Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 407 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 13dbda83-d309-4723-9876-1b19f5ab4620 | < 1.2.10 |
HIGH | 7.2 | The Spam Protect for Contact Form 7 plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 1.… | — | wordfence |
| 13c9a71f-ec0a-4d4a-be08-787aa22a0fae | < 1.2.25 |
HIGH | 7.2 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameter… | — | wordfence |
| 13be8a88-bcd3-4ce9-9538-e93c78323456 | < 4.9.0 |
HIGH | 7.2 | The EAN for WooCommerce plugin for WordPress is vulnerable to arbitrary options updates n all versions up to, and includ… | — | wordfence |
| 13a96e78-c83c-4ff1-a751-3dbaeb683d9d | < 1.8.9 |
HIGH | 7.2 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spe… | — | wordfence |
| 13101551-d62e-4b27-9156-5b3d022f0e55 | < 9.9.4 |
HIGH | 7.2 | The RSVPMaker plugin for WordPress is vulnerable to SQL Injection via the 'delete' parameter in versions up to, and incl… | — | wordfence |
| 12fe64ad-2998-4f41-b8d7-aa5921b0d0d9 | < 1.69.234 |
HIGH | 7.2 | The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to Stored Cross-Site Scripti… | — | wordfence |
| 12f3dc64-322d-4015-8c57-eaa41c9a1829 | < 2.2.16 |
HIGH | 7.2 | The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… | — | wordfence |
| 12b1b1b4-a62f-451e-a78d-c1d85202a4cf | < 5.3.4 |
HIGH | 7.2 | The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via room… | — | wordfence |
| 12a9fbe8-445a-478a-b6ce-cd669ccb6a2d | < 1.1.3 |
HIGH | 7.2 | The Icons Font Loader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… | — | wordfence |
| 12817b77-17d0-418c-a9a1-87d0057da90e | < 1.6.12.4 |
HIGH | 7.2 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to S… | — | wordfence |
| 1268bdb9-7f80-4fdc-a95a-d51b0ab83e17 | < 4.2 |
HIGH | 7.2 | The The School Management – Education & Learning Management plugin for WordPress is vulnerable to SQL Injection via an… | — | wordfence |
| 125e7ea3-574a-4760-b10b-7a98d94c87a5 | < 1.6.0 |
HIGH | 7.2 | The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the id para… | — | wordfence |
| 124f2b72-d8da-46ba-844f-e9cc01441702 | < 8.5.0 |
HIGH | 7.2 | The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cro… | — | wordfence |
| 120514af-41d8-49ca-be87-28c7d4777fee | HIGH | 7.2 | Multiple cross-site scripting (XSS) vulnerabilities in cryptographp/admin.php in the Cryptographp 1.2 and earlier plugin… | — | wordfence | |
| 120313be-9f98-4448-9f5d-a77186a6ff08 | < 1.3.3 |
HIGH | 7.2 | The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validatio… | — | wordfence |
| 11f883d2-c183-4cc9-a330-6c50610a5c39 | < 1.0.8 |
HIGH | 7.2 | The Shariff Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shariff_image' paramete… | — | wordfence |
| 11a469e8-d6af-4ad7-98aa-9f74d0318947 | < 16.9 |
HIGH | 7.2 | The User Extra Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… | — | wordfence |
| 1148b18d-7af1-41c6-bd7f-1b2d53cb44e6 | HIGH | 7.2 | The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check… | — | wordfence | |
| 11305d35-07d6-4c61-a0c7-035671229f07 | HIGH | 7.2 | The bbPress Toolkit plugin for WordPress is vulnerable to Unspecified Cross-Site Scripting in versions up to, and includ… | — | wordfence | |
| 112456a9-8bb6-4007-87da-6d0fba912498 | < 1.2.26 |
HIGH | 7.2 | The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Stor… | — | wordfence |
| 1106e7b2-eac7-459d-8eb3-fe84c76f3b67 | < 3.10.1 |
HIGH | 7.2 | The Custom 404 Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several logged parameters in al… | — | wordfence |
| 11043029-1b77-4e18-bdd8-fca2eadc6901 | HIGH | 7.2 | Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Register Plus plugin 3.5.11 and earlier for W… | — | wordfence | |
| 109a99ca-1173-4367-b8a7-c3d8cffcfcaf | < 2.4.5 |
HIGH | 7.2 | The Chatbot with ChatGPT WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up … | — | wordfence |
| 106fd83b-2ab0-4fcf-8c73-ba18ba9dbe56 | < 2.4.19 |
HIGH | 7.2 | The Kali Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.1… | — | wordfence |
| 105ae6be-2cb7-4ab2-8e4c-5d3ff84c5b9f | < 4.9.5 |
HIGH | 7.2 | The Download Monitor plugin for WordPress is vulnerable to SQL Injection via the 'limit' parameter in all versions up to… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →