0-7a4b69b06908 | < 2.0 |
HIGH | 8.0 | The TablePress plugin for WordPress is vulnerable to CSV Injection in versions up to and including 1.14 via the tablepre… | — | wordfence |
| 1edc84fd-8cb5-4899-9444-1b6ae3144917 | < 2.8.5 |
HIGH | 8.0 | The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth imp… | — | wordfence |
| 1c23d163-1053-403f-80bc-ea8f76fff4e2 | < 4.6.0.4 |
HIGH | 8.0 | A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requ… | — | wordfence |
| 0248f829-84de-40b9-bb63-354fbf06472d | < 3.7.39 |
HIGH | 8.0 | WordPress Core, in versions up to 6.0.2, is vulnerable to SQL Injection that can be exploited by authenticated users via… | — | wordfence |
| de476d40-47eb-417f-927f-d80d32745965 | < 2.72 |
HIGH | 7.8 | The WP-DBManager (aka Database Manager) plugin before 2.72 for WordPress allows remote authenticated users to execute ar… | — | wordfence |
| 92bd8f53-7845-4741-84e7-4930dfa973ea | < 1.5.5 |
HIGH | 7.8 | The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection. | — | wordfence |
| 7317d716-39e0-40d6-92a8-e59bd8470e5d | < 1.12.22 |
HIGH | 7.8 | The WebDorado "Form Maker by WD" plugin before 1.12.22 for WordPress allows CSV injection. | — | wordfence |
| 57d0991b-f10e-4ab8-a8a2-55bf708eefee | < 6.0.8.1 |
HIGH | 7.8 | The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting ma… | — | wordfence |
| 546976ff-eabe-4d24-b106-b8e66b7c2c5a | HIGH | 7.8 | The Social Photo Gallery plugin 1.0 for WordPress allows Remote Code Execution by creating an album and attaching a mali… | — | wordfence | |
| 361315ff-99ef-4fb2-946f-8ccc307bd3be | < 1.0.5 |
HIGH | 7.8 | In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/i… | — | wordfence |
| 25b26369-76e3-44f0-8275-03fc6fc9705c | < 1.3.35 |
HIGH | 7.8 | The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or … | — | wordfence |
| fbf25275-eb33-4581-8602-e8a64ba78692 | < 1.9.10 |
HIGH | 7.7 | The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the… | — | wordfence |
| e46ff294-0be1-47c1-8c21-f6242c6f832a | < 1.15.0.1 |
HIGH | 7.7 | The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Data Exposure in version 1.15 … | — | wordfence |
| e414a36f-7212-47b9-8e7f-6bf0ae6518af | < 6.4.2 |
HIGH | 7.7 | The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_r… | — | wordfence |
| e33fcd17-318b-408e-86bf-b4ece46121cc | < 5.0.17 |
HIGH | 7.7 | The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Upd… | — | wordfence |
| d357f92a-3c20-4972-af4d-65053027d31c | < 3.7.21 |
HIGH | 7.7 | In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF. | — | wordfence |
| CVE-2026-2592 | < 5.0.16. |
HIGH | 7.7 | The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Upd… | — | nvd |
| c25412d4-f24c-4e29-9b1f-fa89b0383f64 | < 6.5.9 |
HIGH | 7.7 | The FS Poster - WordPress Social media Auto Poster & Scheduler plugin for WordPress is vulnerable to SQL Injection in al… | — | wordfence |
| a2a4b5bb-d3c9-42e0-8714-ae75069c7c3a | < 2.2.3 |
HIGH | 7.7 | Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versio… | — | wordfence |
| 9bcdcaa4-c492-4d79-8d18-44802abd02e7 | < 7.28 |
HIGH | 7.7 | The WP Import β Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of d… | — | wordfence |
| 7d61b06b-6709-4f60-8324-53775dbb3c04 | < 3.7.28 |
HIGH | 7.7 | In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deletin… | — | wordfence |
| 68fee8cb-476d-4962-b830-59fd823329ac | < 1.9.10.58 |
HIGH | 7.7 | The Better Messages plugin for WordPress is vulnerable to Resource Exhaustion in versions up to, and including, 1.9.10.5… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →