Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 413 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 01e8e53c-8d23-4bd3-9291-29f97df7c984 | < 1.6.0 |
HIGH | 7.2 | The WordPress Backup and Migrate Plugin β Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported … | — | wordfence |
| 01cfe0da-0ffc-4046-b58a-a31f5d10d1bd | < 1.7.7 |
HIGH | 7.2 | The WPForms Pro plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.7.6. This allows… | — | wordfence |
| 01ba4259-e76a-4876-b910-fd2688680739 | HIGH | 7.2 | The IP Blacklist Cloud plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.00 due to… | — | wordfence | |
| 01acb93b-89ae-4024-9f43-5fd14a7bd5f6 | < 30.0.7 |
HIGH | 7.2 | The Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence |
| 017f5894-be0d-4b0f-82bd-13bf7e2ff53f | < 1.0.25 |
HIGH | 7.2 | The Responsive Filterable Portfolio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ… | — | wordfence |
| 015db31a-eadf-4159-9be4-a455de791e35 | HIGH | 7.2 | The DukaPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.4 … | — | wordfence | |
| 01370a71-2611-4826-b08b-485839ca606a | < 1.1.9 |
HIGH | 7.2 | The Booking Ultra Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in ve… | — | wordfence |
| 011fad07-0235-41e1-83b5-09588dd63d50 | < 1.2 |
HIGH | 7.2 | Cross-site scripting (XSS) vulnerability in the Free Counter plugin 1.1 for WordPress allows remote attackers to inject … | — | wordfence |
| 00fa12c7-5814-45f3-a35e-363cd0920e43 | < 2.7.1.1 |
HIGH | 7.2 | The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… | — | wordfence |
| 00df02cd-b4d3-477a-86ee-aa2f9b5216e8 | < 1.8.9 |
HIGH | 7.2 | The File Manager Pro β Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type … | — | wordfence |
| 00ab5d7e-be38-42ea-befc-e1d91de13d1b | HIGH | 7.2 | The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… | — | wordfence | |
| 0099a8d7-827d-4215-9a2b-b3c268fb5e97 | < 4.9.8 |
HIGH | 7.2 | The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4… | — | wordfence |
| 0082e46d-fdbe-4ab7-bba3-0681a25d4495 | < 0.9.113 |
HIGH | 7.2 | The Migration, Backup, Staging β WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploa… | — | wordfence |
| 007ec879-7241-4dd2-9b81-93e44786bbcb | < 1.8 |
HIGH | 7.2 | The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found… | — | wordfence |
| 00687370-8374-44cc-8fd1-53b462acd061 | < 1.8.0 |
HIGH | 7.2 | The iPanorama 360 plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and… | — | wordfence |
| 00500322-0984-49f5-8a6f-8cf72d125e6a | < 2.80.8 |
HIGH | 7.2 | The WP-DBManager plugin for WordPress is vulnerable to remote code execution due to an incorrect capability check in the… | — | wordfence |
| 00323c12-151d-42e4-a85c-76400bce1ec8 | < 1.1.14 |
HIGH | 7.2 | The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" req… | — | wordfence |
| 002c6fea-4b76-47a6-9a39-1195f18aa6f6 | < 1.9.1 |
HIGH | 7.2 | The Live Scores for SportsPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… | — | wordfence |
| 00162c25-bf56-42cf-b9bd-f6435e788d3d | HIGH | 7.2 | The amr cron manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… | — | wordfence | |
| 00138875-d892-460c-b0ce-7a01335d26dc | < 3.3.8 |
HIGH | 7.2 | The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action … | — | wordfence |
| ff22c969-e580-4290-ab08-7c02b6eac938 | < 1.3.8 |
HIGH | 7.1 | The Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions before 1.3.8 due to insuff… | — | wordfence |
| fc91cae0-6d54-43f3-8c0e-d1f972573d13 | < 3.5.16 |
HIGH | 7.1 | The WP No External Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the βpageβ paramet… | — | wordfence |
| fbbd3209-7ed6-4409-a24e-9f6225cf10f5 | < 4.4 |
HIGH | 7.1 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due t… | — | wordfence |
| f7d80a23-f55d-4ab8-b139-daf5bc436d4f | < 2.7.6 |
HIGH | 7.1 | Cross-site scripting (XSS) vulnerability in captcha-secureimage/test/index.php in the SI CAPTCHA Anti-Spam plugin 2.7.4 … | — | wordfence |
| f7926afb-b441-49bf-9af2-5bfc434319e3 | < 1.0.11 |
HIGH | 7.1 | Multiple cross-site scripting (XSS) vulnerabilities in the Spider Facebook plugin before 1.0.11 for WordPress allow (1) … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →