Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 447 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ab890935-d59a-4d4e-9c02-c4eceea270a9 | MEDIUM | 6.5 | The Duplicate Page and Post plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 du… | — | wordfence | |
| ab870fc4-1651-414e-8702-cbe9829a4e75 | < 6.10.2 |
MEDIUM | 6.5 | Vulnerable versions of the Jupiter Theme allow arbitrary plugin deletion by any authenticated user, including users with… | — | wordfence |
| ab3b52f7-e2c3-44f7-8e19-b6c51ccd50e0 | < 10.8.0 |
MEDIUM | 6.5 | The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a … | — | wordfence |
| ab15fa8b-4072-435a-8a1c-ca6fd964a260 | < 1.8.1 |
MEDIUM | 6.5 | The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of … | — | wordfence |
| ab07e612-b561-41fc-8195-22d22fe06acd | MEDIUM | 6.5 | The Editor Wysiwyg Background Color plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… | — | wordfence | |
| aa7be3a9-8a11-46c7-9fa0-7c5bda7a9846 | MEDIUM | 6.5 | The AllInOne - Banner Rotator plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8 … | — | wordfence | |
| aa7b7474-c170-42a2-be88-0fe410a2e71b | < 6.8.4 |
MEDIUM | 6.5 | WordPress core is vulnerable to XML External Entity (XXE) Injection via the bundled getID3 library in all versions up to… | — | wordfence |
| aa698e7e-b1c7-4ead-aa2e-7fbfc9dfac80 | < 2.0.7 |
MEDIUM | 6.5 | The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and includin… | — | wordfence |
| aa30b959-cdf2-4b3b-9c65-d52e1d839a79 | < 9.6.5 |
MEDIUM | 6.5 | The The XStore theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, … | — | wordfence |
| aa1eaac2-a23b-4ef6-803a-15f7ec7e5728 | < 2.4.10 |
MEDIUM | 6.5 | The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to… | — | wordfence |
| aa174135-d7aa-44f1-8924-44313fc70a75 | < 2.5.7 |
MEDIUM | 6.5 | The WooCommerce GoCardless Gateway plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up… | — | wordfence |
| a9e4e989-8e55-4ea7-8f42-9f67cfab1168 | < 1.3.2 |
MEDIUM | 6.5 | The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Acti… | — | wordfence |
| a973dd0a-1a36-4ea2-a300-0f8bb277dfaa | < 3.7.2 |
MEDIUM | 6.5 | The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does … | — | wordfence |
| a9576cee-2375-437e-9dc8-713209a96a73 | < 3.7.8 |
MEDIUM | 6.5 | The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all version… | — | wordfence |
| a920a77a-681a-4309-bce2-1f77c11c8b29 | < 1.3.0 |
MEDIUM | 6.5 | The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'no_of_reviews' at… | — | wordfence |
| a8ecc765-ae00-4091-81dc-e93f91bbd86e | MEDIUM | 6.5 | The WP Google Map Plugin plugin for WordPress is vulnerable to blind SQL Injection via the 'id' parameter of the 'google… | — | wordfence | |
| a8a31080-c124-49be-b9d1-7bc5abe7cbda | < 2.84 |
MEDIUM | 6.5 | The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions … | — | wordfence |
| a8839665-8f98-4c81-b234-9201236e0194 | < 2.0.5 |
MEDIUM | 6.5 | The CBX Bookmark & Favorite plugin for WordPress is vulnerable to generic SQL Injection via the ‘orderby’ parameter … | — | wordfence |
| a8790df5-7228-4854-870c-1e6d3d0cfbaa | < 93.0.0 |
MEDIUM | 6.5 | The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance'… | — | wordfence |
| a8360ce3-6885-418c-9950-4a5f888c703b | < 1.2.2 |
MEDIUM | 6.5 | The Client Portal – Private user pages and login plugin for WordPress is vulnerable to unauthorized access due to a mi… | — | wordfence |
| a83061c0-d8d3-4dbe-bf2a-65350d17094b | MEDIUM | 6.5 | The Short URL plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data … | — | wordfence | |
| a82bffab-77c3-48e8-af84-39709bf0353b | < 4.4.4 |
MEDIUM | 6.5 | The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud serv… | — | wordfence |
| a8208866-2bac-41e4-8a88-ae32520ff208 | MEDIUM | 6.5 | The Flickr set slideshows plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.9 due … | — | wordfence | |
| a809de9f-e552-4ed0-914a-a37992dcab4b | MEDIUM | 6.5 | The Ultra Portfolio plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.7 due to ins… | — | wordfence | |
| a8077d07-acaf-40f2-bc0f-e28a44ead94c | < 5.5.3 |
MEDIUM | 6.5 | The Icegram Express plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 5.5.2. This al… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →