Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 338 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 55fa8423-9a41-4afe-9401-03d232caa656 | < 7.2.2 |
HIGH | 7.3 | The The GamiPress β Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPre… | — | wordfence |
| 53bb0871-343a-4299-9902-682c422152d1 | < 8.9.01.001 |
HIGH | 7.3 | The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrendere… | — | wordfence |
| 4ff1d12e-1129-40d3-8c29-3a46ffc77872 | < 3.0.15 |
HIGH | 7.3 | The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… | — | wordfence |
| 4f726479-c170-4e84-a5a7-2a82d0f62ad0 | < 19.9.8 |
HIGH | 7.3 | The The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to arbitrar… | — | wordfence |
| 4f1a1171-3d7b-46a4-982e-fe318e3017b7 | < 3.9.5 |
HIGH | 7.3 | The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versio… | — | wordfence |
| 4a7be578-5883-4cd3-963d-bf81c3af2003 | < 3.3.04 |
HIGH | 7.3 | The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and … | — | wordfence |
| 4635f5c1-c326-4f53-bc54-a402cf5dae00 | < 5.6.66 |
HIGH | 7.3 | The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode e… | — | wordfence |
| 459b7fef-806c-4f5b-bb31-b7197750e941 | < 1.4.11 |
HIGH | 7.3 | The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing… | — | wordfence |
| 4270a5c2-abc0-4505-9683-030dc08a462d | < 2.7.8 |
HIGH | 7.3 | The Feature Image from URL plugin for WordPress is vulnerable to authorization bypass due to missing capability checks o… | — | wordfence |
| 3f2d6c42-4baa-4d15-934f-0f8998c7d654 | < 2.3.5 |
HIGH | 7.3 | The Post Carousel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on multip… | — | wordfence |
| 3efe6b81-72db-4419-92a3-26e22ebf46e8 | < 2.0.13 |
HIGH | 7.3 | The Advanced Ads βΒ Ad Manager & AdSense plugin for WordPress is vulnerable to Remote Code Execution in all versions u… | — | wordfence |
| 3ccd3504-5663-48cd-90bc-502c2ce232f7 | < 1.5 |
HIGH | 7.3 | The The Request a Quote for WooCommerce and Elementor β Get a Quote Button β Product Enquiry Form Popup β Product … | — | wordfence |
| 3c7cc2d2-8de4-453b-b4dc-48f75b151078 | < 3.7.4 |
HIGH | 7.3 | The The Logo Slider β Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is … | — | wordfence |
| 3bf76527-9a11-4755-992c-02fbc1a79bae | HIGH | 7.3 | The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including… | — | wordfence | |
| 37836722-eb25-4393-8cdf-91057642ba3f | < 2.7.4 |
HIGH | 7.3 | The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ… | — | wordfence |
| 36b58a4f-0761-4775-9010-9c77d4019c44 | < 5.3.15 |
HIGH | 7.3 | The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to … | — | wordfence |
| 34c627c1-7838-468e-acb7-eb84ad1b4949 | < 14.3.4 |
HIGH | 7.3 | The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includ… | — | wordfence |
| 30b6b0bf-e632-4e83-89ee-a424382534da | < 1.5.0 |
HIGH | 7.3 | The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in versions up to, and includi… | — | wordfence |
| 3000758d-68e0-46a6-aef0-e2407a828168 | < 2.0.0 |
HIGH | 7.3 | The The Uix Shortcodes β Compatible with Gutenberg plugin for WordPress is vulnerable to arbitrary shortcode execution… | — | wordfence |
| 2e3194a7-5b3d-4805-9a35-50ebe65aa6ae | < 2.6.8 |
HIGH | 7.3 | Unspecified vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.8 for WordPress has unspeci… | — | wordfence |
| 2b2769bc-523b-4a8f-9042-1e879db3f8ed | < 2.0.14 |
HIGH | 7.3 | The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-regist… | — | wordfence |
| 2ad5544a-6694-41e4-940f-fa96daf4b41d | < 3.1.1 |
HIGH | 7.3 | The Checkout with Zelle on Woocommerce plugin for WordPress is vulnerable to unauthorized actions due to a missing capab… | — | wordfence |
| 2a0f539c-5d1d-4e1b-9a4b-719c096ba23c | < 1.16.8 |
HIGH | 7.3 | The The NitroPack β Caching & Speed Optimization for Core Web Vitals, Defer CSS & JS, Lazy load Images and CDN plugin … | — | wordfence |
| 2735f9a5-3f5b-4eac-a19a-59925c1fe1b5 | < 3.3 |
HIGH | 7.3 | Unspecified vulnerability in the Image News slider plugin before 3.3 for WordPress has unspecified impact and remote att… | — | wordfence |
| 266032a8-a139-4a14-8eda-8be7a66357df | HIGH | 7.3 | The The Grid Plus β Unlimited grid layout plugin for WordPress is vulnerable to arbitrary shortcode execution via grid… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →