Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 349 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| dd389d3b-046c-41cb-a077-7dcb9fd50eda | < 14.16.7 |
HIGH | 7.2 | The WP Statistics β Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored… | — | wordfence |
| dcf54e27-e2d1-4d87-8eb6-2881054b70fe | < 1.5.8 |
HIGH | 7.2 | The Fluent Support plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and i… | — | wordfence |
| dcf38298-9ccf-4939-b764-f83dbca4d54e | < 1.3.2 |
HIGH | 7.2 | The WPCS β WordPress Currency Switcher Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting … | — | wordfence |
| dc9676ef-34d7-4a88-a295-1c7136a0e6cd | HIGH | 7.2 | The Dextaz Ping plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.65. … | — | wordfence | |
| dc8b33c7-23ef-4b5c-bdb9-b4e548d18832 | < 2.10.4 |
HIGH | 7.2 | The Ultimate Member β User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… | — | wordfence |
| dc5276e2-e9de-4409-bbe0-4d0b37244367 | < 4.9.51 |
HIGH | 7.2 | The WooCommerce Follow-Up Emails plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4… | — | wordfence |
| dc4a6c2a-9a16-47dc-97ea-914adfb34688 | < 2.1.1 |
HIGH | 7.2 | The MelaPress Login Security plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including… | — | wordfence |
| dc2532b4-907f-438b-baab-c3966cf30f74 | < 1.8.0 |
HIGH | 7.2 | The Student Results or Employee Database plugin for WordPress is vulnerable to unauthorized REST calls in versions up to… | — | wordfence |
| dbf2b1a9-c248-4b77-a90d-4d3b5cfc447c | HIGH | 7.2 | The WP Real IP-based Access Control plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… | — | wordfence | |
| db701ad3-10fd-4a40-b239-139fbc95ab61 | < 1.8.0 |
HIGH | 7.2 | The Rich Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the POST body 'update' parameter i… | — | wordfence |
| db6f08f9-4da3-450d-bf1e-5c9f0aab02a1 | < 4.9.32 |
HIGH | 7.2 | The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'MWP-Key-Name' HTTP reques… | — | wordfence |
| db484c8a-e46d-457b-b634-28d823ff2120 | < 3.0.2 |
HIGH | 7.2 | Unvaludated input in the Advanced Database Cleaner plugin, versions before 3.0.2, lead to SQL injection allowing high pr… | — | wordfence |
| db3d9cd4-e7d8-4aab-bbaf-83473c70af40 | < 3.6.33 |
HIGH | 7.2 | The My auctions allegro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… | — | wordfence |
| db1bb11d-4752-42d0-b538-2d2a4c827226 | < 4.7.9 |
HIGH | 7.2 | The AI ChatBot plugin for WordPress is vulnerable to SQL Injection via the orderby parameter in all versions up to, and … | — | wordfence |
| dadfa92b-c674-4523-89b9-e8817e521c17 | < 5.7.3 |
HIGH | 7.2 | The AutomatorWP β Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for Wor… | — | wordfence |
| dad27b29-d106-44f2-9b88-6cce0c0cf4a5 | < 4.3.45 |
HIGH | 7.2 | The WPtouch plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation when upload… | — | wordfence |
| dab0ddfb-6e30-4bde-95fb-90570579ff04 | < 2.0.2 |
HIGH | 7.2 | Multiple cross-site scripting (XSS) vulnerabilities in the "post comment" functionality of WordPress 2.0.1 and earlier a… | — | wordfence |
| da848ced-acc4-48bc-8fbe-e90cdd53b3e8 | < 20160215 |
HIGH | 7.2 | The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field. | — | wordfence |
| da8166f3-02d8-4519-a518-0f5e9e1b1ab3 | < 2.97.4 |
HIGH | 7.2 | The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… | — | wordfence |
| da235dea-4884-4e6a-a8b8-65d34f050684 | < 9.2.3 |
HIGH | 7.2 | The NEX-Forms β Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting … | — | wordfence |
| d9f6b761-9c4b-4dcc-885d-9a5b4e8e534d | < 2.5.1 |
HIGH | 7.2 | The AI Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.5.0 vi… | — | wordfence |
| d97c3379-56c9-4261-9a70-3119ec121a40 | < 7.87 |
HIGH | 7.2 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing… | — | wordfence |
| d969fb35-2ee9-42ca-a9e8-f6453a1e6be9 | < 3.3.6 |
HIGH | 7.2 | The Companion Auto Update plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.3.5 du… | — | wordfence |
| d9244775-eab8-4cf4-98bb-97e467dcc5cf | < 5.3 |
HIGH | 7.2 | The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection. | — | wordfence |
| d91cd902-f429-4b13-a0d0-04af8f908c95 | < 3.1.58 |
HIGH | 7.2 | The Cart Lift β Abandoned Cart Recovery for WooCommerce and EDD plugin for WordPress is vulnerable to Stored Cross-Sit… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →