Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 383 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 68e6ec3a-c5fd-4f63-a9a0-2c9ddfb96e2e | < 2.4.6 |
HIGH | 7.2 | The YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and … | — | wordfence |
| 68d4aa8c-70f9-46ba-92ce-fbb427954e86 | < 2.0.6 |
HIGH | 7.2 | The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form entr… | — | wordfence |
| 68b202f7-fff1-4056-9b5b-b42b25189706 | < 2.5 |
HIGH | 7.2 | The Contact Form Integrated With Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… | — | wordfence |
| 68774d9c-7abc-416d-8ab9-2713a1bad377 | < 8.1.9 |
HIGH | 7.2 | The teachPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tab’ parameter in versions… | — | wordfence |
| 684253b3-0a96-4822-84c8-bde8ed45f35e | < 3.1.11 |
HIGH | 7.2 | The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin … | — | wordfence |
| 68110321-db1a-4634-98cd-0afd3ec933b8 | < 8.0.9 |
HIGH | 7.2 | The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the … | — | wordfence |
| 67f143a4-2467-48cf-8024-8529ef4ed449 | < 3.0 |
HIGH | 7.2 | The WPIDE plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.6. This allows … | — | wordfence |
| 67b0ddc6-9381-4b18-b623-372a149ffa49 | < 3.9 |
HIGH | 7.2 | The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenti… | — | wordfence |
| 67aee1ec-44af-4904-8a9b-ecfbb8d3b302 | < 1.0.3 |
HIGH | 7.2 | The Check & Log Email WordPress plugin before 1.0.3 does not validate and escape the "order" and "orderby" GET parameter… | — | wordfence |
| 67aa489c-5c54-4163-bc32-5d3ac9ba4e33 | HIGH | 7.2 | The G Auto-Hyperlink WordPress plugin through 1.0.1 does not sanitise or escape an 'id' GET parameter before using it in… | — | wordfence | |
| 67631693-ae8a-4532-a9e3-f21b385131a2 | < 5.149 |
HIGH | 7.2 | Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated … | — | wordfence |
| 6755c415-427e-4572-908c-061ab8f7490a | < 5.9.13.27 |
HIGH | 7.2 | The Link Library plugin for WordPress is vulnerable to generic SQL Injection via the "$_GET[‘linkid’]" parameter in … | — | wordfence |
| 67176209-443c-4f66-b5a8-1dde2f7f0837 | < 1.4.10 |
HIGH | 7.2 | Cross-site scripting (XSS) vulnerability in the Postie plugin before 1.4.10 for WordPress allows remote attackers to inj… | — | wordfence |
| 6713c2dc-fc7f-4992-bde7-cfb94c383664 | < 3.6.9 |
HIGH | 7.2 | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site … | — | wordfence |
| 670f4e26-75c9-40cd-8088-2fa4c40f6feb | < 4.0.50 |
HIGH | 7.2 | The Brevo for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_connection_i… | — | wordfence |
| 6709f9b0-0915-4361-9fb0-1f2696e26c2f | < 10.5.5 |
HIGH | 7.2 | The RSVPMaker plugin for WordPress is vulnerable to SQL Injection via the 'resend' parameter in versions up to, and inc… | — | wordfence |
| 66f73c3d-3937-4b9f-a7d6-29c249e46b92 | HIGH | 7.2 | The Mapwiz plugin for WordPress is vulnerable to SQL Injection via the 'mid' parameter in versions up to, and including,… | — | wordfence | |
| 66da0ad7-18a3-42b9-b59a-5927c6bc836b | HIGH | 7.2 | The Order Your Posts Manually plugin for WordPress is vulnerable to SQL Injection via the 'sortdata' parameter in versio… | — | wordfence | |
| 66cd0ed5-070a-4408-9faa-b3d840279f77 | < 3.9.0 |
HIGH | 7.2 | The WordPress Announcement & Notification Banner Plugin – Bulletin plugin for WordPress is vulnerable to SQL Injection… | — | wordfence |
| 66bc8d9c-1a5f-4dca-b15f-8fdf821dbc6f | HIGH | 7.2 | The WP RSS By Publishers plugin for WordPress is vulnerable to generic SQL Injection via an unspecified parameter in ver… | — | wordfence | |
| 66a3abc1-0508-4ce3-952b-7dbf3738879a | < 1.8.97 |
HIGH | 7.2 | The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inclu… | — | wordfence |
| 666b8b39-fab0-4e99-b365-a4ac9f964494 | HIGH | 7.2 | The Symbiostock – Sell Photos Online For Free! plugin for WordPress is vulnerable to arbitrary file uploads due to mis… | — | wordfence | |
| 66559c2a-1c8d-4861-8151-31972982683d | < 4.6.11 |
HIGH | 7.2 | The Ultimate Before After Image Slider & Gallery – BEAF plugin for WordPress is vulnerable to arbitrary file uploads d… | — | wordfence |
| 6635ff4d-cbb4-4e78-9df1-1274eaa737aa | < 7.41 |
HIGH | 7.2 | The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… | — | wordfence |
| 66130071-668e-4692-afd3-5fcc9039f10f | < 1.9.12 |
HIGH | 7.2 | The Tutor LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several user profile parameters in v… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →