Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 428 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 13cfa202-ab90-46c0-ab53-00995bfdcaa3 | < 1.28.0 |
MEDIUM | 6.6 | The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the 'for… | — | wordfence |
| 1388873f-8053-4ba9-8707-093bc0e8f2f5 | < 2.1.79 |
MEDIUM | 6.6 | The WooCommerce Product Vendors plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions… | — | wordfence |
| 102e32d5-5ccc-43f8-adef-f0e2b145bf53 | < 5.9.14 |
MEDIUM | 6.6 | The Icegram Express Pro plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.9… | — | wordfence |
| 0e55c464-1ece-4dc2-b814-3a94ca90ae79 | < 3.4.4 |
MEDIUM | 6.6 | The eCommerce Product Catalog plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includin… | — | wordfence |
| 0d423c90-89ca-4295-92eb-d26acd445db0 | < 3.1.16 |
MEDIUM | 6.6 | The Real Testimonials – Testimonial Slider, Collect Customer Reviews and Video Testimonials plugin for WordPress is vu… | — | wordfence |
| 0d3f7676-5ab0-4fe0-a0be-786f4cf84056 | < 2.2.6 |
MEDIUM | 6.6 | The WordPress Brute Force Protection – Stop Brute Force Attacks plugin for WordPress is vulnerable to SQL Injection vi… | — | wordfence |
| 0c7beb26-a4ac-47a3-9ee1-64f399e3218b | < 1.0.4 |
MEDIUM | 6.6 | The User Rights Access Manager plugin for WordPress is vulnerable to unauthorized access in versions up to, and includin… | — | wordfence |
| 0c458644-a799-4bea-abcb-06a946dc19df | < 2.1.66 |
MEDIUM | 6.6 | The wpDataTables - Tables & Table Charts plugin for WordPress is vulnerable to PHP Object Injection in versions up to, a… | — | wordfence |
| 0a86f6ed-9755-4265-bc0d-2d0e18e9982f | < 2.1.5 |
MEDIUM | 6.6 | The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file up… | — | wordfence |
| 0a6707ef-aab7-449c-8160-034bc188a998 | < 4.1.40 |
MEDIUM | 6.6 | In all current versions of WordPress Core before 6.4.3, plugins uploaded via the admin area are not verified as being ZI… | — | wordfence |
| 08fb51d6-30c1-4a48-b626-a8c6f203ac83 | MEDIUM | 6.6 | The Clockwork SMS Notfications plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versi… | — | wordfence | |
| 06863974-e428-418b-891a-ade59ee46c4f | < 6.5.0.3 |
MEDIUM | 6.6 | The SEOPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.5.0.2 via de… | — | wordfence |
| 03b1376e-8ef3-4bd2-904b-6819aa21d144 | < 2.0 |
MEDIUM | 6.6 | The Computer Repair Shop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in ver… | — | wordfence |
| fffd7d50-6563-4652-8fae-3fe698125c59 | < 7.3.1 |
MEDIUM | 6.5 | The WooCommerce Checkout Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… | — | wordfence |
| fff419fc-e617-4f7f-92c1-6b58108a993e | < 3.0.12 |
MEDIUM | 6.5 | The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.9 du… | — | wordfence |
| fff1cff1-6745-4124-ba93-8b0749eae61a | < 1.7.1 |
MEDIUM | 6.5 | The tagDiv Opt-In Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘subscriptionCouponId… | — | wordfence |
| ffe1eca0-eba0-4b4c-afe5-9bff4aa2f3f1 | < 5.0.26 |
MEDIUM | 6.5 | The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX act… | — | wordfence |
| ffb8c561-ce2a-447c-add6-d7e01c8c9435 | MEDIUM | 6.5 | The Infility Global plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.12.7 due to … | — | wordfence | |
| ffb70e82-355b-48f3-92d0-19659ed2550e | < 1.0.93.2 |
MEDIUM | 6.5 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a mis… | — | wordfence |
| ff6e6101-8ba5-4cc7-9b02-67a0d9a978b6 | MEDIUM | 6.5 | The Browser and Operating System Finder plugin for WordPress is missing authorization checks on functionality that reset… | — | wordfence | |
| ff5d8f5f-c7af-4789-9920-a09d2733b8ee | < 4.2.3 |
MEDIUM | 6.5 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option c… | — | wordfence |
| ff449224-d405-453f-8c45-5c6f79bc76d6 | < 1.13.13 |
MEDIUM | 6.5 | The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1… | — | wordfence |
| ff294b0f-97fe-4d27-bf93-f5bbb57ac1f6 | < 6.7.1 |
MEDIUM | 6.5 | The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vu… | — | wordfence |
| feb0e1f0-5c0e-4a02-986b-3fbfa1b8ec1b | < 1.4.3 |
MEDIUM | 6.5 | The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to SQL Injection in versions up to, and inclu… | — | wordfence |
| fdc806de-9d93-4e89-a708-d4c142dd14af | MEDIUM | 6.5 | The Easy Post Duplicator plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.1 due… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →