Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 352 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d2b7ed73-a654-40ef-8d80-6171393da8e7 | < 5.4.8 |
HIGH | 7.2 | The All-In-One Security (AIOS) β Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripti… | — | wordfence |
| d253a001-7023-4070-81c5-35d485ffd36c | HIGH | 7.2 | The Advanced Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data parameter in all vers… | — | wordfence | |
| d21b09f2-6766-4f55-9745-ae9fd4a0d88c | HIGH | 7.2 | The KKProgressbar2 Free β advanced progress bars plugin for WordPress is vulnerable to Cross-Site Request Forgery in a… | — | wordfence | |
| d2165d61-dc86-4893-91c4-85f0a577fc1c | < 13.1.6 |
HIGH | 7.2 | The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization o… | — | wordfence |
| d1e0d59b-903e-466b-9892-a2cee6f7a53f | < 7.7.5 |
HIGH | 7.2 | The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence |
| d1b4ea18-0937-4bd4-b161-a3780e6c6749 | < 2.1.0 |
HIGH | 7.2 | The Easy Invoice plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0… | — | wordfence |
| d18d800b-647f-4706-9ec1-a8ea4e643965 | < 3.3.20 |
HIGH | 7.2 | The Multiple Page Generator Plugin β MPG plugin for WordPress is vulnerable to SQL Injection in the projects_list and … | — | wordfence |
| d16363d6-ca4b-4de0-abae-a7b07803e2e3 | < 2.4.1 |
HIGH | 7.2 | The TS Poll β Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the … | — | wordfence |
| d159130a-c99d-44d3-a130-aa0146f17157 | < 5.1.13 |
HIGH | 7.2 | The Seamless Donations: A Platform for Global Fundraising and Rebuilding using Stripe and PayPal plugin for WordPress in… | — | wordfence |
| d0e0d284-2056-414e-9069-d2302db0670d | HIGH | 7.2 | The Live Chat Unlimited plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inc… | — | wordfence | |
| d0c9f4c5-a4f6-4cab-8531-5b88b3f347ea | < 2.9.10 |
HIGH | 7.2 | The PostX β Gutenberg Blocks for Post Grid plugin for WordPress is vulnerable to Cross-Site Scripting in versions up t… | — | wordfence |
| d09985e9-ee18-41a0-94d0-05dd80a68ed9 | < 8.2.0 |
HIGH | 7.2 | The Nelio A/B Testing β AB Tests and Heatmaps for Better Conversion Optimization plugin for WordPress is vulnerable to… | — | wordfence |
| d070e12e-ec53-4574-ac37-dc8805d9a553 | < 2.2.5 |
HIGH | 7.2 | The WPSchoolPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the βClassIDβ parameter i… | — | wordfence |
| d056ad60-0102-490e-89a8-31fe6513645e | < 5.2.0.4 |
HIGH | 7.2 | The plugin WP phpMyAdmin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.… | — | wordfence |
| d04f11b4-ee58-428b-aaa2-dc7d9f3e68e3 | < 2.0.5 |
HIGH | 7.2 | The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST … | — | wordfence |
| d0318ed9-a464-498b-a821-f7746740937c | < 2.8.2 |
HIGH | 7.2 | Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attacker… | — | wordfence |
| CVE-2026-2365 | HIGH | 7.2 | The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fluentform_step_form_sav… | — | nvd | |
| CVE-2026-2019 | HIGH | 7.2 | The Cart All In One For WooCommerce plugin for WordPress is vulnerable to Code Injection in all versions up to, and incl… | — | nvd | |
| CVE-2026-1945 | HIGH | 7.2 | The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_ema… | — | nvd | |
| CVE-2026-1931 | HIGH | 7.2 | The Rent Fetch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'keyword' parameter in all vers… | — | nvd | |
| CVE-2026-1216 | HIGH | 7.2 | The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in … | — | nvd | |
| CVE-2025-14452 | HIGH | 7.2 | The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' param… | — | nvd | |
| CVE-2025-12886 | HIGH | 7.2 | The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, … | — | nvd | |
| cffaa829-3eee-4390-b3c0-5c0f04ff9e8f | < 1.15.15 |
HIGH | 7.2 | The Asgaros Forum WordPress plugin before 1.15.15 does not validate or escape the forum_id parameter before using it in … | — | wordfence |
| cfc6b4a5-ff13-457f-9e06-de15e8cb5510 | < 3.9.27 |
HIGH | 7.2 | The WP Import Export Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includin… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →