Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 339 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 24aa6c0b-88bc-4c3e-ada7-2e89d84bdfc3 | < 1.2.17 |
HIGH | 7.3 | The PressMart - Modern Elementor WooCommerce WordPress Theme theme for WordPress is vulnerable to arbitrary shortcode ex… | — | wordfence |
| 2481f37b-a220-435d-9b43-6e7c5f42034f | < 3.7.18 |
HIGH | 7.3 | The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in Wor… | — | wordfence |
| 22cc6da1-fd22-4b2a-90ab-24086879f0f6 | HIGH | 7.3 | The azurecurve Shortcodes in Comments plugin for WordPress is vulnerable to arbitrary shortcode execution in all version… | — | wordfence | |
| 2144ba9f-cb0a-4b54-a23f-3ecb2548a490 | < 3.7.31 |
HIGH | 7.3 | WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary… | — | wordfence |
| 1f2f390b-332b-452c-9fe7-ccd1a45390dd | < 7.11.14 |
HIGH | 7.3 | The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode executi… | — | wordfence |
| 1df6d436-c183-4ace-bd6c-1f22fbe7240f | < 1.16.3.6 |
HIGH | 7.3 | Import and export users and customers WordPress Plugin through 1.16.3.5 allows CSV injection via a customer's profile. | — | wordfence |
| 1be557db-daa8-4d86-819a-462f29da884b | < 1.6.8.7 |
HIGH | 7.3 | The Appointment Booking Calendar β Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to a… | — | wordfence |
| 18498171-7db1-4ebb-8fe0-a66d9343cb46 | < 3.3.24 |
HIGH | 7.3 | The MasterStudy LMS WordPress Plugin β for Online Courses and Education plugin for WordPress is vulnerable to limited … | — | wordfence |
| 1816a385-0b50-4f0d-848c-f583c247c8fc | < 6.2.20 |
HIGH | 7.3 | The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it i… | — | wordfence |
| 15b2a08f-2122-4eaf-ab46-1945cf6a68ca | < 6.2.5 |
HIGH | 7.3 | The The Special Text Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, an… | — | wordfence |
| 120fa415-81e3-4084-8943-df83cde334c5 | < 2.8.3 |
HIGH | 7.3 | Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthoriz… | — | wordfence |
| 10d92d5e-1c23-4f6a-bfab-0756876190a5 | < 2.7.4 |
HIGH | 7.3 | The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthenticated privilege escalation in all version… | — | wordfence |
| 0cac1dc0-87dc-43eb-9db1-638a91200b43 | < 1.3.6 |
HIGH | 7.3 | The The WP Popup Builder β Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary s… | — | wordfence |
| 0ae3cf36-ca3a-4f6d-90c3-6fb67c6862b9 | < 2.12.1 |
HIGH | 7.3 | The Ultimate Member β User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… | — | wordfence |
| 0935ede4-05bc-48a2-94a3-8d92002e02bb | < 2.3.0 |
HIGH | 7.3 | The ReviewX β WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin f… | — | wordfence |
| 0747b104-5be6-44eb-b62c-0026f810573c | < 6.1.5 |
HIGH | 7.3 | The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to authorization bypass in versions before 6.1.5. This… | — | wordfence |
| 067031e8-6aa8-451c-a318-b1848c7a4f92 | < 3.3.41 |
HIGH | 7.3 | The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up … | — | wordfence |
| 032e775a-97be-4d93-bac3-094e35be4b11 | HIGH | 7.3 | The WP GDPR plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up … | — | wordfence | |
| fff9fee5-3dca-447d-b7a8-981a5818ec12 | < 1.3.6 |
HIGH | 7.2 | The Simple Events Calendar for WordPress is vulnerable to SQL Injection via the βevent_idβ parameter in versions bef… | — | wordfence |
| fff57224-f597-4501-b33c-e04061bd0b1a | < 2.2.9 |
HIGH | 7.2 | The Prague plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.8 due… | — | wordfence |
| ffd44a71-486b-4182-bd91-e31dd06d0d4d | HIGH | 7.2 | The Orders functionality in the WP iCommerce WordPress plugin through 1.1.1 has an `order_id` parameter which is not san… | — | wordfence | |
| ffbf5930-50f3-44ca-8333-7b934dcd5ef7 | HIGH | 7.2 | The Simple Buttons Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Add Button" functi… | — | wordfence | |
| ff7ead53-4b20-48ba-95cd-118fb4eab330 | < 5.21 |
HIGH | 7.2 | The Social proof testimonials and reviews by Repuso plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… | — | wordfence |
| ff3aa112-bee2-485f-b5a1-ad156662ab03 | < 2.0.8 |
HIGH | 7.2 | The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it… | — | wordfence |
| ff1d2bd8-cc46-4763-8ba7-832b982ff56a | < 5.1.1 |
HIGH | 7.2 | The Invisible Anti-Spam & CAPTCHA β reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored C… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →