Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 319 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 38826657-ee20-4743-baef-de735a01f4d5 | < 10.11.1 |
HIGH | 7.5 | The AcyMailing β An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is… | — | wordfence |
| 387f7ee0-6b1e-4862-8270-dbb3aee70a7e | < 3.1.0 |
HIGH | 7.5 | The JS Help Desk β AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection in versio… | — | wordfence |
| 38672a45-b7a7-445f-9e77-7050df6920fa | < 1.7 |
HIGH | 7.5 | The Post Grid, Slider & Carousel Ultimate β with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is… | — | wordfence |
| 3852cdf8-70f7-4eba-9083-def6e5299043 | HIGH | 7.5 | The Neon Product Designer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.1 du… | — | wordfence | |
| 38391221-c435-4672-809a-ebabf639c9bb | HIGH | 7.5 | The Spirit Framework plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.… | — | wordfence | |
| 37e84cab-746a-4b64-b9a1-7232584d1f19 | HIGH | 7.5 | The Woocommerce Product Design plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and incl… | — | wordfence | |
| 37d13a43-13f4-460d-b5ea-5def8a379d54 | < 4.3 |
HIGH | 7.5 | The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?a… | — | wordfence |
| 3776c594-5c67-4331-a95b-051fc58b214e | < 6.5.1 |
HIGH | 7.5 | The PDF for Elementor Forms + Drag And Drop Template Builder plugin for WordPress is vulnerable to PHP Object Injection … | — | wordfence |
| 375aab8b-d46b-48b1-874b-0fb7136cb312 | HIGH | 7.5 | The WOOEXIM β WooCommerce Export Import Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versi… | — | wordfence | |
| 37053b53-8308-4e54-99c2-7616ed8cb379 | < 9.0 |
HIGH | 7.5 | The Email Newsletter for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 8.0. This … | — | wordfence |
| 36dec90a-fead-48f5-a88b-dfbc6d8bffb4 | < 2.3.12 |
HIGH | 7.5 | The NotificationX plugin for WordPress is vulnerable to generic SQL Injection via the βidβ parameter found within th… | — | wordfence |
| 36daf2af-1db3-4b35-8849-480212660b2f | < 2.0.1 |
HIGH | 7.5 | The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions … | — | wordfence |
| 36d3dae0-4705-487a-a4a4-c12280e866a3 | HIGH | 7.5 | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads via the 'dl' parameter found… | — | wordfence | |
| 36629099-eb8d-4ddb-ba85-e1506262e245 | HIGH | 7.5 | The Triply theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.7. This makes… | — | wordfence | |
| 36615cae-418f-48b0-ba69-b54515cbe1d7 | < 2.5.3 |
HIGH | 7.5 | The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and … | — | wordfence |
| 35e33e30-e102-445a-99d0-27adb7fc4638 | < 4.0.3.1 |
HIGH | 7.5 | The JetBooking plugin for WordPress is vulnerable to SQL Injection via the 'check_in_date' parameter in all versions up … | — | wordfence |
| 35c12f80-d069-44ed-b6a5-caa060fbd281 | < 2.4 |
HIGH | 7.5 | Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows rem… | — | wordfence |
| 35acdb85-e463-46b1-aea7-a6d4c3581499 | < 3.4 |
HIGH | 7.5 | The Advance Seat Reservation Management for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'pro… | — | wordfence |
| 35a55336-2cd1-41a8-b9ef-09ab4a8dd632 | < 8.0.2 |
HIGH | 7.5 | The ActivityPub plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 8.0.2 (exclus… | — | wordfence |
| 359b596e-1973-4bf6-a012-84b422c0f2c1 | < 2.6.91 |
HIGH | 7.5 | The Customizable WordPress Gallery Plugin β Modula Image Gallery plugin for WordPress is vulnerable to authorization b… | — | wordfence |
| 355d6e61-a45b-4682-bfad-77df18ae79f4 | < 1.55.1 |
HIGH | 7.5 | The Forminator Forms β Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Director… | — | wordfence |
| 3528acaa-0068-4476-82d7-fe7d68a55743 | HIGH | 7.5 | The Brook - Agency Business Creative WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versio… | — | wordfence | |
| 351a035a-9768-4efd-9887-e0905e129634 | < 1.2.1 |
HIGH | 7.5 | The GeekyBot β AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content plugin for WordPress is vulnerable to S… | — | wordfence |
| 34f8d60e-01c8-40d6-b655-1dce127b607c | HIGH | 7.5 | The Multiple Carousel plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0 due … | — | wordfence | |
| 34adbae5-d615-4f8d-a845-6741d897f06c | < 2.10.1 |
HIGH | 7.5 | The Ultimate Member β User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →