Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 384 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 660058f0-ccd9-4bb9-9e11-f1e1d1100ef2 | HIGH | 7.2 | The Edit Role functionality in the Display Users WordPress plugin through 2.0.0 had an `id` parameter which is not sanit… | — | wordfence | |
| 651fa700-2462-4c9c-bd13-85f3a53a64df | < 2.10.1 |
HIGH | 7.2 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10… | — | wordfence |
| 64f879af-aa8f-4edf-8369-ca032603d529 | < 2.4.7.1 |
HIGH | 7.2 | The WC Vendors Marketplace plugin for WordPress is vulnerable to SQL Injection via search date parameters in versions up… | — | wordfence |
| 64f07bca-5d04-4b28-b775-f47ed692575e | < 2.7.2 |
HIGH | 7.2 | The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions … | — | wordfence |
| 64cf0ae2-8d66-40d1-8bb6-0cab1dafab0d | < 6.1.1 |
HIGH | 7.2 | The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and i… | — | wordfence |
| 64be6e85-00c9-49f5-9ee2-08dbe434a848 | < 1.6.3 |
HIGH | 7.2 | The User Activity Log plugin for WordPress is vulnerable to SQL Injection via several parameters like 'userrole', 'useri… | — | wordfence |
| 64b10a7d-ca11-47ec-ba8a-e2b838fd8a2a | HIGH | 7.2 | The check_order function of The Sorter WordPress plugin through 1.0 uses an `area_id` parameter which is not sanitised, … | — | wordfence | |
| 645ad965-4da3-45e4-aa9e-d5f5f8c9f087 | HIGH | 7.2 | The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2c… | — | wordfence | |
| 644c8702-08ad-4048-ae91-041f1771f1dc | < 3.3.4 |
HIGH | 7.2 | The Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin for WordPress is vulnerable to deserial… | — | wordfence |
| 644a0628-2401-4581-a3a2-463dc2172808 | < 8.2 |
HIGH | 7.2 | The NEX-Forms LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 8.2 due to insuff… | — | wordfence |
| 643f92e2-b14e-4056-97fc-1c631027c54f | < 6.2.12 |
HIGH | 7.2 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vul… | — | wordfence |
| 643b8b82-c4e1-4b81-a7e0-aee0f9270702 | < 1.6.1 |
HIGH | 7.2 | The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable… | — | wordfence |
| 63f86449-144c-494f-85d8-ce7c8d7d65d3 | < 1.6.4 |
HIGH | 7.2 | The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead valu… | — | wordfence |
| 63f6ca11-abfb-4f87-a9f7-0321f1de9abe | < 3.10 |
HIGH | 7.2 | The Formidable PRO2PDF plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up to, and… | — | wordfence |
| 63df43cc-7f84-4316-80fc-b0242b9f454c | < 4.1.0 |
HIGH | 7.2 | The Careerfy theme for WordPress is vulnerable to Multiple Cross-Site Scripting in versions up to, and including, 4.0.0 … | — | wordfence |
| 63d49d5e-5562-4803-9e2c-429acd4ca75d | < 5.1.7.7 |
HIGH | 7.2 | The Survey Maker by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to 5.1.7.7 … | — | wordfence |
| 63af91ef-54ef-4322-9931-a0d29dbd2aec | HIGH | 7.2 | The Email Artillery (MASS EMAIL) plugin for WordPress is vulnerable to various SQL Injection via the 'post_id' and 'emai… | — | wordfence | |
| 63af403f-facd-40e3-94bf-12f211d0c7ed | HIGH | 7.2 | The Simple Basic Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… | — | wordfence | |
| 63a2d09d-9cb8-47ba-8e40-5b43894552e3 | < 3.8.3 |
HIGH | 7.2 | The Wordfence Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wfwhois’ parameter… | — | wordfence |
| 63973f61-81f0-4fc8-810c-a15734ff824e | < 2.10.1 |
HIGH | 7.2 | The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to an… | — | wordfence |
| 637af5d1-eed3-4216-8d47-e68f83c63f43 | HIGH | 7.2 | The MicroCopy plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and incl… | — | wordfence | |
| 635e19ba-da98-459c-ab91-ff969b0812fd | < 6.2.8 |
HIGH | 7.2 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vul… | — | wordfence |
| 634d4062-7004-4e89-89a8-323c939aae93 | < 1.2.7 |
HIGH | 7.2 | The WP Fastest Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2… | — | wordfence |
| 6334b02e-ffab-49f9-969b-d015c2babc29 | < 5.0.5 |
HIGH | 7.2 | The Slimstat Analytics plugin for WordPress is vulnerable to SQL Injection via the 'misc[limit_results]' parameter in ve… | — | wordfence |
| 63323552-354b-44b6-81a4-0b6e82480910 | HIGH | 7.2 | The Simply Poll for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘question’ parameter in versions … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →