Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 423 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 3b515142-4e04-4570-b5cb-18261974c659 | < 4.4.7 |
MEDIUM | 6.8 | Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <… | — | wordfence |
| 3b497bc0-bf47-43c7-9d5f-8e130dd0bab2 | < 3.1.9 |
MEDIUM | 6.8 | The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.… | — | wordfence |
| 38d5d951-588f-4808-b691-5105021eb1e8 | < 1.1.27 |
MEDIUM | 6.8 | The 10WebSocial plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and incl… | — | wordfence |
| 371deb9d-707f-47e4-96d7-1a287926b536 | < 3.7.34 |
MEDIUM | 6.8 | In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScr… | — | wordfence |
| 314520d5-bd9d-46c1-b903-5e5cb3bb3417 | < 6.5.8 |
MEDIUM | 6.8 | The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vuln… | — | wordfence |
| 25baf78e-e9bc-421b-8a66-9571ac3625c3 | < 6.9.10 |
MEDIUM | 6.8 | The Blog2Social plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 6.9… | — | wordfence |
| 21e3d4a5-aaf3-4f42-8868-cd8c9bccd026 | < 1.2.13 |
MEDIUM | 6.8 | The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functio… | — | wordfence |
| 105dcbbb-9ee2-4a5a-9b65-bbac931d1080 | < 2.0 |
MEDIUM | 6.8 | The Wp Social plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.9.0. This i… | — | wordfence |
| fb56c071-d7b9-40e0-8cc5-2dd48c93b8cf | MEDIUM | 6.6 | The Contact Form Maker plugin for WordPress is vulnerable to blind SQL Injection in versions before 1.13.23 due to insuf… | — | wordfence | |
| fab8d770-2add-4470-980b-b1ea84b7ab7e | < 2.3.4 |
MEDIUM | 6.6 | The WebToffee WooCommerce Product Feeds – Google Shopping, Pinterest, TikTok Ads, & More plugin for WordPress is vulne… | — | wordfence |
| f922ea86-5876-40ce-82ee-fb2b6dbddf17 | MEDIUM | 6.6 | The Sendit WP Newsletter plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘id_lista’ par… | — | wordfence | |
| f833e236-2ca6-49bc-9c98-cce06a47f1b1 | < 4.8.7 |
MEDIUM | 6.6 | The Maps plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.8.6 via deserial… | — | wordfence |
| f728cc5e-7330-4dda-b5f7-55c33def6f02 | < 1.2.1 |
MEDIUM | 6.6 | The Interactive Polish Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings i… | — | wordfence |
| f2967b6a-38e1-405b-83a3-ae6ea07b8840 | < 6.6.27 |
MEDIUM | 6.6 | The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress i… | — | wordfence |
| f256518c-9a3e-4e6e-8d49-d309e397c14d | MEDIUM | 6.6 | The Bravo Translate plugin for WordPress is vulnerable to SQL Injection via multiple parameters in versions up to, and … | — | wordfence | |
| e8b62157-8c32-462f-aba7-dab137f98f32 | < 9.2.0 |
MEDIUM | 6.6 | A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) … | — | wordfence |
| e58634c3-7fcd-4885-b897-4e6a97fb06ac | < 7.59 |
MEDIUM | 6.6 | The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to… | — | wordfence |
| e48ce7d2-0c57-499a-81b6-2d9488de704c | < 3.12.8 |
MEDIUM | 6.6 | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to … | — | wordfence |
| e31119ab-963d-48a4-9948-0a0dce761918 | < 1.26.13 |
MEDIUM | 6.6 | The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin … | — | wordfence |
| e2f5a49a-117a-473c-8853-ed292eece620 | < 1.9.8 |
MEDIUM | 6.6 | The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scr… | — | wordfence |
| e1f0ec5c-6853-4df9-816a-1790f3dc86e0 | < 5.9.1 |
MEDIUM | 6.6 | The WooCommerce Payments plugin for WordPress is vulnerable to SQL Injection via the ‘currency', 'currency_is', and 'c… | — | wordfence |
| e0b8c24b-3e51-4637-9d8e-da065077d082 | < 3.1.4 |
MEDIUM | 6.6 | The Advanced Database Cleaner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and incl… | — | wordfence |
| e0a294c5-dc2f-4739-9519-ae2a1268ff55 | MEDIUM | 6.6 | The tweet_info function in class/__functions.php in the SecureMoz Security Audit plugin 1.0.5 and earlier for WordPress … | — | wordfence | |
| e09f8e0a-ff68-41be-b91a-5c6951def3f3 | MEDIUM | 6.6 | The uListing plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.0 via dese… | — | wordfence | |
| df045b6c-ce8a-494e-a023-ed8165b0634c | < 1.6.20 |
MEDIUM | 6.6 | The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →