Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 332 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 96d264fe-e7e1-4eec-b235-9d288bc5a22f | < 1.5 |
HIGH | 7.4 | The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on se… | — | wordfence |
| 9652575b-389c-42e3-800a-0f133e0c224b | < 2.07 |
HIGH | 7.4 | The Shortcodes by Angie Makes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wc_button’ … | — | wordfence |
| 9495e25d-a5a6-4f25-9363-783626e58a4a | < 1.0.126 |
HIGH | 7.4 | The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_admin… | — | wordfence |
| 8ed9a5df-90d0-4abe-be1c-49c50a6b48b3 | < 3.4 |
HIGH | 7.4 | The Duplicate Page plugin for WordPress is vulnerable to generic SQL Injection via the ‘post' parameter in versions up… | — | wordfence |
| 8d18e1c7-65b6-4c1f-88bf-4014418ff920 | < 1.2.3 |
HIGH | 7.4 | The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in version… | — | wordfence |
| 8806a1b7-03c9-40a8-a1ef-f122329e0443 | < 3.31.0 |
HIGH | 7.4 | The FG Joomla to WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter… | — | wordfence |
| 80dfc293-a182-4ed5-9127-6ec788312416 | < 1.0.41 |
HIGH | 7.4 | The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that red… | — | wordfence |
| 74f0af24-e4d9-4b89-b91e-c6ec3e3918e7 | < 1.4.1 |
HIGH | 7.4 | The Post to CSV by BestWebSoft plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4… | — | wordfence |
| 747d7649-bdf5-46d0-a496-59cb7eac77ac | < 3.0.12 |
HIGH | 7.4 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification and r… | — | wordfence |
| 71da4bd0-79d7-42ec-9e79-3a44411c2313 | HIGH | 7.4 | The Add Subtitle WordPress plugin through 1.1.0 does not sanitise or escape the sub-title field (available only with cla… | — | wordfence | |
| 70f2965a-37fe-4b7e-890a-9bf73b5de1c7 | < 1.9.10.69 |
HIGH | 7.4 | The Better Messages plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to 1.9.10.68. This … | — | wordfence |
| 6b8655a6-f410-480d-8c45-2527b53fa129 | < 5.0.1 |
HIGH | 7.4 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to PHP Object Injection in versio… | — | wordfence |
| 65b3baaf-86e4-4dd2-b3eb-84c21eabdd6d | < 0.8.7.5 |
HIGH | 7.4 | The WP Fastest Cache plugin for WordPress is vulnerable to blind SQL Injection via the ‘$comment_id’ parameter in ve… | — | wordfence |
| 5ce22e5b-7f5c-41be-a50e-dc8100348122 | HIGH | 7.4 | The Olevmedia Shortcodes for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [button] shortcode … | — | wordfence | |
| 5629d479-143d-4a03-ac64-cb304954a5ca | < 3.4.0 |
HIGH | 7.4 | The Web To Print Shop : uDraw WordPress plugin up to 3.3.3 does not validate the url parameter in its udraw_convert_url_… | — | wordfence |
| 50298ef3-352d-4fd2-bbb9-a55cfd329837 | < 4.0 |
HIGH | 7.4 | The Ultimate Affiliate Pro for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions… | — | wordfence |
| 4c30b925-47ca-4e14-a418-d9524648db2a | < 2.10.24 |
HIGH | 7.4 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and incl… | — | wordfence |
| 434a724e-0bc6-4218-8ad4-c52e1880a75f | < 2.3.1 |
HIGH | 7.4 | The WP Blog and Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in … | — | wordfence |
| 419b20fa-6fea-41d7-9e3d-45ac25b4131f | < 3.8.3 |
HIGH | 7.4 | Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow … | — | wordfence |
| 39e90b51-c5f2-4a9f-ace8-6fbc6749557b | HIGH | 7.4 | The YaDisk Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode attributes… | — | wordfence | |
| 38cc5a39-6ec3-4ce9-b9ad-d4ca5dafe9a7 | HIGH | 7.4 | The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to a missing capability… | — | wordfence | |
| 36ae4183-5fa7-484c-b858-5df10ae3d3f2 | < 1.6 |
HIGH | 7.4 | The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp… | — | wordfence |
| 246eea09-abe5-41e9-811e-5cddedbbe01e | < 5.3.6 |
HIGH | 7.4 | The iThemes Security plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the… | — | wordfence |
| 1d93db2c-7baf-42d8-9b4a-be91b27221a7 | < 4.5 |
HIGH | 7.4 | The UX Flat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all… | — | wordfence |
| 12dc9e63-17bb-4755-be3c-ae8b26edd3cd | < 5.9.10 |
HIGH | 7.4 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPre… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →