Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 438 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d21c7537-8437-43aa-ab52-9e14d27a6e7f | < 3.1.7 |
MEDIUM | 6.5 | The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missi… | — | wordfence |
| d2137662-d328-4da7-986a-341ff1bdca63 | < 3.4.4 |
MEDIUM | 6.5 | The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in version… | — | wordfence |
| d1a78208-0909-4134-bc78-19e395fe7e24 | < 5.0.9 |
MEDIUM | 6.5 | The Taskbuilder β Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to ge… | — | wordfence |
| d18684e3-0745-4415-a765-8c99af33aba6 | < 1.3.1 |
MEDIUM | 6.5 | The Skimlinks Affiliate Marketing Tool plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… | — | wordfence |
| d13ccd77-a39a-4779-86e6-9cd9484ff82a | MEDIUM | 6.5 | The Wishlist plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.44 due to insuffi… | — | wordfence | |
| d117d930-d210-44bf-ac49-19c003ca5a24 | MEDIUM | 6.5 | The Gestion de tarifs plugin for WordPress is vulnerable to SQL Injection via the 'tarif' and 'intitule' shortcodes in a… | — | wordfence | |
| d0fd1c19-b752-4562-9365-165d709b91b2 | < 2.9.9 |
MEDIUM | 6.5 | The Infility Global plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … | — | wordfence |
| d0eafb20-4ef2-448b-9da7-ad8aa9e45215 | < 2.1 |
MEDIUM | 6.5 | The Simple Download Counter plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and includi… | — | wordfence |
| d0b4a357-fddd-4b42-8834-3a294e0d150c | < 1.8.5 |
MEDIUM | 6.5 | Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before … | — | wordfence |
| d01a8636-3796-4fb3-b603-d1ef42bc3e72 | < 3.7.1 |
MEDIUM | 6.5 | The GD Rating System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7 due to in… | — | wordfence |
| CVE-2026-6262 | MEDIUM | 6.5 | The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is… | — | nvd | |
| CVE-2026-2899 | MEDIUM | 6.5 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and … | — | nvd | |
| CVE-2026-2426 | MEDIUM | 6.5 | The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 v… | — | nvd | |
| CVE-2026-2363 | MEDIUM | 6.5 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'order_by' attribute of the… | — | nvd | |
| CVE-2026-1793 | MEDIUM | 6.5 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, … | — | nvd | |
| CVE-2026-1651 | MEDIUM | 6.5 | The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the 'workflow_ids' para… | — | nvd | |
| CVE-2026-1461 | < 4.7.1 |
MEDIUM | 6.5 | The Simple Membership plugin for WordPress is vulnerable to Improper Handling of Missing Values in all versions up to, a… | — | nvd |
| CVE-2026-0722 | MEDIUM | 6.5 | The Shield Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… | — | nvd | |
| CVE-2025-15470 | MEDIUM | 6.5 | The Eleganzo theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient path validation in th… | — | nvd | |
| CVE-2025-11725 | < 3.0.3 |
MEDIUM | 6.5 | The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… | — | nvd |
| CVE-2024-10938 | MEDIUM | 6.5 | The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives … | — | nvd | |
| cffb26bc-3d3f-4593-bb36-d2abcd67861e | < 4.5.2 |
MEDIUM | 6.5 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Arbitrary Option Updates in versions up to, and i… | — | wordfence |
| cfd1e59a-a76d-4f6d-9d22-021afd45d9af | < 5.10.4 |
MEDIUM | 6.5 | The Better Click To Tweet plugin for WordPress is vulnerable to authorization bypass due to a missing capability check o… | — | wordfence |
| cfbbb8cf-ea03-4a99-92a2-6d0672c82190 | < 4.0.0 |
MEDIUM | 6.5 | The KiviCare plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.6.16 due to insuffi… | — | wordfence |
| cfb09dcd-f8ec-4b0a-ae77-4b4b7b54c93b | MEDIUM | 6.5 | The ElementCamp plugin for WordPress is vulnerable to time-based SQL Injection via the 'meta_query[compare]' parameter i… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →