Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 347 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| e4414b5d-9ce5-4378-ab41-c82ae3bebd6e | < 3.12.5 |
HIGH | 7.2 | The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) plugin for WordPress is vulnerable to SQL Injection via … | — | wordfence |
| e4188b26-80f8-41b8-be19-1ddcbd7e39f5 | < 4.0.52 |
HIGH | 7.2 | The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to un… | — | wordfence |
| e411c319-3eb0-4a41-9ba7-9a6a4f203809 | < 3.6.0 |
HIGH | 7.2 | The Real Estate 7 WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… | — | wordfence |
| e4077fda-3f39-4e17-b7b8-3f1b6bf0a9e1 | < 4.5.5 |
HIGH | 7.2 | The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via numerous parameters in versions u… | — | wordfence |
| e3ce37e7-1dca-4f74-86ce-65bf29ef091e | < 3.1.6 |
HIGH | 7.2 | The Quick Interest Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'loan-amount' and 'l… | — | wordfence |
| e3a8f554-7cb6-40b7-b83c-819e7785058a | HIGH | 7.2 | The HyperComments plugin for WordPress is vulnerable to Arbitrary File Deletion via the 'xml' GET parameter in versions … | — | wordfence | |
| e39810d7-260f-4729-9b11-69dba0e16684 | HIGH | 7.2 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor… | — | wordfence | |
| e363c09a-4381-4b3a-951c-9a0ff5669016 | < 6.0.8 |
HIGH | 7.2 | WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versio… | — | wordfence |
| e349f07d-a520-4700-a6e0-25e68c1deeae | < 1.5.4 |
HIGH | 7.2 | The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin, version 1.5.3, is vulnerable to Post-Authentic… | — | wordfence |
| e340863f-c029-43c9-9e48-08cc5b93e400 | HIGH | 7.2 | The Dinatur plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.18 due… | — | wordfence | |
| e32a4038-0f67-48b3-80c9-94d279752c31 | < 1.6.8 |
HIGH | 7.2 | The Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to,… | — | wordfence |
| e2d29afd-06e8-461a-918f-38228441a51a | < 6.6.16 |
HIGH | 7.2 | The Slider Revolution plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including,… | — | wordfence |
| e2b4586a-f87d-4a51-8f4e-932d7254518e | < 1.8.9 |
HIGH | 7.2 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ema… | — | wordfence |
| e2b16b9c-48c7-4370-839b-696797ff2101 | < 4.24.9 |
HIGH | 7.2 | The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all … | — | wordfence |
| e2960224-4446-4fc6-8d18-6f9911b4cbad | < 6.8.1 |
HIGH | 7.2 | The Rich Shortcodes for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the content… | — | wordfence |
| e26b7e73-2d04-493a-a7d9-2276bc0e1ba8 | < 1.3.6 |
HIGH | 7.2 | The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parame… | — | wordfence |
| e25f524e-360d-4c80-a0ab-90ee94825b1b | < 2.71 |
HIGH | 7.2 | The WP-Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pollq_question and polla_answe… | — | wordfence |
| e2521876-cd1c-4c4a-8486-b1c4da78ffdb | < 3.3.17 |
HIGH | 7.2 | The Instantio – WooCommerce Quick Checkout | Direct Checkout, Floating Cart, Side Cart & Popup Cart plugin for WordPre… | — | wordfence |
| e2256157-e65f-46fb-b226-fa778ad3e69c | < 1.5.9 |
HIGH | 7.2 | The Fediverse Embeds plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includ… | — | wordfence |
| e1e973e3-f2a2-465c-aec7-5a7d4290c00b | < 3.5.2 |
HIGH | 7.2 | Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before … | — | wordfence |
| e1cd9978-2d8d-4818-8baf-8f31e0212957 | < 1.15.0 |
HIGH | 7.2 | The ACF City Selector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… | — | wordfence |
| e1c16bcb-c188-4e01-9d0b-e4e1a1ef82ee | < 2.1.10 |
HIGH | 7.2 | The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hb_country_iso', 'hb_usa_state_iso'… | — | wordfence |
| e18b3a85-9d4a-4af8-9a73-1f8794ad467b | HIGH | 7.2 | The searchterms-tagging-2 plugin through 1.535 for WordPress has SQL injection via the pk_stt2_db_get_popular_terms coun… | — | wordfence | |
| e1523ba0-9cac-43e2-9441-4d02fbaaf705 | < 6.5.6 |
HIGH | 7.2 | The Google Analyticator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.5… | — | wordfence |
| e11c9f2c-4ac6-4da2-9b4c-d393e2d3332b | < 1.6.12.4 |
HIGH | 7.2 | The Simply Schedule Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →