Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 451 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 991ab188-869c-4875-80f3-940000a1717b | < 1.2.11 |
MEDIUM | 6.5 | The The Orders Tracking for WooCommerce plugin for WordPress for WordPress is vulnerable to arbitrary shortcode executio… | — | wordfence |
| 98ab4a17-c350-49a9-921d-7ef04e923110 | MEDIUM | 6.5 | The Pixelating image slideshow gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and includ… | — | wordfence | |
| 984ca0d3-26c3-40cf-8e77-2ec1e3b89ce2 | < 2.8.7 |
MEDIUM | 6.5 | The Cost of Goods for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… | — | wordfence |
| 97fbbf5b-d3c7-47ce-b251-ce1fe38af152 | < 2.6.3 |
MEDIUM | 6.5 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and inclu… | — | wordfence |
| 97c07a3e-4538-4e0f-a597-6b843ff7feb5 | < 1.2.5 |
MEDIUM | 6.5 | Directory traversal vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.2.5 for WordPress allo… | — | wordfence |
| 97a6da6b-ed85-4bf4-8ae7-5cd831d022a7 | < 1.2.42 |
MEDIUM | 6.5 | The Form Builder CP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.41 due to … | — | wordfence |
| 97845a09-d7ae-42bc-b59b-e93f76289b09 | MEDIUM | 6.5 | The CWS SVGicons plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.5 due to insu… | — | wordfence | |
| 97827e26-d418-4c96-b0d0-10b92a4513bd | < 1.0.9 |
MEDIUM | 6.5 | The Responsive Filterable Portfolio plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all ve… | — | wordfence |
| 96a80b89-94e0-4bbd-88cf-5eb5349c320b | < 1.13.20 |
MEDIUM | 6.5 | The Geo Mashup plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geo_mashup_null_fields' par… | — | wordfence |
| 9638fb98-045b-44ec-8b53-15cfa3693ee7 | < 0.21.13 |
MEDIUM | 6.5 | The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id' parameter in all versions up to… | — | wordfence |
| 962f31e6-7863-45e1-835e-c679046deeea | MEDIUM | 6.5 | The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option me… | — | wordfence | |
| 96112707-04ca-4647-9008-31954764486f | < 1.4.7 |
MEDIUM | 6.5 | The Gallery Portfolio plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to mi… | — | wordfence |
| 95dc0d79-b65a-4bfb-89c0-569bf26232df | < 6.8.2 |
MEDIUM | 6.5 | A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress a… | — | wordfence |
| 95ce3773-a676-4aa6-9314-6adccf44d070 | < 11.5.0 |
MEDIUM | 6.5 | The WP Travel β Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injec… | — | wordfence |
| 951b8cbd-0509-4548-ae69-6cfd67e83b1a | < 1.43 |
MEDIUM | 6.5 | The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" w… | — | wordfence |
| 950bed9d-8698-4aa0-86a4-fac9e07bb42b | < 1.8.10.5 |
MEDIUM | 6.5 | The Charitable β Donation Plugin for WordPress β Fundraising with Recurring Donations & More plugin for WordPress is… | — | wordfence |
| 94f7f2d2-e90b-4978-bab8-eee160949567 | < 4.0.7 |
MEDIUM | 6.5 | The MainWP UpdraftPlus Extension for WordPress is vulnerable to authorization bypass due to a missing capability check w… | — | wordfence |
| 94c98edf-6f4a-4c23-afa7-d5caaa22397f | < 1.2.3 |
MEDIUM | 6.5 | The Youzify β BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPres… | — | wordfence |
| 9479c9ff-6da3-4391-802d-9e3eb14eff77 | < 4.20 |
MEDIUM | 6.5 | The Anti Hacker plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the anti… | — | wordfence |
| 94392c66-6e50-48bb-93cb-9aa9d0229761 | < 3.11.13 |
MEDIUM | 6.5 | The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'que… | — | wordfence |
| 940aabdc-e98e-45be-87dd-cafae45f2474 | < 2.3.3 |
MEDIUM | 6.5 | The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, when registration is enabled, allows remote attackers… | — | wordfence |
| 93f9862f-745f-44d5-ac49-f8d2d19b35ed | < 3.3.7 |
MEDIUM | 6.5 | WordPress plugin Wordfence versions 3.3.6 and older were vulnerable to Cross-Site Scripting via the unlockEmail function… | — | wordfence |
| 93d8ed64-0b3e-4410-9166-6e7861d885ca | < 3.7.26 |
MEDIUM | 6.5 | The MasterStudy LMS WordPress Plugin β for Online Courses and Education plugin for WordPress is vulnerable to SQL Inje… | — | wordfence |
| 938e5d6b-1ad6-4021-a148-1d1c9e8a0a83 | < 6.1.2 |
MEDIUM | 6.5 | The Fluent Forms β Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vul… | — | wordfence |
| 930e7fd6-ae0b-465a-aa93-04ef80011d32 | < 8.7.5 |
MEDIUM | 6.5 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of d… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →