Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 284 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d0abc8f9-7b6f-443d-a17f-8da034359c52 | < 3.7.4 |
HIGH | 7.5 | The Polylang plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.7.3 via … | — | wordfence |
| d042649e-abdc-4c9d-a94a-f0cea31f4e91 | HIGH | 7.5 | The Entrepreneur - Booking for Small Businesses WordPress theme for WordPress is vulnerable to PHP Object Injection in v… | — | wordfence | |
| d0215e53-0394-4845-93e4-463cd5642fb3 | < 2.0.1.8.2 |
HIGH | 7.5 | The Modal Survey Plugin for WordPress is vulnerable to Arbitrary Survey Update, Deletion and Creation in versions before… | — | wordfence |
| d0029883-79e0-4dd3-85a3-6bbf30452267 | < 1.5.43 |
HIGH | 7.5 | The Page Builder: Live Composer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and in… | — | wordfence |
| CVE-2026-6403 | < 1.3.3. |
HIGH | 7.5 | The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is… | — | nvd |
| CVE-2026-4020 | HIGH | 7.5 | The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi… | — | nvd | |
| CVE-2026-2471 | HIGH | 7.5 | The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1… | — | nvd | |
| CVE-2026-2428 | HIGH | 7.5 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in… | — | nvd | |
| CVE-2026-2416 | HIGH | 7.5 | The Geo Mashup plugin for WordPress is vulnerable to SQL Injection via the 'sort' parameter in all versions up to, and i… | — | nvd | |
| CVE-2026-2232 | HIGH | 7.5 | The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to time-based SQL Injection v… | — | nvd | |
| CVE-2026-2020 | HIGH | 7.5 | The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1… | — | nvd | |
| CVE-2026-1581 | HIGH | 7.5 | The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all version… | — | nvd | |
| CVE-2026-1557 | HIGH | 7.5 | The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0 … | — | nvd | |
| CVE-2025-12707 | HIGH | 7.5 | The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all version… | — | nvd | |
| CVE-2025-11754 | < 4.1.3 |
HIGH | 7.5 | The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch… | — | nvd |
| cffeac2c-8ca3-44f7-b54c-3c23b7a849a3 | < 6.50 |
HIGH | 7.5 | The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-c… | — | wordfence |
| cfea0427-78dc-4151-864a-63b6761fc294 | < 3.9.1 |
HIGH | 7.5 | The MinimogWP β The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to price manipulation … | — | wordfence |
| cfa487fb-c014-47f1-9537-73881ede30b4 | HIGH | 7.5 | The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th… | — | wordfence | |
| cfa375a8-ab07-45da-bc77-1e7edc996e05 | < 8.41 |
HIGH | 7.5 | The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.4… | — | wordfence |
| cf91d75e-cef4-4154-aa16-6ca96db9c5bb | < 3.5.2 |
HIGH | 7.5 | The Friends plugin for WordPress is vulnerable to PHP Object Injection in version 3.5.1 via deserialization of untrusted… | — | wordfence |
| cf24ee30-7d9f-47c3-bc2a-1c3c92971ba8 | < 19.1.5.1 |
HIGH | 7.5 | The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to … | — | wordfence |
| cf245445-27fd-4678-b95d-fb0b1c2aff7b | HIGH | 7.5 | The Spirit Framework plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.13… | — | wordfence | |
| cf11be7a-0b31-46ce-82ce-5a42898a8a10 | HIGH | 7.5 | The Log WP_Mail WordPress plugin through 0.1 saves sent email in a publicly accessible directory using predictable filen… | — | wordfence | |
| cefb979e-2b5b-4820-a350-ee106131f0f9 | < 3.1.1 |
HIGH | 7.5 | The make_clickable function in wp-includes/formatting.php in WordPress before 3.1.1 does not properly check URLs before … | — | wordfence |
| ceef080c-3d3b-494d-8cfa-fe9724b9207f | < 2.0 |
HIGH | 7.5 | The SecuPress Free and SecuPress Pro plugins for WordPress is vulnerable to unauthenticated arbitrary IP bans in version… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →