Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 323 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 24b319e6-1903-44a9-9f69-0e5ebe891870 | HIGH | 7.5 | The history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter. | — | wordfence | |
| 24902fab-44ea-44c9-bcf5-70960cfeb402 | < 3.14.1 |
HIGH | 7.5 | The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… | — | wordfence |
| 2480091f-2b5d-440c-9617-934d097b3a63 | < 3.4 |
HIGH | 7.5 | The InFocus Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 3.3. This is … | — | wordfence |
| 247b1921-70a6-4e65-819a-2895bc395e9f | < 1.4.19 |
HIGH | 7.5 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all… | — | wordfence |
| 245e9117-ca63-458e-a094-60a759f5ec19 | < 0.0.5 |
HIGH | 7.5 | The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validati… | — | wordfence |
| 242b274d-a922-4db5-ac7a-b74cbf8212da | < 1.6.4 |
HIGH | 7.5 | The Nest Addons plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.3 due to insuf… | — | wordfence |
| 242819d5-0cc5-463f-984a-8e70e032bfe4 | < 3.0.10 |
HIGH | 7.5 | The Exhibz theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.0.9. This makes… | — | wordfence |
| 24225f47-cec2-4270-88f0-8696ebfb7168 | HIGH | 7.5 | The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed… | — | wordfence | |
| 241d9cd3-9331-49b2-8083-dc646070488e | < 1.1.0 |
HIGH | 7.5 | The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all ve… | — | wordfence |
| 2403dd59-7b9e-490e-86d8-5a10f9eee616 | < 3.6.5 |
HIGH | 7.5 | The LTL Freight Quotes – TForce Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id'… | — | wordfence |
| 23bcd8b4-04c9-4b7e-b114-70f2675ca2bd | < 1.5 |
HIGH | 7.5 | The Multiple Shipping And Billing Address For Woocommerce plugin for WordPress is vulnerable to SQL Injection in version… | — | wordfence |
| 22c6f81b-d456-44b9-ba6c-8b207a9ee6e1 | HIGH | 7.5 | The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0 … | — | wordfence | |
| 22be5fb5-143e-4934-9f93-e17def18e883 | < 7.8.9.3 |
HIGH | 7.5 | The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file upl… | — | wordfence |
| 22b55747-8b46-4812-9345-0db03500105f | < 3.15.2 |
HIGH | 7.5 | The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter i… | — | wordfence |
| 2295b532-7833-4f5d-9778-de26390b04bd | < 3.7 |
HIGH | 7.5 | The Protect WP Admin WordPress plugin before 3.7 does not check for authorisation in the lib/pwa-deactivate.php file, wh… | — | wordfence |
| 2263d356-b2ed-4e16-98ee-b01d4274d1d9 | < 2.5.1 |
HIGH | 7.5 | The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of d… | — | wordfence |
| 2240b2d3-b4cc-445f-b207-0ccbd527a0f3 | < 1.26 |
HIGH | 7.5 | The RokStories plugin for WordPress is vulnerable to Full Path Disclosure in versions up to, and including, 1.25 via the… | — | wordfence |
| 221dab8e-2f8d-47d7-b9f5-a2f0d4edcef7 | < 4.9.3 |
HIGH | 7.5 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulne… | — | wordfence |
| 21cf5a39-831b-4423-b901-98bf15416fc8 | < 2.0.0 |
HIGH | 7.5 | NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability. | — | wordfence |
| 21cd8cb8-2a29-4b66-ab7a-8d8b2f85e2e0 | < 5.26.6 |
HIGH | 7.5 | The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and inclu… | — | wordfence |
| 2187311d-6651-4eca-806d-aa2ff9fae4e2 | < 2.145.1 |
HIGH | 7.5 | The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized SQL Injection due to an auth… | — | wordfence |
| 213fde1b-13dc-442a-8f48-4b1074155a6f | < 19.1.5 |
HIGH | 7.5 | The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due t… | — | wordfence |
| 212ee91a-9713-4a1a-ac55-742a89eb2704 | < 1.6.27 |
HIGH | 7.5 | The Riode Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.26 due to insuf… | — | wordfence |
| 20b9dcd9-d87d-46ef-82b1-30743fcdc909 | < 3.1 |
HIGH | 7.5 | The Kentha Elementor Widgets plugin for WordPress is vulnerable to Local File Inclusion in versions up to 3.1. This make… | — | wordfence |
| 2049712a-6ff2-4e2a-98f8-93a493a5bfd3 | < 8.41 |
HIGH | 7.5 | The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →