Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 427 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 47aed582-efb6-4caf-a65b-57995907ecaa | < 2.1.4 |
MEDIUM | 6.6 | The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all… | — | wordfence |
| 477d3d7a-6028-4dd3-b713-6098bfe32832 | < 2.35.0 |
MEDIUM | 6.6 | The 404 Solution plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 2.35… | — | wordfence |
| 43b72542-623f-4ecf-892b-273cb6a8d6cf | < 2.1.12 |
MEDIUM | 6.6 | The LTL Freight Quotes – Day & Ross Edition plugin for WordPress is vulnerable to PHP Object Injection in versions up … | — | wordfence |
| 433ab82d-31ce-4386-ab1b-6d3498d7722a | < 4.1.20 |
MEDIUM | 6.6 | The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.19. This ma… | — | wordfence |
| 4284c31c-fa58-49fe-89ed-35d7b1bd6ec8 | < 19.1.5 |
MEDIUM | 6.6 | The Contest Gallery Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 d… | — | wordfence |
| 3f0ed355-b5c8-4143-b391-7436d67ba0de | < 1.20.24 |
MEDIUM | 6.6 | The E2Pdf – Export To Pdf Tool for WordPress plugin for WordPress is vulnerable to SQL Injection via an unknown parame… | — | wordfence |
| 3bc8e26f-0a35-4223-b69a-e9f0b4f13cc8 | MEDIUM | 6.6 | The Aitasi Coming Soon plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, … | — | wordfence | |
| 39ec49b4-f0f3-4ec7-b11b-ce808c025577 | < 1.1.8 |
MEDIUM | 6.6 | The Simple User Import Export plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, … | — | wordfence |
| 391f76a1-098b-4b88-be71-4270d9942c66 | < 269.2 |
MEDIUM | 6.6 | The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to PHP Object Injection in… | — | wordfence |
| 37426991-7778-4dc4-8cae-2725584fb8b8 | < 1.1.5 |
MEDIUM | 6.6 | The Icons Font Loader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… | — | wordfence |
| 360a022d-8530-48af-be34-77d6b4b5c19d | < 2.2.0 |
MEDIUM | 6.6 | The All In One Redirection plugin for WordPress is vulnerable to SQL Injection via the request URI in versions up to, an… | — | wordfence |
| 3498c871-9404-4d12-9609-16fecf218b30 | < 2.0.14 |
MEDIUM | 6.6 | The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Obj… | — | wordfence |
| 34267e02-4270-4656-a946-e4895f796786 | < 2.1.0 |
MEDIUM | 6.6 | The HT Contact Form 7 plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0… | — | wordfence |
| 32b2b8e9-aa49-4cc3-97b7-249695969461 | < 5.7.8 |
MEDIUM | 6.6 | The Media File Renamer: Rename Files (Manual, Auto & AI) plugin for WordPress is vulnerable to Remote Code Execution in … | — | wordfence |
| 304765f9-772c-4d47-b929-08fd708736ab | MEDIUM | 6.6 | The eDS Responsive Menu plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2… | — | wordfence | |
| 2f796373-7116-4fd3-9d53-5f520e6e1a0c | < 4.1.5 |
MEDIUM | 6.6 | The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up… | — | wordfence |
| 2b821728-eb16-4157-906f-96f6420fa850 | < 2.1.5 |
MEDIUM | 6.6 | The Easy Invoice plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.4. Thi… | — | wordfence |
| 2a69576e-4796-421a-b6ee-08a3b40d4805 | < 9.4.3.1 |
MEDIUM | 6.6 | The Booking Calendar plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and… | — | wordfence |
| 2881e144-a109-4034-afe8-2f72efd70360 | < 1.0.13 |
MEDIUM | 6.6 | The History Log by click5 plugin for WordPress is vulnerable to time-based SQL Injection via the mail log functionality … | — | wordfence |
| 27a36e90-9678-4832-9f37-b54fe75f5571 | < 20.9.0 |
MEDIUM | 6.6 | The Popup Box Business and Developer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setting… | — | wordfence |
| 1a1fc6c9-50cd-40fd-a777-9eed98aab797 | < 4.3.4 |
MEDIUM | 6.6 | The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and includ… | — | wordfence |
| 17b16fa4-9ea7-4bc5-accb-8249ed7280aa | < 1.3.10 |
MEDIUM | 6.6 | The Small Package Quotes – USPS Edition plugin for WordPress is vulnerable to PHP Object Injection in versions up to, … | — | wordfence |
| 17a787da-5630-42ec-b5b0-47435db765a7 | < 1.6.3 |
MEDIUM | 6.6 | The User Activity Log plugin for WordPress is vulnerable to generic SQL Injection via the ‘txtsearch’ parameter in v… | — | wordfence |
| 15f38932-2687-4d71-8793-843058a657d1 | < 6.9 |
MEDIUM | 6.6 | Authenticated Stored Cross-Site Scripting (XSS) vulnerability in WordPress Absolutely Glamorous Custom Admin plugin (ver… | — | wordfence |
| 1597859c-2808-4e0f-aa8d-4e2727728e22 | < 3.7.20 |
MEDIUM | 6.6 | The Dokan plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.7.19 via deseri… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →