Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 377 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 7d7b2c79-c4f7-4611-a22a-685d4421a4ab | < 1.0.7 |
HIGH | 7.2 | The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all versi… | — | wordfence |
| 7d55c2b8-c05e-419b-8c2d-8c07c8655c17 | < 1.0.25 |
HIGH | 7.2 | The Contact Form Builder plugin for WordPress is vulnerable to blind SQL Injection via the 'order_by' parameter in versi… | — | wordfence |
| 7d54a72c-8fd5-418f-8109-078d0d75138d | < 2.3.11 |
HIGH | 7.2 | The HollerBox β Fast & Effective Popups & Lead-Generation plugin for WordPress is vulnerable to Stored Cross-Site Scri… | — | wordfence |
| 7ce4050e-3563-4aac-b1c1-16cba20e1e86 | < 8.9.3 |
HIGH | 7.2 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… | — | wordfence |
| 7cda6aad-36e1-45c7-af46-a7b90bb2d339 | < 1.12.21 |
HIGH | 7.2 | The Giveaways and Contests by RafflePress β Get More Website Traffic, Email Subscribers, and Social Followers plugin f… | — | wordfence |
| 7cb9cc24-920f-402d-8a87-8b6c6a1b1a51 | < 5.0.0 |
HIGH | 7.2 | The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_date parameter before … | — | wordfence |
| 7c94f47a-4a1b-434c-b446-0ff1a7290e16 | < 1.2.5 |
HIGH | 7.2 | The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect ru… | — | wordfence |
| 7c500c5b-04b9-47d7-9296-dd5378cd5ab0 | HIGH | 7.2 | The Event Banner WordPress plugin through 1.3 does not verify the uploaded image file, allowing admin accounts to upload… | — | wordfence | |
| 7c4fc322-1f62-48e3-8177-4894c947624b | < 1.7.6 |
HIGH | 7.2 | The Shared Files β Advanced File Sharing & Download Manager with Frontend Uploads plugin for WordPress is vulnerable t… | — | wordfence |
| 7c3f7108-eb32-425a-a705-4f032e7da6b0 | < 1.0.3 |
HIGH | 7.2 | The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t… | — | wordfence |
| 7c1c24cc-9388-4d91-8dc6-c67d3420cc94 | < 1.0.64 |
HIGH | 7.2 | The 10WebMapBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Plugin Settings Change in vers… | — | wordfence |
| 7bff8172-b879-40b0-a229-a54787baa38a | HIGH | 7.2 | The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'form-id' par… | — | wordfence | |
| 7bf4fe42-435b-449e-bb8c-57cef3b93471 | HIGH | 7.2 | The Conditional Payment Methods for WooCommerce plugin for WordPress is vulnerable to SQL Injection via an unknown param… | — | wordfence | |
| 7bde6d5c-85a1-47d4-a017-23ce69a3bb5e | < 2.5.0 |
HIGH | 7.2 | The Gutenverse Form β Contact Form Builder, Block Form & Booking Form plugin for WordPress is vulnerable to Stored Cro… | — | wordfence |
| 7bd89bd9-4f99-4828-bacc-15d2cfe13066 | < 2.9.29 |
HIGH | 7.2 | The Ninja Forms Contact Form plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including… | — | wordfence |
| 7bc2d608-637c-4098-8ac9-07997df3138a | < 3.4.2 |
HIGH | 7.2 | The Vitepos β Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all ve… | — | wordfence |
| 7b4f63af-cb43-4287-8fdd-0ff1df70c6d6 | < 3.2.2 |
HIGH | 7.2 | The Rencontre β Dating Site plugin for WordPress is vulnerable to SQL Injection via the 'activ' parameter in versions … | — | wordfence |
| 7b452283-9f0d-469b-b1b8-4bd253f9ea1d | < 1.7.6 |
HIGH | 7.2 | The URL Shortify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the referrer header in versions u… | — | wordfence |
| 7b384246-7f6f-489f-897d-53f1b1ae51c3 | < 8.10.8 |
HIGH | 7.2 | The Advanced IP Blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… | — | wordfence |
| 7b2ebbb5-0590-4e4a-a9b6-abc80b220d18 | < 4.6.60 |
HIGH | 7.2 | The Tradetracker-Store plugin for WordPress is vulnerable to generic SQL Injection via the βtestβ parameter in versi… | — | wordfence |
| 7b1019ef-02fd-4220-9dcf-e7776d40b3e7 | < 10.9.3.2 |
HIGH | 7.2 | The Thrive Visual Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… | — | wordfence |
| 7b049489-50b1-4199-9e66-0db5d745b968 | HIGH | 7.2 | The Lawyer Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… | — | wordfence | |
| 7ae0710a-8c9b-41b0-860f-ae79b7ed1ee4 | < 3.9.12 |
HIGH | 7.2 | The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up … | — | wordfence |
| 7adf3335-ed13-43f4-a5f3-05e89be44d2d | < 13.2.5 |
HIGH | 7.2 | The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, … | — | wordfence |
| 7adebd83-8186-402a-8327-c7f9c009ed62 | HIGH | 7.2 | The Simple Schools Staff Directory WordPress plugin through 1.1 does not validate uploaded logo pictures to ensure that … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →