Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 388 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 568aa6d6-10a1-4653-ab95-845faf005b8e | HIGH | 7.2 | The Post Meta Data Manager plugin for WordPress is vulnerable to multisite privilege escalation in all versions up to, a… | — | wordfence | |
| 5686bc0f-efe7-4268-a6e1-bec939504ab4 | < 1.1.4 |
HIGH | 7.2 | The Hostel Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'contact_name' and 'contact_… | — | wordfence |
| 565b4026-0807-449d-a78e-798da53c3f52 | < 3.5.1.11 |
HIGH | 7.2 | The Smart Slider 3 plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5.1.9 … | — | wordfence |
| 56439ae3-bdbc-4c57-abf4-8c94dea8c6f5 | < 3.2.0 |
HIGH | 7.2 | The "Shortcode Addons- with Visual Composer, Divi, Beaver Builder and Elementor Extension" plugin for WordPress is vulne… | — | wordfence |
| 55ed6e73-4e9a-4201-91c2-0f7153ec1cb7 | < 1.5.3 |
HIGH | 7.2 | The WP User Merger plugin for WordPress is vulnerable to generic SQL Injection via 'user_id' parameter (in function 'wpu… | — | wordfence |
| 55b3e2dc-dc4f-408b-bbc6-da72ed5ad245 | < 2.4.9 |
HIGH | 7.2 | The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficie… | — | wordfence |
| 559a92e0-609e-415f-aab3-649a185eb431 | < 1.2.7 |
HIGH | 7.2 | The Ninja Forms Google Sheet Connector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … | — | wordfence |
| 5536a6fd-3df0-4595-b71d-b8bcdbb64a9f | < 1.43 |
HIGH | 7.2 | Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers… | — | wordfence |
| 54c94de4-59b4-4f0b-85db-2074a41d04f8 | HIGH | 7.2 | The Who Hit The Page – Hit Counter plugin for WordPress is vulnerable to SQL Injection in versions up to, and includin… | — | wordfence | |
| 54bee415-b1f4-4176-a317-3e2a651298fb | < 4.1.2 |
HIGH | 7.2 | The LWS Optimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1… | — | wordfence |
| 54bdacd9-49e4-4f45-99bb-baa9eba97ecf | < 1.7.9.2 |
HIGH | 7.2 | The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrator… | — | wordfence |
| 54acaeeb-bc39-441a-b0bc-6005dc452d27 | < 3.4.6 |
HIGH | 7.2 | The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vuln… | — | wordfence |
| 54897968-55fe-4542-bac8-190b29f68b0d | < 9.1.8 |
HIGH | 7.2 | The NEX-Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.1.7 … | — | wordfence |
| 542a4079-b1a2-49bc-9ddd-ba7978c9992e | < 2.10.2 |
HIGH | 7.2 | The Beautiful Cookie Consent Banner for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nsc_bar_content_… | — | wordfence |
| 541fbcd6-353f-4ef7-88f1-fc81a6b73e04 | < 3.1.8 |
HIGH | 7.2 | The Gift Up Gift Cards for WordPress and WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery i… | — | wordfence |
| 5414259c-339d-41fe-a0dc-4d4e4d966e15 | < 2.1.1 |
HIGH | 7.2 | The Debug Bar ElasticPress plugin for WordPress is vulnerable to Cross-Site Scripting via the ‘query’ parameter in v… | — | wordfence |
| 53fb54bc-6eaa-4e99-a41c-e59a9bae81e5 | HIGH | 7.2 | The Glossary by WPPedia – Best Glossary plugin for WordPress plugin for WordPress is vulnerable to PHP Object Injectio… | — | wordfence | |
| 53a28cee-fda0-43eb-8012-5059bb061694 | HIGH | 7.2 | The wp-stats-dashboard plugin through 2.9.4 for WordPress has admin/graph_trend.php type SQL injection. | — | wordfence | |
| 539cd606-1884-48df-beae-f5686a4e2400 | HIGH | 7.2 | The multimedial images plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0b due to… | — | wordfence | |
| 5351212d-122e-4356-b6d1-86bd0cd2cc68 | < 3.15.0.8 |
HIGH | 7.2 | The FunnelKit Funnel Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… | — | wordfence |
| 5350e519-3fa5-4463-b7b4-12bbe6fd5591 | < 3.2.5 |
HIGH | 7.2 | Cross-site scripting (XSS) vulnerability in inc/admin/content.php in the Better WP Security (iThemes) plugin before 3.2.… | — | wordfence |
| 534e6f80-b162-4a4b-a979-72ed63a8b0dc | < 2.2.1 |
HIGH | 7.2 | The Paytm Payment Donation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST data in the i… | — | wordfence |
| 5340204a-8a4f-4e23-82a1-c228b884c34a | < 3.6.4 |
HIGH | 7.2 | The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which coul… | — | wordfence |
| 5339024c-afcc-4fdc-a14b-056068ff2f5b | < 6.79 |
HIGH | 7.2 | The CleanTalk Anti-Spam. Spam Firewall & Bot protection plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… | — | wordfence |
| 5331c7cc-3854-4975-9f28-e9b0d6407227 | < 2.1.1 |
HIGH | 7.2 | The Smart Forms – when you need more than just a contact form plugin for WordPress is vulnerable to authorization bypa… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →