Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 405 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 197449f5-9304-49df-9261-a354145fc00e | < 1.15.41 |
HIGH | 7.2 | The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box… | — | wordfence |
| 194a4dd0-9cd2-477b-8926-360f8a8a0a0f | HIGH | 7.2 | The File Manager Plugin For WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t… | — | wordfence | |
| 1941f1e7-c65f-4894-8de7-1aeacf35fc69 | HIGH | 7.2 | The EONSR AEO Agent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence | |
| 18ff2556-9e20-42f6-a8fb-b81473c42576 | < 3.9.16 |
HIGH | 7.2 | The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Arbitrary File Upload due to insuffi… | — | wordfence |
| 18f16148-b4a8-4f89-af0d-c0baba8f9ccf | < 3.8.1 |
HIGH | 7.2 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in ve… | — | wordfence |
| 18d1ba80-ddf6-4076-bc78-78647b964bcf | HIGH | 7.2 | The CataBlog plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.7.0. T… | — | wordfence | |
| 18a37063-31aa-4b1f-b1a5-1ea921a20686 | < 4.4.18 |
HIGH | 7.2 | The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization… | — | wordfence |
| 188c4417-962a-4b28-b215-1c567b39ba7a | < 2.0.4 |
HIGH | 7.2 | The Nexter Extension plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.3… | — | wordfence |
| 188b6da2-1d4f-44af-82e1-a642170bcb36 | HIGH | 7.2 | The Edit domain functionality in the WP Domain Redirect WordPress plugin through 1.0 has an `editid` parameter which is … | — | wordfence | |
| 186180ed-321f-4618-8828-65b93fa054a4 | HIGH | 7.2 | The Theme Demo Import plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.1… | — | wordfence | |
| 184b9ae4-945a-4602-99da-679ff9db3029 | < 6.0.1.1 |
HIGH | 7.2 | The RegistrationMagic β User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to … | — | wordfence |
| 183282c6-2069-4fb5-acbd-539aea265d74 | < 2.0.13 |
HIGH | 7.2 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… | — | wordfence |
| 18003103-3a14-4cbc-8bed-87a8ab050308 | < 26.1.1 |
HIGH | 7.2 | The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery β Upload, Vote, Sell via PayPal or S… | — | wordfence |
| 17dd97b6-a186-4351-b08b-1eff696e25b1 | < 4.7.5 |
HIGH | 7.2 | The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameteriza… | — | wordfence |
| 17d295d6-c594-4342-8be7-37f472a6310c | < 5.10.5.2 |
HIGH | 7.2 | The TheGem (Elementor) theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… | — | wordfence |
| 1774b9b6-b98b-410c-98eb-326eda53adca | < 3.3.6.2 |
HIGH | 7.2 | Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress … | — | wordfence |
| 175eba7e-454b-4ba3-bbb5-22bd56734f5c | HIGH | 7.2 | The Skitter Slideshow plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu… | — | wordfence | |
| 172e740c-f69d-4b35-87fd-167530c5f8a0 | < 1.1.3 |
HIGH | 7.2 | The NHR Options Table Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and incl… | — | wordfence |
| 172b2191-6595-47dd-bf2d-97dc3d17e5ca | HIGH | 7.2 | The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers… | — | wordfence | |
| 17150263-261d-422f-8b36-a2981d4aaad3 | < 1.5 |
HIGH | 7.2 | The tagDiv Opt-In Builder plugin is vulnerable to Blind SQL Injection via the 'couponId' parameter of the 'recreate_stri… | — | wordfence |
| 1714c26f-775a-4ccc-8b55-e85ca1fb3a84 | < 4.0.7 |
HIGH | 7.2 | The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters b… | — | wordfence |
| 170cd2e3-e31b-452e-8c15-d44a8be7757b | < 1.2.23 |
HIGH | 7.2 | The atec Debug plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation on… | — | wordfence |
| 170bb0cc-85c0-41e2-a7e0-a082aee1e6c0 | < 1.2.7 |
HIGH | 7.2 | The Affiliate Program Suite β SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … | — | wordfence |
| 16ded5aa-c8e8-4d98-b07f-e689ad0e03c7 | HIGH | 7.2 | The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' sh… | — | wordfence | |
| 16d1eb4a-c68a-43b9-a514-d8751687709a | < 2.3.2 |
HIGH | 7.2 | The Debug Log Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →