Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 422 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ef9010e3-f060-4bef-b62b-4a648f5e5577 | < 1.7.6 |
MEDIUM | 6.8 | The Zombify plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5. This is du… | — | wordfence |
| ee792903-3b55-4f1d-bba1-59ea3f1826a1 | < 3.2 |
MEDIUM | 6.8 | The Library Management System β Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via… | — | wordfence |
| ea56f0a1-7359-4beb-aae6-e2a3757ec8cd | < 4.0.0 |
MEDIUM | 6.8 | The Enable Media Replace plugin for WordPress is vulnerable to path traversal when renaming files in versions up to, and… | — | wordfence |
| e82cdfab-8090-4979-81b6-5b860e9ae187 | < 2.1.1 |
MEDIUM | 6.8 | Authenticated (administrator or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Hover Effect… | — | wordfence |
| dbd76c3d-028a-48e3-9a80-1a8da934d097 | < 1.2 |
MEDIUM | 6.8 | Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugi… | — | wordfence |
| ce2b4f93-93a6-480f-a877-ca47bd133bb6 | < 5.2.9 |
MEDIUM | 6.8 | Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a… | — | wordfence |
| ca98fbc6-8cfa-4997-8a46-344afb75a97e | < 7.2.6 |
MEDIUM | 6.8 | The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.2.5 v… | — | wordfence |
| c9205896-487d-4b8f-84cf-7ba16e1205e3 | < 1.9.2 |
MEDIUM | 6.8 | The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege… | — | wordfence |
| c0e53aa4-9acf-4501-9b5e-b7694851fc63 | < 2.2 |
MEDIUM | 6.8 | Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Popup Box plugin … | — | wordfence |
| ba4e982d-b8ac-4407-97b0-c725b8f43bbd | MEDIUM | 6.8 | The CaPa Protect WordPress plugin through 0.5.8.2 does not have CSRF check in place when updating its settings, which co… | — | wordfence | |
| a9992d0d-7c6e-4184-8f48-1515d50cc028 | < 3.4.2.1 |
MEDIUM | 6.8 | The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i… | — | wordfence |
| a8163dc0-e380-4a0b-bd18-34a3e80ca3dd | < 2.4.5 |
MEDIUM | 6.8 | The VR Calendar plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.4. This… | — | wordfence |
| a626dfd4-d8c3-4cd1-a624-bae719bea93a | < 1.0.173 |
MEDIUM | 6.8 | The Music Player for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting several parameters in… | — | wordfence |
| a2ad2c0d-542e-4b40-91a8-19b27297545e | < 1.7.5.5 |
MEDIUM | 6.8 | The Contact Form by WPForms plugin for WordPress is vulnerable to Directory Traversal via email template paths in versio… | — | wordfence |
| 9d8304bf-bec2-4fcf-9fe2-46b626b3dae9 | < 2.9.13 |
MEDIUM | 6.8 | The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, … | — | wordfence |
| 98085a23-0cb6-442a-a28a-cb5c2890b60d | < 4.0.2 |
MEDIUM | 6.8 | The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the j… | — | wordfence |
| 81b4302f-1a2f-49f4-8bfc-a511604dc51b | < 1.8 |
MEDIUM | 6.8 | The BP Email Assign Templates plugin for WordPress is vulnerable to unauthorized loss of data due to insufficient valida… | — | wordfence |
| 7f559d7f-3faf-4549-b529-f4db03dce2dd | < 5.2.5 |
MEDIUM | 6.8 | The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Server-Side Request Forgery… | — | wordfence |
| 76c38826-4d49-4204-b6b6-b01d01373fa9 | < 1.8.24 |
MEDIUM | 6.8 | The Photo Gallery by 10Web β Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all… | — | wordfence |
| 7047d53e-c9e4-46f9-8b5f-3489a1fb7e97 | < 1.1.6 |
MEDIUM | 6.8 | The Database Management tool β Adminer plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to… | — | wordfence |
| 6ed9a567-fde4-4b6f-81c1-423c5cbba0a9 | < 5.8 |
MEDIUM | 6.8 | WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database… | — | wordfence |
| 6aa0dfdf-95b0-48a2-8281-1872b99b87d6 | < 4.5.98 |
MEDIUM | 6.8 | The Download Monitor plugin for WordPress is vulnerable to arbitrary file downloads due to not verifying that downloaded… | — | wordfence |
| 4c72abf9-f63d-4460-8c9b-10e3f65b71ba | < 5.8.2 |
MEDIUM | 6.8 | The WP Scraper plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5… | — | wordfence |
| 41a362cf-e27e-436a-85f1-7c48e2e098eb | < 5.4.27 |
MEDIUM | 6.8 | The Woffice Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation … | — | wordfence |
| 3be1a1af-baab-4e57-a2c7-5e6963f986cc | < 1.3.9 |
MEDIUM | 6.8 | The Post to CSV by BestWebSoft plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →