Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 464 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 58f9bef5-6596-40b2-bcb6-d686e87d8d8f | < 8.3.18 |
MEDIUM | 6.5 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, … | — | wordfence |
| 58e3b7f1-26f4-453a-ae1f-a1e6eed0348c | < 5.0.3 |
MEDIUM | 6.5 | WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can … | — | wordfence |
| 58cc0a13-cda1-499b-b29a-e0b358a2e8e5 | < 5.3.0 |
MEDIUM | 6.5 | The YML for Yandex Market plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path va… | — | wordfence |
| 58a1f3a1-e00c-4b63-83ad-73205c67c0ac | MEDIUM | 6.5 | The eBay Dropshipping and Affiliate by Wooshark plugin for WordPress is vulnerable to authorization bypass due to missin… | — | wordfence | |
| 58695d72-d78e-4e5a-8179-a5d12a80b370 | < 1.1.5 |
MEDIUM | 6.5 | The WP Sessions Time Monitoring Full Automatic plugin for WordPress is vulnerable to SQL Injection in versions up to, an… | — | wordfence |
| 58387a60-ef68-4911-9349-97b0f7e7726f | < 1.8.13 |
MEDIUM | 6.5 | The Qubely β Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βal… | — | wordfence |
| 582fa92d-8e52-49a9-94ce-f1b49229f591 | < 3.5.6 |
MEDIUM | 6.5 | The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and i… | — | wordfence |
| 5808b671-7795-4a1a-8c8c-b64a3d0db378 | MEDIUM | 6.5 | The Simple Job Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1 due to … | — | wordfence | |
| 57a12c21-4a5d-4fbd-8720-93e78164f216 | < 4.5.8 |
MEDIUM | 6.5 | An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not… | — | wordfence |
| 575ec3a9-26f7-415b-9df6-d0401557a578 | < 1.6.2 |
MEDIUM | 6.5 | The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to… | — | wordfence |
| 570bca1e-78d0-49e8-8919-eba19f9457b9 | < 1.4.1 |
MEDIUM | 6.5 | includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin … | — | wordfence |
| 564b8271-ba1a-4bf1-b072-7dadadb02ccf | < 1.1.31 |
MEDIUM | 6.5 | The CubeWP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.30 due to insuffici… | — | wordfence |
| 56233337-ddde-4630-99b7-46a8e2be70af | MEDIUM | 6.5 | The smart SEO plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0 due to insuffici… | — | wordfence | |
| 561479ed-2402-4511-9344-d6b9e28f2f33 | < 5.0.7 |
MEDIUM | 6.5 | The Taskbuilder β Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to ti… | — | wordfence |
| 5589754a-2234-457e-bfa4-59fb4161d736 | < 7.6.1 |
MEDIUM | 6.5 | The Product Feed Manager for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and incl… | — | wordfence |
| 55604ee9-7343-472c-9a29-035d18b266ab | < 2.0.1 |
MEDIUM | 6.5 | The JS Job Manager plugin for WordPress is vulnerable to unauthorized access to plugin functionality due to missing capa… | — | wordfence |
| 54db1807-69ff-445c-9e02-9abce9fd3940 | < 4.10.1 |
MEDIUM | 6.5 | The GiveWP β Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in al… | — | wordfence |
| 54cccd61-35d0-432c-8832-28e7928c464d | < 1.3 |
MEDIUM | 6.5 | The Add Multiple Marker plugin for WordPress is vulnerable authorization bypass in versions up to, and including, 1.2. T… | — | wordfence |
| 549cd23f-3b3a-41b7-baa2-cc5c6b826a2e | < 3.5.8 |
MEDIUM | 6.5 | The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions funct… | — | wordfence |
| 546f388e-16e2-4c0b-acb0-a462bff4ef77 | MEDIUM | 6.5 | The Webmaster Tools Verification plugin for WordPress is vulnerable to authorization bypass due to a missing capability … | — | wordfence | |
| 546bd215-61aa-48bd-915e-7ced0128f53d | < 3.4.2 |
MEDIUM | 6.5 | The wpDataTables β Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated us… | — | wordfence |
| 54344300-6288-40bc-b539-3dc9b555ed00 | < 2.2.1 |
MEDIUM | 6.5 | The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to Stored Cross-Site… | — | wordfence |
| 541d202b-f3ed-44d8-93a6-e158209db885 | < 1.2.4 |
MEDIUM | 6.5 | The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when c… | — | wordfence |
| 54154f34-96be-4b67-bca8-8efc4ab8543e | < 1.3.19 |
MEDIUM | 6.5 | The Premmerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.18.… | — | wordfence |
| 53f12e61-fdb0-4838-b733-fc4d7a4ff016 | < 1.8.7 |
MEDIUM | 6.5 | The Ovatheme Events Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →