Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 403 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 1f9d8bbe-205f-44b6-a0c6-89b9135e6363 | < 17.0.5 |
HIGH | 7.2 | The Contest Gallery – Files Upload and Contest Plugin for WordPress plugin for WordPress is vulnerable to SQL Injectio… | — | wordfence |
| 1f7e2323-42e9-4cc7-b3f4-d133e0073b7b | < 2.8.6 |
HIGH | 7.2 | The CM Download Manager plugin for WordPress is vulnerable to arbitrary file uploads because it allows administrators to… | — | wordfence |
| 1f533dbd-4dd0-48ec-b083-e6284acab067 | < 4.9.3 |
HIGH | 7.2 | The Slimstat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI in versions up … | — | wordfence |
| 1f37ed0e-3e03-4f00-9967-16047beab1cf | HIGH | 7.2 | The MSync plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.0 due to insufficien… | — | wordfence | |
| 1f34302c-b08c-4542-9aa9-c66fe1f0288d | < 3.1.0 |
HIGH | 7.2 | The WP-CopyProtect plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘CopyProtect_nrc_text’ … | — | wordfence |
| 1ed98565-3f86-46c0-a696-13d678f2d523 | < 1.0.27 |
HIGH | 7.2 | The Rank Math SEO is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including 1.0.26. | — | wordfence |
| 1ed6c1c2-8fbd-4bcb-854a-492d1060364b | < 2.8.15 |
HIGH | 7.2 | The System Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includ… | — | wordfence |
| 1ec907bc-bd10-4dc5-be35-4f2aaf5ef444 | < 20260110 |
HIGH | 7.2 | The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Store… | — | wordfence |
| 1ec45848-33b1-4088-ba06-9a12d291120e | < 3.5.4 |
HIGH | 7.2 | The Better WP Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inc/secure.php' file i… | — | wordfence |
| 1ec3cc3e-c11b-43b6-9dd0-caa5ccfb90c8 | < 1.17.0 |
HIGH | 7.2 | The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Re… | — | wordfence |
| 1e84fbbf-05b0-497b-81d8-1b029d24cddd | < 5.11.1 |
HIGH | 7.2 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 did not properly… | — | wordfence |
| 1e72d5c7-c601-4775-a825-4786bbd1b5f0 | < 2.04 |
HIGH | 7.2 | The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. Thi… | — | wordfence |
| 1e518d40-deda-438a-9787-b3cf7faad7a4 | < 2.4.6 |
HIGH | 7.2 | The Import WP – Import and Export WordPress data to XML or CSV files plugin for WordPress is vulnerable to arbitrary f… | — | wordfence |
| 1e35eb83-716e-4177-99ba-24a884725265 | < 2.169 |
HIGH | 7.2 | The Login Security, FireWall, Malware removal by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scrip… | — | wordfence |
| 1e273170-9c37-4f34-ab46-097d3eac47df | < 1.4.5 |
HIGH | 7.2 | The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.4.5 due to insuff… | — | wordfence |
| 1e223e0e-959f-498e-8c0e-daae36bd28cb | < 2.7.1 |
HIGH | 7.2 | The WP Easy Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 'galleryId' or 'select_gallery' … | — | wordfence |
| 1e0cf512-f676-4f47-abaa-5198998376b7 | < 1.5.18 |
HIGH | 7.2 | The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custome… | — | wordfence |
| 1e0c77a6-08fd-4d54-8ecd-6e5fe0e03e14 | < 1.12.4 |
HIGH | 7.2 | The WP ERP plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in versions up to 1.12.4 due to … | — | wordfence |
| 1e0426e9-f6d8-40aa-9ceb-a3e5515ac316 | HIGH | 7.2 | An id GET parameter of the Easy Testimonial Manager WordPress plugin through 1.2.0 is not sanitised, escaped or validate… | — | wordfence | |
| 1e030085-a323-4275-848a-3c6cbc587748 | < 1.0.59 |
HIGH | 7.2 | The Timetics – Appointment Booking Calendar & Scheduling System plugin for WordPress is vulnerable to Stored Cross-Sit… | — | wordfence |
| 1defa728-9f9d-4e8f-8f6c-432c615da7f5 | < 2.2.0 |
HIGH | 7.2 | The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'a… | — | wordfence |
| 1de41980-93bb-4831-bb31-50675499f648 | < 2.2.13.1 |
HIGH | 7.2 | The Permalink Manager Lite WordPress plugin before 2.2.13.1 does not validate and escape the orderby parameter before us… | — | wordfence |
| 1d8c5b14-6a4c-4d66-85cc-b6ab3b886ff7 | < 1.6.10 |
HIGH | 7.2 | The Zippy plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ZippyC… | — | wordfence |
| 1d46033d-27aa-4d92-aa41-3547a3d17aff | < 1.6.1 |
HIGH | 7.2 | The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… | — | wordfence |
| 1d4469e4-5d99-4a56-bde8-9a0aaca7794f | HIGH | 7.2 | The 123.chat - Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and i… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →