Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 317 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4209eddd-47ac-4802-b309-e42e5907a0cd | < 2.5 |
HIGH | 7.5 | The Echelon Theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.4. This is … | — | wordfence |
| 41e2dd3e-8e50-4f55-aa35-ff9d16e63a05 | < 4.5.4 |
HIGH | 7.5 | The RH - Real Estate WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and in… | — | wordfence |
| 41d7b3f1-a133-4678-b2d9-3f9951cbc005 | < 1.4.0 |
HIGH | 7.5 | The Event Monster β Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object… | — | wordfence |
| 4192f1eb-e52a-4b79-8795-ef79c687e9ae | < 1.2.4 |
HIGH | 7.5 | The TrueBooker β Appointment Booking and Scheduler System plugin for WordPress is vulnerable to SQL Injection in versi… | — | wordfence |
| 416ab7d5-9f3b-4ccc-9a0f-bfe5d38b6f97 | HIGH | 7.5 | The KenBurner Slider plugin for WordPress is vulnerable to Path Traversal in all versions via the kbslider_show_image fu… | — | wordfence | |
| 4143635d-00f0-4065-8670-5962d87940ee | < 2.0.0 |
HIGH | 7.5 | The Download Manager Addons for Elementor plugin for WordPress is vulnerable to SQL Injection in versions up to, and inc… | — | wordfence |
| 412d555c-9bbd-42f5-8020-ccfc18755a79 | < 5.0.4 |
HIGH | 7.5 | The MW WP Form plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 5.0.3… | — | wordfence |
| 4107362f-ae21-4509-b83a-0bffbde23330 | < 4.1.3 |
HIGH | 7.5 | The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch… | — | wordfence |
| 40e2e8fb-ea36-4602-bead-8daf75d6dfb9 | < 2.5 |
HIGH | 7.5 | The Ultimate GDPR & CCPA plugin for WordPress is vulnerable to unauthenticated settings import and export via the export… | — | wordfence |
| 40e09aec-48af-4bf9-9254-b34bad7008c3 | < 1.1.6 |
HIGH | 7.5 | The Easy Photo Album plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.1… | — | wordfence |
| 407d8ebe-f3fc-433a-856f-de2ad4e58b9e | < 19.1.5 |
HIGH | 7.5 | The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due t… | — | wordfence |
| 407351fe-4148-4872-9a18-f05de0d5075b | < 3.3.0 |
HIGH | 7.5 | The JobSearch WP Job Board plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.9 d… | — | wordfence |
| 3f80902e-edc8-4cac-a50d-6332fef35356 | < 7.6 |
HIGH | 7.5 | The Super Store Finder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.5 due to … | — | wordfence |
| 3f4893b9-e032-45d6-a542-0ead70c61e2f | < 0.14.11 |
HIGH | 7.5 | The webp-express plugin before 0.14.11 for WordPress has insufficient protection against arbitrary file reading. | — | wordfence |
| 3f389cbf-a327-46a1-9fb7-ed393212033a | < 3.0 |
HIGH | 7.5 | WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, w… | — | wordfence |
| 3f36839b-850e-4c39-aa61-4fd7a89cd5bc | < 7.4 |
HIGH | 7.5 | The WP Database Backup β Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sens… | — | wordfence |
| 3f244b8e-94ae-4d95-83a7-53b826e98656 | < 1.2.2.38 |
HIGH | 7.5 | The WP Stripe Checkout plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i… | — | wordfence |
| 3ef98c6f-4243-46bf-8231-3c751473fff7 | < 4.11.0 |
HIGH | 7.5 | The JupiterX Core plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.10.1 vi… | — | wordfence |
| 3ed92523-e0e4-4e2a-b727-325e8dff37d9 | < 5.7.7 |
HIGH | 7.5 | The Eduma theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.7.6. This makes … | — | wordfence |
| 3e9672b1-6d00-45bc-91ef-0c5583b5306e | < 19.1.5 |
HIGH | 7.5 | The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due … | — | wordfence |
| 3e63ce97-40af-493d-9376-231a99d9bd58 | HIGH | 7.5 | The Popup β MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to SQL Injectio… | — | wordfence | |
| 3e4da578-aa8d-40b4-98c7-3efef911f850 | < 2.4.20 |
HIGH | 7.5 | The ad-inserter plugin before 2.4.20 for WordPress has path traversal. | — | wordfence |
| 3e0f0a0c-8ef8-419d-92bf-964166508ebc | < 1.4.110 |
HIGH | 7.5 | The Motors β Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to SQL Injection in versio… | — | wordfence |
| 3e0b66b9-2e33-41e0-a024-35574716c91d | HIGH | 7.5 | The Downloable by American Osteopathic Association plugin for WordPress is vulnerable to Directory Traversal in all vers… | — | wordfence | |
| 3debeffa-5cc3-4d13-aed8-72753a62d8fc | < 3.6.0 |
HIGH | 7.5 | The Real Estate 7 WordPress theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.5.9 d… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →