Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 385 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 630516a5-9b73-48f7-9deb-1771b67e76b6 | < 4.6.1 |
HIGH | 7.2 | The Order Delivery Date for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to… | — | wordfence |
| 62fd472e-208b-48db-8f98-3d935c7a678c | < 1.11.17 |
HIGH | 7.2 | The Broken Link Checker plugin for WordPress is vulnerable to deserialization of untrusted input via the '$log_file' val… | — | wordfence |
| 62d81e01-9b6e-48e9-b9da-85444a3694e7 | < 1.5.7 |
HIGH | 7.2 | The WordPress Post Grid Layouts with Pagination β Sogrid plugin for WordPress is vulnerable to Local File Inclusion in… | — | wordfence |
| 62c46925-8e97-4989-8c2c-56223d6911a2 | < 3.1.3 |
HIGH | 7.2 | The Advanced Database Cleaner plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in version… | — | wordfence |
| 621ef583-bf99-4b81-ae9c-b4f1c86b86aa | < 3.8.4 |
HIGH | 7.2 | The UberMenu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.… | — | wordfence |
| 6208b87a-496c-404c-ac2e-0cc709cc5a5c | HIGH | 7.2 | The Booking Calendar Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up t… | — | wordfence | |
| 61ce76cc-4895-46f7-b6c9-5bc652b1c73c | < 2.9.2 |
HIGH | 7.2 | The Maspik β Spam blacklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… | — | wordfence |
| 61a93e58-09e2-4a84-b6ad-853f5c8b5a79 | < 2.15.4 |
HIGH | 7.2 | The Contact Form to Chat Apps | Click to Chat to Order β FormyChat plugin for WordPress is vulnerable to Stored Cross-… | — | wordfence |
| 61a63ba6-129a-4ce2-be40-89c2fa44a670 | < 2.1.6 |
HIGH | 7.2 | The Lifetime free Drag & Drop Contact Form Builder for WordPress VForm plugin for WordPress is vulnerable to Stored Cros… | — | wordfence |
| 61a4aea3-88a0-428c-8eba-78c9c3397ac9 | HIGH | 7.2 | The Dokan Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 … | — | wordfence | |
| 61a3c83f-1910-4c25-9b79-293c75d06e5a | HIGH | 7.2 | The Unlimited PopUps WordPress plugin through 4.5.3 does not sanitise or escape the did GET parameter before using it in… | — | wordfence | |
| 618854b9-fa85-4302-9a38-ae5cbd7c7b9f | < 5.17.3 |
HIGH | 7.2 | The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_acti… | — | wordfence |
| 615beb4d-c2df-4e1a-8e6b-a393c0fe4834 | < 3.3.3 |
HIGH | 7.2 | The AI Engine β The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to arbitrary file upl… | — | wordfence |
| 61584724-fa1d-4823-af3d-d44501dc1f60 | < 2.3 |
HIGH | 7.2 | The Chat Bubble plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2 … | — | wordfence |
| 60b16755-ac0e-4069-b21a-cca003fecbdc | HIGH | 7.2 | The FlightLog WordPress plugin through 3.0.2 does not sanitise, validate or escape various POST parameters before using … | — | wordfence | |
| 60a574c7-47de-4427-8d38-d510ea996f75 | < 2.0.7 |
HIGH | 7.2 | The Monolit theme for WordPress is vulnerable to Stored Cross-Site Scripting via unspecified parameters in versions up t… | — | wordfence |
| 6077a093-b2ec-4491-a4a7-d70b2858d772 | < 4.5.11 |
HIGH | 7.2 | The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php. | — | wordfence |
| 5fd495e8-d7e8-4949-b7aa-43ef40063ca1 | < 2.3.2 |
HIGH | 7.2 | The FooGallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' and 'extension' par… | — | wordfence |
| 5fd449d7-d14e-46d6-851c-828207c3c302 | < 3.2.4 |
HIGH | 7.2 | The Sprout Clients β CRM and Lead Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers… | — | wordfence |
| 5fb4f619-7fc8-482d-862f-ebb02c3870f8 | < 2.2.4 |
HIGH | 7.2 | The Property Hive plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… | — | wordfence |
| 5fb3a347-e124-484b-9eff-281a10c25a5c | < 5.4.2 |
HIGH | 7.2 | The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence |
| 5f837ba2-64a2-4d8e-8212-b646cb94b0d7 | < 1.4.4 |
HIGH | 7.2 | The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing … | — | wordfence |
| 5f0795f7-6eba-4ff0-b0da-5d2b544adf14 | < 0.8.4 |
HIGH | 7.2 | The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, … | — | wordfence |
| 5ef2196d-3617-44ba-a8c5-dc1b45408293 | < 1.8.0 |
HIGH | 7.2 | The Contact Forms by Cimatti plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… | — | wordfence |
| 5ecc0811-916d-4c60-9047-a09242de36bd | < 3.0.6.2 |
HIGH | 7.2 | The Post Indexer plugin before 3.0.6.2 for WordPress has SQL injection via the period parameter by a super admin. | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →