Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 421 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 13f6bf06-2c24-43ac-9412-08b3d4914a21 | < 1.5.3 |
HIGH | 7.1 | Cross-site scripting (XSS) vulnerability in wp-tmkm-amazon-search.php in the wp-tmkm-amazon plugin 1.5b and earlier for … | — | wordfence |
| 13b0f306-cfd1-4c36-b694-de7968f0ae1c | < 1.0.19 |
HIGH | 7.1 | The Optinly plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJA… | — | wordfence |
| 12acf651-6476-491b-84b3-afbc6c655b17 | < 1.10.19 |
HIGH | 7.1 | The plugin Popup by Supsystic for WordPress is vulnerable to prototype pollution, which could make injecting malicious w… | — | wordfence |
| 1161f41b-1594-4b1b-8a89-44a5a5a9dca6 | < 1.0.126 |
HIGH | 7.1 | The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in u… | — | wordfence |
| 10a54a3b-db6d-45c5-9280-7042ccc17ccd | < 8.1 |
HIGH | 7.1 | The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Multiple Cross-Site Scrip… | — | wordfence |
| 1080810b-ec9a-44fb-b4da-49b28646a441 | < 1.19.21 |
HIGH | 7.1 | The FooEvents for WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improp… | — | wordfence |
| 106b31ed-d509-4551-a134-02193ab22fe1 | HIGH | 7.1 | The DASHBOARD BUILDER – WordPress plugin for Charts and Graphs plugin for WordPress is vulnerable to Cross-Site Reques… | — | wordfence | |
| 0f9d18a4-262b-4011-91e9-b29a27a76470 | < 2.1.5 |
HIGH | 7.1 | The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.4. Th… | — | wordfence |
| 0f87d37a-879f-4506-a651-8c965a558e28 | < 1.0.1 |
HIGH | 7.1 | The Thumbnail carousel slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting and Cross-Site Request F… | — | wordfence |
| 0f20c7d3-8987-4dc0-9d97-98a29adbab85 | HIGH | 7.1 | The WP Shopping Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence | |
| 0e46ac8d-89ee-4480-bb96-83f2044a4323 | < 3.0.3 |
HIGH | 7.1 | The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. Th… | — | wordfence |
| 0e43d6fc-28f1-4208-a529-f264304fe8aa | < 10.38 |
HIGH | 7.1 | The Subscribe2 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.37.… | — | wordfence |
| 0d4420bf-1095-44ca-8fa6-dd5ea11c7489 | < 1.3.32 |
HIGH | 7.1 | The Findgo theme for WordPress is vulnerable to Cross-Site Scripting in versions before 1.3.32 due to insufficient input… | — | wordfence |
| 0b6e9430-bb78-47c3-9958-4f40028c3d93 | < 5.0.5 |
HIGH | 7.1 | Cross-site request forgery (CSRF) vulnerability in the Quick Page/Post Redirect plugin before 5.0.5 for WordPress allows… | — | wordfence |
| 0b540fed-e358-485f-8c12-f2241078459a | < 2.0.0 |
HIGH | 7.1 | Cross-site request forgery (CSRF) vulnerability in bluewrench-video-widget.php in the Blue Wrench Video Widget plugin be… | — | wordfence |
| 0903521d-3b07-4539-97c9-15e6bbe2cc2e | < 9.1.05.009 |
HIGH | 7.1 | The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ par… | — | wordfence |
| 0593311a-54d7-42b2-ad5e-185938b42452 | HIGH | 7.1 | The Portfolio Gallery plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on se… | — | wordfence | |
| 0406b7a0-517d-4462-9b65-d4f708cf364d | < 2.0.11 |
HIGH | 7.1 | Multiple cross-site request forgery (CSRF) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress al… | — | wordfence |
| 02ac8b9e-bc59-4c46-9f9c-23e3b6ae615c | HIGH | 7.1 | The Picture Factory plugin for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization an… | — | wordfence | |
| 026f8d9b-a66b-4a59-8375-fba587a4eef7 | < 1.6.5 |
HIGH | 7.1 | The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable … | — | wordfence |
| 01105d96-e181-4228-b785-074a4b49ce18 | < 3.0.0 |
HIGH | 7.1 | The WP Google Map Plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting via several p… | — | wordfence |
| 00a1b66d-d81c-4539-846b-ff66301a94ca | < 4.2.6 |
HIGH | 7.1 | The SearchWP Premium plugin for WordPress is vulnerable to authorization bypass due to leaking a nonce protecting a func… | — | wordfence |
| 0089498d-c4b3-4167-8bf4-8d9f68a4cbd0 | < 1.6 |
HIGH | 7.1 | Multiple cross-site scripting (XSS) vulnerabilities in the All-in-One Event Calendar plugin 1.4 and 1.5 for WordPress al… | — | wordfence |
| 8f617090-f2cf-4ac4-8d09-c1d5c21e120d | < 1.3.8 |
MEDIUM | 6.9 | Authenticated Stored Cross-Site Scripting (XSS) vulnerability in YITH Maintenance Mode (WordPress plugin) versions <= 1.… | — | wordfence |
| 3589fd35-df91-48fb-b3be-4954f1e05656 | < 1.4.0 |
MEDIUM | 6.9 | Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in YITH Maintenance Mode (WordPress plugin) ver… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →