Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 314 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 5214a399-21a4-4573-9840-1d5043781bc0 | < 1.6.9.13 |
HIGH | 7.5 | The Appointment Booking Calendar β Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to b… | — | wordfence |
| 51b0c1e5-08f7-44b3-8518-6b0902b84758 | HIGH | 7.5 | The Ebook Downloader plugin for WordPress is vulnerable to SQL Injection via the 'download' parameter in all versions up… | — | wordfence | |
| 515a6a42-f353-47ae-9e74-4f9b2000bcb8 | < 3.2 |
HIGH | 7.5 | The WP ULike plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ulik… | — | wordfence |
| 51381ef9-7fac-4a1a-8c39-6a32f87ea5d5 | < 1.4.3 |
HIGH | 7.5 | The Consulting Elementor Widgets plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inclu… | — | wordfence |
| 50d1b8f6-8b60-4c49-a41c-4d5e0df2e7e2 | < 9.6.1 |
HIGH | 7.5 | The XStore theme for WordPress is vulnerable to Local File Inclusion in versions up to 9.6.1. This makes it possible for… | — | wordfence |
| 509a40d2-a33a-49ba-b858-fa8805127a1b | < 6.3.8 |
HIGH | 7.5 | The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization… | — | wordfence |
| 504fca80-7e81-412b-891f-2679451ff6e6 | HIGH | 7.5 | The WebARX plugin 1.3.0 for WordPress allows firewall bypass by appending &cc=1 to a URI. | — | wordfence | |
| 502cf45c-1350-4534-a806-6e248912ef6d | HIGH | 7.5 | The Floating Tweets plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.0.1 vi… | — | wordfence | |
| 50192909-9351-4cf5-b578-f34be72aeda6 | HIGH | 7.5 | The Revy plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.18 due to insufficient … | — | wordfence | |
| 4fce3965-3b91-4d19-ac58-2b5475d59c35 | < 2.5.2 |
HIGH | 7.5 | The WP Multistore Locator plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5.1 du… | — | wordfence |
| 4f69c239-d429-4970-bc1b-b2a7d96f4b7a | < 5.11.1 |
HIGH | 7.5 | The TheGem Theme Elements (for Elementor) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, … | — | wordfence |
| 4f4a7933-7e93-4d8e-a51a-57ab63e26644 | HIGH | 7.5 | The EduMall theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.4.7. This make… | — | wordfence | |
| 4eea120e-839e-4b01-a5a8-af21f5ab99f5 | < 2.2.4 |
HIGH | 7.5 | The CarSpot β Dealership Wordpress Classified Theme for WordPress is vulnerable to Insecure Direct Object References i… | — | wordfence |
| 4ede9023-732d-43e4-9c19-7cf704c95c29 | < 1.9.5.6 |
HIGH | 7.5 | participants-database.php in the Participants Database plugin 1.9.5.5 and previous versions for WordPress has a time-bas… | — | wordfence |
| 4e88efe0-ffad-4d66-bb03-3f3a9dcbe5b1 | < 2.3.16 |
HIGH | 7.5 | The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, … | — | wordfence |
| 4e72828e-a6f6-43fc-8a10-d9908004c0fc | < 5.0.21 |
HIGH | 7.5 | The LTL Freight Quotes β Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropsh… | — | wordfence |
| 4e534021-1c63-4db9-914b-7f9b3b613087 | HIGH | 7.5 | The WP Hide plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when updating t… | — | wordfence | |
| 4e27137d-1120-4ca5-8560-bbd5a382222e | HIGH | 7.5 | The Terms descriptions plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i… | — | wordfence | |
| 4e219891-7342-4dd9-ac4f-636a5058ecad | HIGH | 7.5 | The Travel & Tours Meta Search plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.3… | — | wordfence | |
| 4dd7d751-961a-4167-bb4a-2bcd66fc3c46 | < 4.5.2 |
HIGH | 7.5 | The Order Delivery Date for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and inclu… | — | wordfence |
| 4d19c023-4aa1-40ec-a87b-dcde945e7a2c | < 4.4.5 |
HIGH | 7.5 | The AWP Classifieds plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… | — | wordfence |
| 4ccc2f0c-07d5-45a5-86ec-1e6b6c5a316d | < 8.3.2 |
HIGH | 7.5 | The WoodMart theme for WordPress is vulnerable to Local File Inclusion in versions up to 8.3.2. This makes it possible f… | — | wordfence |
| 4c9cbe99-699a-4812-a8ae-aefd2b1e2c00 | < 3.9.16 |
HIGH | 7.5 | The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data d… | — | wordfence |
| 4c842ece-f4d4-4ba5-8676-da99994609d5 | < 3.1.0 |
HIGH | 7.5 | The HiStudy - Online Courses & Education Template theme for WordPress is vulnerable to SQL Injection in all versions up … | — | wordfence |
| 4c716fd3-6297-4b3a-a796-65f68f2986cf | < 1.2.1 |
HIGH | 7.5 | The GeekyBot β Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to S… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →