Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 392 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4757590a-f5dc-48d6-aef1-80158f728b6e | < 2.1.0 |
HIGH | 7.2 | classes\controller\admin\modals.php in the Easy Modal plugin before 2.1.0 for WordPress has SQL injection in an untrash … | — | wordfence |
| 473ff00e-e045-4b66-b0af-89d666de4de8 | < 1.1.2 |
HIGH | 7.2 | The Crelly Slider plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter found in the ~/wordpress/ad… | — | wordfence |
| 47337214-9cc3-4b12-bb71-9acbab3649b7 | < 2.4.2 |
HIGH | 7.2 | The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to… | — | wordfence |
| 470d91c1-bcde-4497-a558-35bc0156ddca | < 4.1.5 |
HIGH | 7.2 | Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page with… | — | wordfence |
| 4707fcf6-ad11-4ffc-ba56-30f6571e3d9e | < 6.8.1 |
HIGH | 7.2 | The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipula… | — | wordfence |
| 4701d3b2-1bf4-430d-b8c8-95da5d699a89 | < 1.6.7 |
HIGH | 7.2 | The CRT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… | — | wordfence |
| 46c988ff-9cc5-4f2b-a3dd-06eaef5a7919 | < 3.28.24 |
HIGH | 7.2 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acff' parame… | — | wordfence |
| 469a9c8a-0708-4c93-99d8-e9157a1f91f5 | < 1.7.49 |
HIGH | 7.2 | The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-… | — | wordfence |
| 46706adb-fc2e-47d4-b1ff-748b89b1decf | HIGH | 7.2 | SQL injection vulnerability in the administration panel in the DMSGuestbook 1.7.0 plugin for WordPress allows remote aut… | — | wordfence | |
| 465f2fd1-9eb3-43ca-8acc-74acf6bcde1a | HIGH | 7.2 | The Demo Import Kit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence | |
| 465f29c0-99b9-4f7d-9817-3d3a49a2d943 | < 1.4.7 |
HIGH | 7.2 | The 'Live Chat with Messenger Customer Chat' plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… | — | wordfence |
| 463d0ecd-408c-4ccf-9f2c-8bff3deca213 | < 1.5.15 |
HIGH | 7.2 | The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file … | — | wordfence |
| 4624c43b-6c5f-48c5-bfe4-26ec6d7de418 | HIGH | 7.2 | SQL injection vulnerability in the stripshow-storylines page in the stripShow plugin 2.5.2 for WordPress allows remote a… | — | wordfence | |
| 46150f65-e662-4539-ae99-eaee297a2608 | < 1.5.1 |
HIGH | 7.2 | The Seriously Simple Stats plugin for WordPress is vulnerable to SQL Injection via the order_by parameter in versions up… | — | wordfence |
| 45ef9293-dd94-490a-8cb8-df6bccf4739a | < 5.0.0 |
HIGH | 7.2 | The Dynamic Pricing With Discount Rules for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… | — | wordfence |
| 45bfa9fb-f35b-4fd4-8553-cf87bf69df6b | < 5.1.57 |
HIGH | 7.2 | The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form page href para… | — | wordfence |
| 45690747-0b8d-4e2e-8dd0-07c12791c064 | < 3.0.13 |
HIGH | 7.2 | The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to… | — | wordfence |
| 4550681f-d115-4451-9839-7862b84714fe | < 3.6.3 |
HIGH | 7.2 | The BSK Forms Blacklist plugin for WordPress is vulnerable to generic SQL Injection via the 'order' and 'orderby' parame… | — | wordfence |
| 4532cb38-453b-460c-879d-6f0e1caacafc | < 6.0.6.3 |
HIGH | 7.2 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … | — | wordfence |
| 4528f9a1-7027-4aa9-b006-bea84aa19c84 | < 1.40.4 |
HIGH | 7.2 | The EditorsKit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the '… | — | wordfence |
| 44fde2c8-8012-4ede-8455-08b8e744ba36 | < 3.1.15 |
HIGH | 7.2 | Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting in various versions due to insufficient inp… | — | wordfence |
| 44f3b2e4-c537-4369-b2d6-39fbc6cb8e08 | < 5.2.2 |
HIGH | 7.2 | The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all v… | — | wordfence |
| 4483fb33-3815-4ec9-9df4-a971844f4855 | < 2.0.6 |
HIGH | 7.2 | The Woocommerce Vietnam Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom shippi… | — | wordfence |
| 446b160a-299e-4f91-bd49-02a7a16b6e5f | < 2.5.9 |
HIGH | 7.2 | Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attacke… | — | wordfence |
| 44373541-adc5-4aa0-abde-0693f2760afb | < 9.9.4 |
HIGH | 7.2 | The RSVPMaker plugin for WordPress is vulnerable to SQL Injection via the ‘$email’ variable in versions up to, and i… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →