Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 406 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 16ac73ae-6a0a-4c9b-8830-e0745061e587 | < 2.10.4 |
HIGH | 7.2 | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all vers… | — | wordfence |
| 168e7eac-21ad-43ca-93d1-73c38e12bc29 | < 3.4.5 |
HIGH | 7.2 | The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP Referer header in versions … | — | wordfence |
| 1664fef3-6416-4678-9ee7-bed2184d7490 | < 4.0.4 |
HIGH | 7.2 | The Simple Membership plugin for WordPress is vulnerable to time-based SQL Injection via the 's' and 'status' parameters… | — | wordfence |
| 1653c4e0-c5e5-44c6-a84d-cdd070696ac4 | HIGH | 7.2 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor… | — | wordfence | |
| 163fc78a-753e-4aa4-80d5-1b2a5f68e65a | HIGH | 7.2 | The Flaming Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including… | — | wordfence | |
| 1630129e-d983-4c44-92a4-357e1e471c9a | < 13.3.0 |
HIGH | 7.2 | The Free Gifts for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … | — | wordfence |
| 162dff28-94ea-4a47-a6cb-a13317cf1a04 | < 17.0.18 |
HIGH | 7.2 | The Shield Security plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including, … | — | wordfence |
| 162a194c-a7de-44c4-a659-8188e303b6a2 | < 3.6.5 |
HIGH | 7.2 | The WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads via the tax rate importer due to missing fi… | — | wordfence |
| 15e90f19-e4cb-4096-8192-85d4f1f5ec24 | HIGH | 7.2 | The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Sto… | — | wordfence | |
| 15d9817c-910d-4ce1-a5fb-67a2b6580e16 | < 1.3.0 |
HIGH | 7.2 | The Injection Guard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via malicious query parameter name… | — | wordfence |
| 15ce2e54-ca5a-4dbc-9795-6e989e85b330 | < 2.4.4 |
HIGH | 7.2 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to miss… | — | wordfence |
| 15c35ed2-a614-4cac-8a2e-b1a2417919d7 | < 1.1 |
HIGH | 7.2 | Cross-site scripting (XSS) vulnerability in popup.php in the Simple Popup Images plugin for WordPress allows remote atta… | — | wordfence |
| 15c2cc20-8d10-4e77-8009-df91e171183f | < 9.7.2 |
HIGH | 7.2 | The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Arbitrary Options Update in versions up to, and i… | — | wordfence |
| 15b0cf88-cbb1-4264-af89-302822089284 | < 1.1.1 |
HIGH | 7.2 | The WP Gravity Forms Constant Contact Plugin plugin for WordPress is vulnerable to Open Redirect in all versions up to, … | — | wordfence |
| 1575f0ad-0a77-4047-844c-48db4c8b4e91 | < 3.3.18 |
HIGH | 7.2 | The Multiple Page Generator Plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order par… | — | wordfence |
| 15679ce4-984a-4933-86c5-c8349b03abf9 | < 1.2.6.5 |
HIGH | 7.2 | The Contact Form 7 Database Addon plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, … | — | wordfence |
| 155f765c-65ab-443a-a4b7-50d916e2903c | < 3.4.1 |
HIGH | 7.2 | The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Remote Code Execution in all versions u… | — | wordfence |
| 1525e1c9-4b94-4f9f-92c5-fc69fe000771 | < 2.1.3 |
HIGH | 7.2 | The WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions u… | — | wordfence |
| 1500c72a-0621-4f97-9cab-0c9c8abeaf8f | < 2.6.0 |
HIGH | 7.2 | The File Manager Advanced Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an… | — | wordfence |
| 14ebc642-ebe4-4493-859b-22192bc5b10d | < 1.1.8 |
HIGH | 7.2 | The GMap Targeting plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… | — | wordfence |
| 14acb770-9a32-4308-993d-a3d3dec91f78 | < 3.6.8 |
HIGH | 7.2 | The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to Reflected Cros… | — | wordfence |
| 14958861-305e-4a9b-b428-de204cd6781e | < 2.34.0 |
HIGH | 7.2 | The 404 Solution plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up … | — | wordfence |
| 14759eb0-455f-4b7d-abab-4e4d89b32bb1 | HIGH | 7.2 | The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… | — | wordfence | |
| 142bcbdd-7495-49be-a5b3-8ba1674cd64d | HIGH | 7.2 | SQL injection vulnerability in the All Video Gallery (all-video-gallery) plugin 1.2 for WordPress allows remote authenti… | — | wordfence | |
| 1419f089-7656-43a1-aeee-c33eef604c84 | < 2.1.1 |
HIGH | 7.2 | The Ultimate Product Catalog plugin for WordPress is vulnerable to generic SQL Injection via the Catalogue_ID, SubCateg… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →