Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 457 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 7aab1307-7fb5-46fb-ae12-087dce3086fc | < 1.5.1 |
MEDIUM | 6.5 | The ilGhera Carta Docente for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, an… | — | wordfence |
| 7aa6da4d-7221-4878-8532-5372227f906a | < 4.1.0 |
MEDIUM | 6.5 | The Simple Membership WordPress plugin before 4.1.0 does not have Cross-Site Request Forgery (CSRF) protections in place… | — | wordfence |
| 7a747542-0601-4fa5-a97c-c72d1347013b | < 3.9.7 |
MEDIUM | 6.5 | The MStore API plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks … | — | wordfence |
| 7a7157c0-8378-4aa0-bc47-635be4ba2f8f | < 3.2.68 |
MEDIUM | 6.5 | The Cost Calculator Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_ids’ param… | — | wordfence |
| 7a51fe96-f3d3-46fe-9e3a-fb7c1bd17b05 | < 3.7.26 |
MEDIUM | 6.5 | The MasterStudy LMS WordPress Plugin for Online Courses and Education plugin for WordPress is vulnerable to Time-based B… | — | wordfence |
| 7a275fd7-e1c9-462a-8fe5-2c05e171f235 | < 1.6.002 |
MEDIUM | 6.5 | The Premium SEO Pack plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.001 due t… | — | wordfence |
| 7a2420ca-e079-429b-b1f1-47bf1d0a9f71 | < 4.6.19 |
MEDIUM | 6.5 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based SQL Injection via the… | — | wordfence |
| 79f9632e-cfaf-48bd-aeed-919fc729f2b4 | < 1.8.3 |
MEDIUM | 6.5 | The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online course solution WordPre… | — | wordfence |
| 79e786ce-a3eb-40df-8dad-4c9c75243bec | < 1.8 |
MEDIUM | 6.5 | The LeadConnector plugin for WordPress is vulnerable to unauthorized modification & loss of data due to a missing capabi… | — | wordfence |
| 79da7239-0343-465e-8dda-44ff440939c4 | < 1.13.2 |
MEDIUM | 6.5 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is… | — | wordfence |
| 798d120a-edec-4af9-b574-46f9beabc491 | < 2.6.17 |
MEDIUM | 6.5 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for … | — | wordfence |
| 796c0ded-3a23-4dd6-968a-a8e60bd8ea0e | < 8.5.3 |
MEDIUM | 6.5 | The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to… | — | wordfence |
| 79545b24-b325-486b-b34f-87bba14b8cd4 | < 3.9.5 |
MEDIUM | 6.5 | The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any… | — | wordfence |
| 7951c8e4-b610-4cc4-ab27-4cfa78d72302 | < 5.0 |
MEDIUM | 6.5 | The Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and includ… | — | wordfence |
| 79125ac2-f3ed-40c9-a81b-340195fc8da5 | < 2.6 |
MEDIUM | 6.5 | The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin … | — | wordfence |
| 790514c4-47f2-4c8f-a0c0-cd0b761dd5fc | < 1.1.11 |
MEDIUM | 6.5 | The Hydra Booking plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.10 due to in… | — | wordfence |
| 78ac100e-ba2f-4ba6-9125-9cc2d531cc0e | < 2.1.2 |
MEDIUM | 6.5 | The Miraculous Core plugin for WordPress is vulnerable to SQL Injection in versions up to 2.1.2 due to insufficient esca… | — | wordfence |
| 78ab6263-7762-4fd2-af42-2224efa9509e | < 5.0.9 |
MEDIUM | 6.5 | The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to ge… | — | wordfence |
| 78823184-e90a-4f5c-9f08-5ffc22787f16 | MEDIUM | 6.5 | The avenirsoft-directdownload plugin 1.0 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=avenir_pl… | — | wordfence | |
| 786ef53a-0fcd-4226-b469-52b72cd6890c | < 3.6.0.2 |
MEDIUM | 6.5 | The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_eve… | — | wordfence |
| 7863c5fb-1eda-41a3-b8ec-054784ab2438 | < 1.3.2 |
MEDIUM | 6.5 | The WPExperts Square For GiveWP plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all vers… | — | wordfence |
| 781b00cd-3af9-432a-876b-bff482106ab0 | < 4.9.6 |
MEDIUM | 6.5 | The WPML Multilingual CMS plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in all version… | — | wordfence |
| 7801d3e1-90aa-434d-ae3d-9f19670280c0 | < 5.2.0 |
MEDIUM | 6.5 | The LayerSlider plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 4.6.1 via the Lay… | — | wordfence |
| 77ebd648-3851-47ea-a5eb-86af4899727c | < 3.3.13 |
MEDIUM | 6.5 | The Tatsu WordPress plugin before 3.3.13 add_custom_font action can be used without prior authentication to upload a rog… | — | wordfence |
| 77e5155d-5279-4609-93de-18fa54702c3e | MEDIUM | 6.5 | The Duplicate Page and Post plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.5 … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →