Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 402 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 22ff4b09-063b-425e-9d59-be2e5d283186 | < 2.33.1 |
HIGH | 7.2 | The Give - Donation Plugin plugin for WordPress is vulnerable to privilege escalation due to an insufficient capability … | — | wordfence |
| 22cb2bc4-ddf1-4e23-af1c-4f59ff88e9e1 | < 1.1.3 |
HIGH | 7.2 | The Spider Calendar plugin for WordPress is vulnerable to generic SQL Injection, Cross-Site Scripting, and Parameter Pol… | — | wordfence |
| 22bcfd36-ecf9-4d2c-ac94-94ffa0340c4c | < 5.2.6 |
HIGH | 7.2 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross… | — | wordfence |
| 22a5020a-ab81-43be-b160-082347a2a2d9 | < 2.5.8 |
HIGH | 7.2 | The Custom Field Template plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2… | — | wordfence |
| 225900ea-ab59-4864-a65b-583730d2703f | < 1.4.8 |
HIGH | 7.2 | The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before usin… | — | wordfence |
| 222079a2-20f1-4d53-8420-46ccc50988a8 | < 6.83 |
HIGH | 7.2 | The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting i… | — | wordfence |
| 220b0e71-8e80-4a29-982e-259a475835fe | < 1.15.7 |
HIGH | 7.2 | The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulnerable to time-based SQL Injection via th… | — | wordfence |
| 21e06220-c8f0-4754-ba19-8df519be4038 | < 5.185.1 |
HIGH | 7.2 | The AntiSpam plugin for WordPress is vulnerable to SQL Injection via the ‘ids’ parameter in versions up to, and incl… | — | wordfence |
| 21c87602-bbe7-4fde-8ba2-031120212a8b | < 15.8 |
HIGH | 7.2 | The WP Symposium plugin for WordPress is vulnerable to blind SQL Injection in versions before 15.8 due to insufficient e… | — | wordfence |
| 21c31df6-7515-48f5-ad74-fe116e836da8 | HIGH | 7.2 | The MagicForm plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.1 due to in… | — | wordfence | |
| 213b6dec-a64d-4597-a079-8fb82df9c8b4 | < 1.3.3 |
HIGH | 7.2 | The Five Minute Webshop WordPress plugin through 1.3.2 does not properly validate and sanitise the orderby parameter bef… | — | wordfence |
| 2131e418-bd95-4bd1-868f-0bd3b4abdf78 | < 0.18.10 |
HIGH | 7.2 | The plugin Tainacan for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.18.9 due to … | — | wordfence |
| 211634f6-afc4-4841-8851-6c56a248af95 | HIGH | 7.2 | SQL injection vulnerability in the GD Star Rating plugin 1.9.22 for WordPress allows remote administrators to execute ar… | — | wordfence | |
| 2105a26a-0813-4f63-a28d-6b3bd68ea9a1 | < 3.3.66 |
HIGH | 7.2 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.3.66 due to i… | — | wordfence |
| 20eff8fc-0572-40b9-ab28-758c7ab8ed73 | < 5.3.2 |
HIGH | 7.2 | Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin… | — | wordfence |
| 20d989d9-6bf0-4f9f-acf4-b4c3452855cc | < 3.7.1 |
HIGH | 7.2 | The Custom 404 Pro plugin for WordPress is vulnerable to blind SQL Injection via the ‘path’ parameter in versions up… | — | wordfence |
| 20d30931-bfaf-47bb-9265-b326c959b871 | < 1.7.29 |
HIGH | 7.2 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and inc… | — | wordfence |
| 209019bd-b214-4389-a972-42e38d501203 | < 2.6.4 |
HIGH | 7.2 | The YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service plugin for WordPr… | — | wordfence |
| 2085c9a3-1cc7-4750-875e-d20c7f94bb78 | < 7.3.5 |
HIGH | 7.2 | The Quiz And Survey Master plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up to,… | — | wordfence |
| 20720912-6bfd-4df1-97c7-7025c16d7a0f | < 4.0.2 |
HIGH | 7.2 | The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'st_user_title' paramet… | — | wordfence |
| 206eee58-af07-426d-8c11-7a5e5ec52ddc | < 3.1 |
HIGH | 7.2 | The Classic Addons – WPBakery Page Builder plugin for WordPress is vulnerable to Local File Inclusion in versions up t… | — | wordfence |
| 2046c6cf-32fa-4fac-a4bc-00f11f739d14 | < 1.8.3 |
HIGH | 7.2 | The Website File Changes Monitor plugin for WordPress is vulnerable to SQL Injection via the ‘path' parameter in versi… | — | wordfence |
| 2013b9ac-7853-40b9-8bef-7207ccd58eb1 | < 5.5.2 |
HIGH | 7.2 | The miniorange otp verification plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… | — | wordfence |
| 1fe257e6-4bdf-49ef-adbb-f82ce378e3e7 | < 2.4.12 |
HIGH | 7.2 | The Five Star Restaurant Reservations plugin for WordPress is vulnerable to authorization bypass due to a missing capabi… | — | wordfence |
| 1fb05281-205f-4d9c-aac9-2b37e069a6fb | < 3.2.16 |
HIGH | 7.2 | The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via S… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →