Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 380 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 73a1174d-fb5a-4cc0-ada0-dbf1e011619a | < 2.9.3 |
HIGH | 7.2 | The Pardakht Delkhah plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'submitted_name' paramete… | — | wordfence |
| 739cfb80-da3d-41c8-a299-fd3f0168fb8d | HIGH | 7.2 | The Theme Demo Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… | — | wordfence | |
| 738c6c77-97ef-4e47-9f14-9b73ea425bc2 | < 1.8.2 |
HIGH | 7.2 | The WordPress Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | — | wordfence |
| 73809551-b925-4789-b059-b9e60743f693 | < 11.4.3 |
HIGH | 7.2 | The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… | — | wordfence |
| 736e0010-f1fc-42c4-8173-b81c5c78e34e | < 3.39 |
HIGH | 7.2 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… | — | wordfence |
| 733ae8c8-fa52-418d-b42e-75516906fb66 | < 1.7.3 |
HIGH | 7.2 | The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_p… | — | wordfence |
| 730d0ff6-9881-4d69-bdaf-924d3d9f522c | < 0.13.2 |
HIGH | 7.2 | The IndieBlocks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, … | — | wordfence |
| 72fadfa8-4b53-4661-8b6c-69cdb79d3fd7 | < 0.9.5 |
HIGH | 7.2 | The Customizer Export/Import for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.9.4… | — | wordfence |
| 72b777ac-1870-4588-82fe-da96a784ec81 | HIGH | 7.2 | The Rapid Cache plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 1.2.3. This … | — | wordfence | |
| 726f5063-e904-4512-bbdc-305049219003 | < 2.5.0 |
HIGH | 7.2 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versio… | — | wordfence |
| 723bce00-e0d7-4802-8dde-7edb90015067 | < 2.56.1 |
HIGH | 7.2 | The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.56 du… | — | wordfence |
| 720be34d-3fe4-4395-a27b-d386f8612ba9 | < 1.6 |
HIGH | 7.2 | The Sell BTC - Cryptocurrency Selling Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… | — | wordfence |
| 71f7733a-1350-4e22-98d8-28be401aee69 | HIGH | 7.2 | The Cleverwise Daily Quotes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … | — | wordfence | |
| 71e2db7c-53a7-4b17-b00a-ce71a00bf546 | < 1.24.2 |
HIGH | 7.2 | An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the w… | — | wordfence |
| 71d657d4-b326-4655-808a-913bbc9a8d1d | < 0.7.9 |
HIGH | 7.2 | The Event List plugin for WordPress is vulnerable to time-based SQL Injection via the βidβ parameter in versions bef… | — | wordfence |
| 7179fe0d-8cfa-4b43-82d6-5523d65ff780 | < 3.6.0 |
HIGH | 7.2 | The WP-Lister Lite for eBay plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… | — | wordfence |
| 7148e182-858c-42b1-b9db-9b7a267483e1 | < 4.3.45 |
HIGH | 7.2 | The WPtouch plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.3.44 via dese… | — | wordfence |
| 712e9341-5bd5-4b9c-891c-048ccec1ba45 | < 7.3.24 |
HIGH | 7.2 | The Paid Videochat Turnkey Site β HTML5 PPV Live Webcams plugin for WordPress is vulnerable to Remote Code Execution i… | — | wordfence |
| 710b8e4e-01de-4e99-8cf2-31abc2419b29 | < 1.0.77 |
HIGH | 7.2 | The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the… | — | wordfence |
| 70dfe9ca-77d5-4ab9-b251-360f89cc1de1 | HIGH | 7.2 | The Processing Projects plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… | — | wordfence | |
| 70ca7ad4-6848-4f87-ae2d-4b9c2ffa668e | < 4.1.6 |
HIGH | 7.2 | The WC Fields Factory for WordPress is vulnerable to SQL Injection via the 'post' parameter in versions up to, and inclu… | — | wordfence |
| 70b18fd0-41e5-4679-a7a5-3dd6eaa29136 | < 4.1.17 |
HIGH | 7.2 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and inc… | — | wordfence |
| 7082c181-88c7-40f0-b49c-ffc16ab41dcc | < 3.2.5 |
HIGH | 7.2 | The Zephyr Project Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check … | — | wordfence |
| 70570837-8c11-4361-96ce-7418106fb006 | < 0.10.2 |
HIGH | 7.2 | The CodeColorer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.10… | — | wordfence |
| 6fbf8a8f-56f7-42ae-bf96-30a2df6da378 | < 1.6.2 |
HIGH | 7.2 | The microblog-poster plugin before 1.6.2 for WordPress has SQL Injection via the wp-admin/options-general.php?page=micro… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →