Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 371 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 98cf616d-6c9a-4a86-937d-535211e32bf1 | < 5.7.2 |
HIGH | 7.2 | The PhotoMe theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.7.1 due… | — | wordfence |
| 98adce63-69e6-4a3b-97fe-ecd0480659f4 | < 2.8.7 |
HIGH | 7.2 | The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL s… | — | wordfence |
| 989b4b9d-e22e-46a7-8ebc-5c8b33f98111 | < 2.5.2 |
HIGH | 7.2 | The HTML5 Audio Player β The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server… | — | wordfence |
| 97e68562-92b8-43ac-9a8c-778d2b61f889 | < 4.1.18 |
HIGH | 7.2 | The Mailster WordPress Newsletter Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing fil… | — | wordfence |
| 979699fd-ff31-4cba-bbf2-03fa51554031 | < 5.0.6 |
HIGH | 7.2 | The Multi Rating plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'from-date', 'to-date', and 'post… | — | wordfence |
| 97964ebd-be0b-4187-b393-17edf4ba5caf | < 1.13.2 |
HIGH | 7.2 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is… | — | wordfence |
| 977d1ec4-327b-4563-a3b1-ac4fad195eb7 | HIGH | 7.2 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor… | — | wordfence | |
| 9771d688-9c96-4ffb-823e-dcdf8b1cbc51 | < 6.0.8 |
HIGH | 7.2 | The Awesome Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence |
| 975c02d9-3e70-4e58-a6bb-57d45282459b | < 1.2.63 |
HIGH | 7.2 | The OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) plugin for WordPress is vulnerable to… | — | wordfence |
| 9744055a-b199-4945-afcc-4f5b85f5f1e8 | < 1.7.1058 |
HIGH | 7.2 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and incl… | — | wordfence |
| 970fc0af-d049-4aad-a439-7d1ea6bcca9b | < 3.9.3 |
HIGH | 7.2 | The Coaching theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.9.2 du… | — | wordfence |
| 96bc0d9b-1f03-48d4-aa99-954e92e77c04 | HIGH | 7.2 | The Cyclone Slider Plugin is vulnerable to Remote Code Execution via the slider import functionality in versions up to, … | — | wordfence | |
| 96b68824-3080-4959-a7d7-43d29c5c4119 | < 4.4.5 |
HIGH | 7.2 | The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter bef… | — | wordfence |
| 9699118a-e12f-491f-b464-51129888fb1a | < 3.1.5 |
HIGH | 7.2 | The Two Way Chat plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.1.4 due … | — | wordfence |
| 95fde924-bba5-4b7d-8cee-50bb3d2b4134 | < 1.0.232 |
HIGH | 7.2 | The Rank Math SEO β AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Remote Code Execution … | — | wordfence |
| 95c47c7b-df83-43ee-9091-136b6622e88c | HIGH | 7.2 | The WP Chinese Conversion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… | — | wordfence | |
| 958a036e-2893-40c2-a542-7a33c12161e3 | HIGH | 7.2 | The Helios Solutions Brand Logo Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file … | — | wordfence | |
| 95823720-e1dc-46c1-887b-ffd877b2fbe5 | < 4.13.1 |
HIGH | 7.2 | The GiveWP β Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… | — | wordfence |
| 954e7509-3ebf-429a-8c65-9825ea190d53 | < 5.0.0 |
HIGH | 7.2 | The FluentForm plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.3.25 due to insuf… | — | wordfence |
| 952aec28-a380-4c6d-8391-b21cddf90a5c | < 3.3.2 |
HIGH | 7.2 | The Real Estate 7 Theme for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions … | — | wordfence |
| 952a61e8-4be1-4974-9076-4493708bf51e | < 2.13.11 |
HIGH | 7.2 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil… | — | wordfence |
| 94dcaa35-f39f-4e8b-a57c-78343520cca6 | < 2.6.5 |
HIGH | 7.2 | The Perfmatters plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.… | — | wordfence |
| 94dbf144-4a8f-4d9a-ad32-703a91823acb | < 1.1.0 |
HIGH | 7.2 | The Limit Login Attempts Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging fea… | — | wordfence |
| 94772de9-6ab8-45ff-8b56-19b50a81b66f | < 1.13.2 |
HIGH | 7.2 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is… | — | wordfence |
| 941c9586-96a2-434e-af0d-c488e22ef97f | < 2.5.6 |
HIGH | 7.2 | The Breeze Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →