Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 344 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f00e8169-3b8f-44a0-9af2-e81777a913f8 | < 2.7.2 |
HIGH | 7.2 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection vi… | — | wordfence |
| efdf76b2-7640-4384-a72b-789159eb9c86 | < 2.5.0.2 |
HIGH | 7.2 | The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘answer-x’ parameter in vers… | — | wordfence |
| efc434fd-320a-4808-9289-7c2f63d4f5a4 | < 1.2.2 |
HIGH | 7.2 | The SMTP Mail plugin for WordPress is vulnerable to generic SQL Injection via the ‘order’ and ‘orderby’ paramete… | — | wordfence |
| efab7ec7-7143-4556-8d68-4a7e34f46e9e | < 1.2.2 |
HIGH | 7.2 | The Woocommerce Support System plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versio… | — | wordfence |
| ef9d256b-9156-4172-8892-29a26beddb71 | < 6.2.1 |
HIGH | 7.2 | The Booking Calendar plugin for WordPress is vulnerable to generic SQL Injection via the booking ID field in versions up… | — | wordfence |
| ef888b2e-1fc7-442b-8b67-ebfdcbc76696 | < 3.8.2 |
HIGH | 7.2 | The I Recommend This plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.8.1 … | — | wordfence |
| ef20b3e6-d8f4-458e-b604-b46ef16e229e | < 1.11.2 |
HIGH | 7.2 | The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up … | — | wordfence |
| ef07d6b0-ccdb-4b33-817f-6d4b3ad96243 | < 1.3.7 |
HIGH | 7.2 | The TableMaster for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a… | — | wordfence |
| eee9e199-00c6-4640-bd7c-e1316e2bba51 | HIGH | 7.2 | The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter wh… | — | wordfence | |
| eee60ee9-ec48-4c09-9905-edd2dbbcccf3 | < 1.7.1 |
HIGH | 7.2 | The Advanced Booking Calendar plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in … | — | wordfence |
| eea05676-aa24-4f60-9a8c-716b8a051be6 | < 4.1.2.1 |
HIGH | 7.2 | The JetBooking plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4… | — | wordfence |
| ee7eb754-27f0-47b0-a82f-4781cfbb0fa6 | HIGH | 7.2 | The Neshan Maps plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions up to, and includ… | — | wordfence | |
| ee2bbe3a-b1d2-4266-af55-35f60ac52733 | HIGH | 7.2 | The Arabic Font plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arabic-font.php' and '/inc/pa… | — | wordfence | |
| ee27a988-6afd-4da7-a750-0af801d7fa15 | < 2.8.4 |
HIGH | 7.2 | The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template. | — | wordfence |
| ee269bc7-2822-4a07-be91-6763c1cf6cf2 | < 1.2.7 |
HIGH | 7.2 | The WP SMTP plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in versions 1.2 to 1.2.6 due … | — | wordfence |
| ededbe81-6feb-4952-9dc2-12156444ff5c | < 3.5.2 |
HIGH | 7.2 | The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vul… | — | wordfence |
| edb0ee0c-1eab-4988-9eb6-cc0c253fee15 | < 2.8.3 |
HIGH | 7.2 | The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site S… | — | wordfence |
| edaec73f-25b5-4ace-afef-844eb4143bf2 | < 3.39 |
HIGH | 7.2 | The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to PHAR Deserialization in all versi… | — | wordfence |
| ed9ae337-fd2b-49c1-baac-6540f1152f94 | < 5.8.4 |
HIGH | 7.2 | Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via para… | — | wordfence |
| ed8f8984-bea6-44aa-9bde-5b40b455767f | < 2.1.77 |
HIGH | 7.2 | The WooCommerce Product Vendors plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.… | — | wordfence |
| ed28fe16-0835-4e94-a30e-305e7ba03740 | < 2.5.1 |
HIGH | 7.2 | The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 … | — | wordfence |
| ed1ba10b-bbaf-4753-8ae3-107e2cd3ead3 | < 1.3.0 |
HIGH | 7.2 | The FluentCart plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.3.0 due to insuffic… | — | wordfence |
| ecc59a6f-5e4a-44b4-932d-ed990ebb075a | < 3.06 |
HIGH | 7.2 | The Media Library Assistant for WordPress is vulnerable to SQL Injection via the ‘post_types’ parameter in versions … | — | wordfence |
| ec3ef618-27db-4cdd-a1ea-09f7cb24e954 | < 2.10.9 |
HIGH | 7.2 | The Modula - PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1… | — | wordfence |
| ec2c0542-b5ae-4595-b712-ddcd27d21183 | < 2.15.4 |
HIGH | 7.2 | The Tourfic – Ultimate Hotel Booking, Travel Booking & Car Rental WordPress Plugin | WooCommerce Booking plugin for Wo… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →