Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 391 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4bc38197-3827-4c0e-a0a8-42d55f50605f | < 1.2.0 |
HIGH | 7.2 | The Uploading SVG, WEBP and ICO files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t… | — | wordfence |
| 4b8462ed-6228-42e8-be92-8e02ecd55ae5 | < 1.7.6 |
HIGH | 7.2 | The SiteGround Email Marketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … | — | wordfence |
| 4b24b3d2-589f-47b2-bcdd-bebc87cafeda | < 2.6.3 |
HIGH | 7.2 | The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up … | — | wordfence |
| 4af0e984-896d-4938-a870-8a50644d4823 | < 2.1.5 |
HIGH | 7.2 | The WC Price History for Omnibus plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inclu… | — | wordfence |
| 4ad3ed6b-19d4-47c7-a56c-54092c767fe9 | < 2.3.0 |
HIGH | 7.2 | The FluentSMTP β WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for … | — | wordfence |
| 4a3cae01-620d-405e-baf6-2d66a5b429b3 | < 3.16.2 |
HIGH | 7.2 | The GiveWP β Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to time-based SQL Injection v… | — | wordfence |
| 4a18cb4a-8458-4337-843e-c3278028230f | < 2.0.2 |
HIGH | 7.2 | The Lead Form Builder & Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… | — | wordfence |
| 4a0e962b-b6a0-4179-91d0-5ede508a9895 | < 1.5.0 |
HIGH | 7.2 | The WP Reroute Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions … | — | wordfence |
| 49df1ed8-1c2b-4a04-b33a-1fe95fe12172 | < 1.13.19 |
HIGH | 7.2 | The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.13.… | — | wordfence |
| 49dc267a-48cf-487f-bedc-fd892666e9a0 | < 9.2.3 |
HIGH | 7.2 | The NEX-Forms β Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting … | — | wordfence |
| 49d3d11d-76b1-4242-921f-631e2e270ebe | < 1.11.5 |
HIGH | 7.2 | The Z-Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … | — | wordfence |
| 499a1892-12b7-49d5-b65f-4f53a968a23a | < 3.3.18 |
HIGH | 7.2 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e… | — | wordfence |
| 4973cef3-dddf-4eb5-99f4-c23a0e162fd6 | < 6.7.25 |
HIGH | 7.2 | The WCFM β Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress … | — | wordfence |
| 495804c2-1870-4d64-9a5a-166b01ed7b0e | < 1.5.3 |
HIGH | 7.2 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Script… | — | wordfence |
| 49150180-9de0-4318-b21b-779daaeb7a52 | < 18.3 |
HIGH | 7.2 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and in… | — | wordfence |
| 48e3976a-5dfc-44f5-8d01-0bd1b68575be | HIGH | 7.2 | A c GET parameter of the Comment Highlighter WordPress plugin through 0.13 is not properly sanitised, escaped or validat… | — | wordfence | |
| 488bafe4-746a-4531-95ac-30d17ace2239 | < 1.4.07 |
HIGH | 7.2 | The Calendar Event Multi View plugin for WordPress is vulnerable to authorization bypass due to a missing capability che… | — | wordfence |
| 487185ed-d5ff-4658-9210-958e3ba2fe91 | < 8.0.4 |
HIGH | 7.2 | Multiple plugins and/or themes for WordPress are vulnerable to Remote Code Execution in various versions. This makes it … | — | wordfence |
| 4869dcd8-9b21-4751-8682-10f1aede14a3 | HIGH | 7.2 | The Flickr Shortcode Importer plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includin… | — | wordfence | |
| 48421787-9dc1-48ea-892b-bb43b2a6c4da | < 1.3 |
HIGH | 7.2 | The Import Users from CSV plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includin… | — | wordfence |
| 481be4ab-f8df-4080-b87b-24e4d40f83b1 | < 1.5.12 |
HIGH | 7.2 | The VOD Infomaniak plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… | — | wordfence |
| 48075ef0-b3c5-487b-93c2-d3e630742fe4 | HIGH | 7.2 | A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/camp… | — | wordfence | |
| 47a10dd4-515c-42d9-82ea-c84f8f7574c5 | < 5.0.11 |
HIGH | 7.2 | The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in … | — | wordfence |
| 47940179-1a34-48d3-a6fc-81f2d3cd2670 | HIGH | 7.2 | The Arlo theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.0.3 due to… | — | wordfence | |
| 47938357-7d51-4d62-a08c-4b2bf3f3a062 | < 5.2.4 |
HIGH | 7.2 | The Wordfence Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '$_SERVER['HTTP_HOST']… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →