Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 462 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 621e3b3f-9647-41ec-aa06-e961e3525fea | < 3.05 |
MEDIUM | 6.5 | The Car Dealer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the carde… | — | wordfence |
| 61fdc6e9-75ea-4226-9527-a5fd02efde70 | < 1.8.2 |
MEDIUM | 6.5 | The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthenticated settings reset in versions… | — | wordfence |
| 61e107e8-405a-4f14-b0ff-b9a66b7ccf8b | MEDIUM | 6.5 | The Team Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence | |
| 61b07604-b206-4f13-b25f-7a6d54236eb1 | < 1.7.7 |
MEDIUM | 6.5 | The Slideshow Gallery LITE plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in versions up … | — | wordfence |
| 615f9068-2a42-40c2-aff9-4807b2bd7550 | < 7.0.2 |
MEDIUM | 6.5 | The WPJAM Basic plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.0.1 due to insuf… | — | wordfence |
| 6101c3a2-4284-4b14-995d-06855a8e551d | MEDIUM | 6.5 | The JSP Store Locator plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.0 due … | — | wordfence | |
| 60ee9cfc-016d-45ee-b3f4-da999d093776 | MEDIUM | 6.5 | The Booster Elementor Addons plugin for WordPress is vulnerable to unauthorized access and modification of data due to m… | — | wordfence | |
| 60e642f9-74ff-47f1-a49d-99c8fdb26f4a | MEDIUM | 6.5 | The Scheduling Plugin – Online Booking for WordPress plugin for WordPress is vulnerable to unauthorized loss of data d… | — | wordfence | |
| 60496696-7cb9-44b1-a622-7ee427530c9d | < 5.1.9 |
MEDIUM | 6.5 | The Download Monitor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.1.8 due to … | — | wordfence |
| 603734a3-f471-4a40-9253-92e0d1ef5ac2 | MEDIUM | 6.5 | The Infility Global plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.14.7. T… | — | wordfence | |
| 601ad4f3-2160-4af6-b3d5-c2af52746aab | < 2.2 |
MEDIUM | 6.5 | An issue was discovered in the MULTIDOTS WooCommerce Checkout for Digital Goods plugin 2.1 for WordPress. If an admin us… | — | wordfence |
| 6015e204-1e07-4c75-ad22-969045934468 | < 1.8.5 |
MEDIUM | 6.5 | The Coupon Referral Program plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … | — | wordfence |
| 5fe7668b-9d70-44b7-a347-3922c0b8684c | < 2.1.10 |
MEDIUM | 6.5 | The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized a… | — | wordfence |
| 5f1ba1c7-de88-4070-a4ec-fbe4a0c30920 | < 2.1.2 |
MEDIUM | 6.5 | The GenerateBlocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check o… | — | wordfence |
| 5ee7f904-d150-4da1-a79c-502fe2ca3b37 | < 1.1.5 |
MEDIUM | 6.5 | Server-side request forgery (SSRF) in the Podcast Importer SecondLine (podcast-importer-secondline) plugin 1.1.4 and bel… | — | wordfence |
| 5ee333a6-6b4b-4abb-9fc9-1afd9598b321 | < 2.0.7 |
MEDIUM | 6.5 | A CSRF vulnerability in Settings form in the Custom Simple Rss plugin 2.0.6 for WordPress allows attackers to change the… | — | wordfence |
| 5ec1fd03-f865-4f58-b63b-e70c0c7e701d | < 4.7.15 |
MEDIUM | 6.5 | The CAOS | Host Google Analytics Locally plugin for WordPress is vulnerable to unauthorized modification of data due to … | — | wordfence |
| 5e91f4af-7ac6-4c85-bbf4-ac06d516a570 | < 1.9.27 |
MEDIUM | 6.5 | The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthent… | — | wordfence |
| 5e8933b8-1e09-4cd7-8206-711cc0716dba | < 1.6.8 |
MEDIUM | 6.5 | The Masteriyo - LMS for WordPress plugin is vulnerable to Sensitive Information Exposure in versions up to, and includin… | — | wordfence |
| 5e640767-7998-4404-a894-0b1794464c66 | MEDIUM | 6.5 | The Legoeso PDF Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘checkedVals’ paramet… | — | wordfence | |
| 5e408c1b-6789-4e9c-95c2-89e0a033e6b8 | < 1.4.1 |
MEDIUM | 6.5 | The DynamicTags plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.0 due to insuf… | — | wordfence |
| 5dbe5094-d255-46b1-9e8e-9c48cd74e8a2 | < 1.6.12.11 |
MEDIUM | 6.5 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to I… | — | wordfence |
| 5db00eb6-3e05-42fa-bb84-2df4bcae3955 | < 3.3.2 |
MEDIUM | 6.5 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to unauthorized permalink structure update… | — | wordfence |
| 5dad7348-39ba-4163-a5eb-939601645edb | < 5.12.7 |
MEDIUM | 6.5 | The Shortcodes Ultimate plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 5.12… | — | wordfence |
| 5d9736e0-1a10-4ea0-a514-62ff49e36c43 | < 1.5.4 |
MEDIUM | 6.5 | Directory traversal vulnerability in models/Cart66.php in the Cart66 Lite plugin before 1.5.4 for WordPress allows remot… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →