Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 331 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 010f1cd4-da4c-4693-8d1a-a93e779e36f3 | < 6.5.1 |
HIGH | 7.5 | The PDF for Gravity Forms + Drag And Drop Template Builder plugin for WordPress is vulnerable to PHP Object Injection in… | — | wordfence |
| 00e070b7-bdf6-4a80-a3ee-628243f1cc25 | < 4.1.0 |
HIGH | 7.5 | The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to SQL Injection via the URL path in all v… | — | wordfence |
| 00d8e7db-b1a4-4785-ba57-1dce0fd11dec | < 1.4.6 |
HIGH | 7.5 | The CMSMasters Content Composer plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… | — | wordfence |
| 007df869-dacb-4b0a-9c98-50586934cdab | < 3.9.7 |
HIGH | 7.5 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coup… | — | wordfence |
| 0066b63b-42ff-4edb-b17d-2210babc3502 | < 3.2.3 |
HIGH | 7.5 | The Bpost Shipping Platform plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.2 … | — | wordfence |
| 00612475-7efd-46f2-8196-666900ae7df3 | < 1.3.0 |
HIGH | 7.5 | The WpBookingly plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.9. This… | — | wordfence |
| 00599865-9091-46e1-b2a9-78cbd10f6f22 | < 0.9.2.5 |
HIGH | 7.5 | W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of d… | — | wordfence |
| ff9cfa56-e178-4de7-9e6b-e0a520153eb2 | < 1.37 |
HIGH | 7.4 | The Easy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versio… | — | wordfence |
| f0edfebc-bf6b-4346-9cd7-ce00007e3620 | < 2.4.44 |
HIGH | 7.4 | The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' field of … | — | wordfence |
| ed037e94-68b4-4efc-9d1a-fffc4aff1c45 | < 6.4.4 |
HIGH | 7.4 | The Business Directory Plugin plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.4.… | — | wordfence |
| ecb86ea6-2aca-4f7c-be81-a572b53b7953 | < 8.2.7 |
HIGH | 7.4 | The WP VR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up t… | — | wordfence |
| e14f0fc6-fca4-4dd7-8f7b-ed5ed535c9af | HIGH | 7.4 | The Widget Settings Importer/Exporter Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp_ajax… | — | wordfence | |
| de2c2c90-52b6-4315-a8d1-6519a90f81e7 | < 1.2.2 |
HIGH | 7.4 | The YourChannel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on 'save', … | — | wordfence |
| dc8d63ee-4929-4940-bc6a-931524e20272 | < 2.1 |
HIGH | 7.4 | The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Age Gate… | — | wordfence |
| d6fc087b-c28d-4c6a-a59f-085773d542dd | < 1.2.7 |
HIGH | 7.4 | The Smoke Signal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘text’ parameter in versi… | — | wordfence |
| d33a77c6-9977-4d92-92c4-4273ee73452e | < 1.1.2 |
HIGH | 7.4 | An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lack… | — | wordfence |
| cede59f9-611f-4da4-8140-181bd0a469d5 | < 5.3.1 |
HIGH | 7.4 | The Contact Form by FormGet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘value’ parame… | — | wordfence |
| c8fe569a-62dd-4be5-915d-de589663658f | HIGH | 7.4 | The Craw Data plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.0.0 … | — | wordfence | |
| c12538bc-6e7d-4d47-8e5b-65574ed26ec4 | < 1.8.2 |
HIGH | 7.4 | The Easy Coming Soon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background_color' parame… | — | wordfence |
| c0383bc6-919d-4858-a5b7-abe8a4a6c684 | < 1.2.4 |
HIGH | 7.4 | The editor of the WP Page Builder WordPress plugin before 1.2.4 allows lower-privileged users to insert unfiltered HTML,… | — | wordfence |
| aa309da6-6552-43e4-aeea-f822493dd029 | < 1.4 |
HIGH | 7.4 | The Export Users Plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.2. This allow… | — | wordfence |
| a73f3d93-198c-484c-bed5-59e477f3833e | < 3.12.7 |
HIGH | 7.4 | The Leaflet Maps Marker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in… | — | wordfence |
| a3e7460b-1ed4-4ff7-89c7-0bd2658a800d | < 1.11.3 |
HIGH | 7.4 | The Giveaways and Contests by RafflePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… | — | wordfence |
| 9b320755-1255-4331-8176-ee67d8d4873e | < 2.4.4 |
HIGH | 7.4 | … | — | wordfence |
| 9821e51c-1042-47b8-b104-32f5651c31c9 | < 1.8.9 |
HIGH | 7.4 | The TextMe SMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up t… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →