Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 416 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ad953bc7-5747-4936-b702-37386299369e | < 1.1.2 |
HIGH | 7.1 | The Pop-up plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the function … | — | wordfence |
| aae57fed-1003-4b3a-8489-cfc85c250a04 | < 1.1.4 |
HIGH | 7.1 | The Videos on Admin Dashboard plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 1.1.4 due to… | — | wordfence |
| aacd4a33-499d-4630-a0fb-8a1acfcfb7dd | HIGH | 7.1 | The WP Code Highlight.js plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.… | — | wordfence | |
| aa5c23ed-7239-40e1-a795-1ae8d4c2d6c8 | < 2.7.3 |
HIGH | 7.1 | The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing … | — | wordfence |
| aa2bd74a-563a-4a2d-b1d7-b3678db82b00 | < 6.0.10 |
HIGH | 7.1 | The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple paramet… | — | wordfence |
| a7e24341-b085-4412-aa7b-42712cd94f35 | < 1.1 |
HIGH | 7.1 | The Simple Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in version… | — | wordfence |
| a7c32efa-1872-4302-a947-dc0005080e55 | HIGH | 7.1 | The Citizen Space plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘path’ parameter in v… | — | wordfence | |
| a72e60d7-6019-4d88-88f4-22ec4dedbdd8 | < 0.1.6.7 |
HIGH | 7.1 | Multiple cross-site scripting (XSS) vulnerabilities in pages/3DComplete.php in the WooCommerce SagePay Direct Payment Ga… | — | wordfence |
| a4c0180e-e3f0-42a3-9f97-735b22c1260c | < 1.9.9.5.2 |
HIGH | 7.1 | The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file de… | — | wordfence |
| a1eda885-7e10-4294-9748-5359efd51754 | HIGH | 7.1 | The Mega Addons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the vc_s… | — | wordfence | |
| a0413f69-7251-4c01-b2e0-c8638d797652 | HIGH | 7.1 | The AMP ToolBox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in vers… | — | wordfence | |
| 9ed8e24d-6bd0-4638-9031-997ce2228fad | < 2.1.2 |
HIGH | 7.1 | The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.… | — | wordfence |
| 9df45c8e-c040-4031-9c51-4c43d12f08b0 | < 4.7.20 |
HIGH | 7.1 | Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing iss… | — | wordfence |
| 9dd71a06-b3b5-431a-b6da-3b7db3a3907c | < 2.5.1 |
HIGH | 7.1 | The Plugin Central plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘file' and 'name' para… | — | wordfence |
| 9cfbafce-ba3b-477f-ad8d-ca4e57332f0b | < 1.7.2 |
HIGH | 7.1 | The WangGuard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions be… | — | wordfence |
| 9b90bf09-639c-497c-a58e-3972250db1e4 | HIGH | 7.1 | The Manage Upload Limit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the upload_limit parame… | — | wordfence | |
| 9a85cad9-bcb8-417d-a80b-3334a3ef77a2 | HIGH | 7.1 | The Easy Filtering plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and inclu… | — | wordfence | |
| 9a475017-ef45-4614-bdc6-ddd619b8caf3 | < 3.4.1 |
HIGH | 7.1 | The WP-Stateless – Google Cloud Storage plugin for WordPress is vulnerable to unauthorized loss of data due to a missi… | — | wordfence |
| 99721c3e-cddf-4709-aef9-92bb42e43f83 | < 2.1 |
HIGH | 7.1 | Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the Wo… | — | wordfence |
| 98527ebf-26a3-4900-84b5-3d2245783e8e | HIGH | 7.1 | The BuddyPress BP Gallery Plus plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and includi… | — | wordfence | |
| 97fc00d0-ca3d-462a-ac9f-bfac4c882cc1 | < 1.5.1 |
HIGH | 7.1 | Cross-site scripting (XSS) vulnerability in wlcms-plugin.php in the White Label CMS plugin 1.5 for WordPress allows remo… | — | wordfence |
| 97f6e03b-19ac-450b-9895-45f7d5328907 | < 6.1.3 |
HIGH | 7.1 | Multiple cross-site scripting (XSS) vulnerabilities in wppa-ajax-front.php in the WP Photo Album Plus (aka WPPA) plugin … | — | wordfence |
| 95c8722e-07c3-4728-8723-4d4a6188fe5e | < 1.2.6 |
HIGH | 7.1 | The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing cap… | — | wordfence |
| 943668eb-0185-4029-9459-f99141bf84cf | < 3.1.2 |
HIGH | 7.1 | The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is… | — | wordfence |
| 9269e358-83cb-42e7-a30d-79f1504e576c | < 2.8.3 |
HIGH | 7.1 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Facebook Like Box (cardoza-facebook-like-box) plugin b… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →