Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 390 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 5038d12a-e119-4ab7-aadc-69b765ae7027 | < 3.1 |
HIGH | 7.2 | The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local … | — | wordfence |
| 501e9cd1-1187-4d01-a3cc-5edba64c391f | < 1.0.6 |
HIGH | 7.2 | The Image Compressor & Optimizer β iLoveIMG plugin for WordPress is vulnerable to PHP Object Injection in all versions… | — | wordfence |
| 4fa5b8a9-1683-4806-987d-527834f45d34 | HIGH | 7.2 | The LifePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'n' parameter of the lp_update_m… | — | wordfence | |
| 4fa453f3-d361-452c-940a-108252c9f302 | < 2.5.2 |
HIGH | 7.2 | Unrestricted file upload vulnerability in WordPress 2.5.1 and earlier might allow remote authenticated administrators to… | — | wordfence |
| 4fa00dae-c51d-4586-81da-b568cd6d8124 | < 6.6.13 |
HIGH | 7.2 | The Slider Revolution plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… | — | wordfence |
| 4f77f4cd-f4b3-42bc-a1a9-e5df5daa42b7 | < 6.6.12 |
HIGH | 7.2 | The CTX Feed β WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin in… | — | wordfence |
| 4f3e3311-11d8-4e4f-9d99-36533fe44d56 | HIGH | 7.2 | The Olive One Click Demo Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va… | — | wordfence | |
| 4f060807-cd59-4558-a30b-00b4b947f3f7 | < 1.9.13 |
HIGH | 7.2 | The Everest Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… | — | wordfence |
| 4f018e22-bf07-4371-afc1-3e664ea1c5a3 | < 2.3.7 |
HIGH | 7.2 | The All in One SEO β Best WordPress SEO Plugin β Easily Improve SEO Rankings & Increase Traffic plugin for WordPress… | — | wordfence |
| 4ebbe9a4-3769-4e05-9377-907b43e3fe10 | < 2.67.3 |
HIGH | 7.2 | The WP-EMail plugin for WordPress is vulnerable to Cross-Site Scripting via several form fields in versions up to, and i… | — | wordfence |
| 4e3f4e4f-6781-4134-b0ba-3625d7009d0c | HIGH | 7.2 | The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from whe… | — | wordfence | |
| 4e3931c2-c9b4-412e-941d-840c5bb9be89 | < 14.6 |
HIGH | 7.2 | The Online Booking and Scheduling plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and incl… | — | wordfence |
| 4e0baa10-f576-48f5-ad7f-2cbae9d0abd0 | < 2.8.3 |
HIGH | 7.2 | The NPS computy plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.… | — | wordfence |
| 4dc83aca-f533-4a8c-b12c-e21156ce6088 | < 3.1.43 |
HIGH | 7.2 | The WP Event Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.1.42… | — | wordfence |
| 4da167e0-c1cf-496f-9b14-35fc70386be1 | HIGH | 7.2 | The AJS Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'note_list_class' and 'popup… | — | wordfence | |
| 4d8d581c-8198-4431-a534-aac8f05750cb | < 1.7.7 |
HIGH | 7.2 | The Page Builder: Pagelayer β Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized modific… | — | wordfence |
| 4d6d394e-a8e7-4b12-b2ed-7d1495643106 | < 1.8.8 |
HIGH | 7.2 | The Toolset Types plugin plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 1.8.8 due to insu… | — | wordfence |
| 4d162450-32e2-4366-b442-95f4f7b8f828 | < 1.0.9 |
HIGH | 7.2 | The Toast Mobile Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… | — | wordfence |
| 4d09e2fd-ccbb-49a8-9d34-8ede87429428 | < 4.2.0 |
HIGH | 7.2 | The Houzez Theme - Functionality plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 4.2… | — | wordfence |
| 4cb5837a-665d-4edb-ac8c-a6499b510817 | < 2.4.6 |
HIGH | 7.2 | The JobWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.5 due … | — | wordfence |
| 4cb02d7c-5014-46e9-9d4c-c207e58a1b0b | < 1.7.3 |
HIGH | 7.2 | The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact for… | — | wordfence |
| 4ca4fa28-53b0-4bc4-99f8-fa6dfa14d500 | < 2.4.7 |
HIGH | 7.2 | The Email Log WordPress plugin before 2.4.7 does not properly validate, sanitise and escape the "orderby" and "order" GE… | — | wordfence |
| 4c65519c-06f6-4303-9d22-980dbe36f0b6 | < 2.0.2 |
HIGH | 7.2 | The Builderall Builder for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u… | — | wordfence |
| 4c4f2d9d-d34c-45dd-aff8-ca9bbe808b5a | < 11.2.0.1 |
HIGH | 7.2 | The PixelYourSite β Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Stored Cross-Site Scrip… | — | wordfence |
| 4c437d0f-521a-431f-8c31-a73ff6e9367d | < 5.5.1 |
HIGH | 7.2 | The LatePoint β Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →