Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 474 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 293ad145-dc93-4d7a-83ba-78f8c730ed6d | < 2.7.1 |
MEDIUM | 6.5 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forge… | — | wordfence |
| 292dab09-7090-4ca9-bca2-0d3e6db08818 | < 3.11.3 |
MEDIUM | 6.5 | The SALESmanago & Leadoo plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.11.2 du… | — | wordfence |
| 28cf0f3f-0048-4da9-aa86-243479f7b974 | MEDIUM | 6.5 | The WP Human Resource Management plugin for WordPress is vulnerable to Arbitrary User Deletion due to a missing authoriz… | — | wordfence | |
| 288946ae-6e58-42e6-89d1-8951539728d3 | MEDIUM | 6.5 | The Easy Newsletter Signups plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due t… | — | wordfence | |
| 28477bd5-a55f-4763-b7f2-86b0d9c92fd8 | < 3.1.2 |
MEDIUM | 6.5 | The Traveler Code plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.1 due to ins… | — | wordfence |
| 2830c958-13d1-4c69-8dde-7fc091db02eb | < 3.0.3 |
MEDIUM | 6.5 | The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… | — | wordfence |
| 28246279-ecd8-4731-a4cc-64a3a4167323 | < 2.0.4 |
MEDIUM | 6.5 | The All in One Time Clock Lite plugin for WordPress is vulnerable to unauthorized access due to a missing authorization … | — | wordfence |
| 2804c88e-895c-427a-8372-2ef794d9d136 | MEDIUM | 6.5 | The nicen-localize-image plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.9 due… | — | wordfence | |
| 27d25885-1a85-40a0-9759-3ae0c8d73d11 | < 1.5 |
MEDIUM | 6.5 | The WP FullCalendar plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on seve… | — | wordfence |
| 2799ede9-1905-44b9-b731-ce5398d561b1 | MEDIUM | 6.5 | The Batch Cat WordPress plugin through 0.3 defines 3 custom AJAX actions, which both require authentication but are avai… | — | wordfence | |
| 27941859-f784-4401-a233-9a58a6e52eb3 | MEDIUM | 6.5 | The Flickr set slideshows plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.9 due … | — | wordfence | |
| 278d2d44-16e1-4560-9988-02d900443e42 | MEDIUM | 6.5 | The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape… | — | wordfence | |
| 2741ec8c-7bd3-42f9-b964-4532216e1cea | < 2.0.24 |
MEDIUM | 6.5 | The Distance Based Shipping Calculator plugin for WordPress is vulnerable to SQL Injection in versions up to, and includ… | — | wordfence |
| 27394b03-3604-4fb0-950f-e1f838cabb05 | < 1.8.41 |
MEDIUM | 6.5 | The Photo Gallery by 10Web β Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based blind SQL … | — | wordfence |
| 26fa1781-3919-41a4-9954-325bec856688 | < 3.6 |
MEDIUM | 6.5 | The Tuturn - Online Tutors Marketplace WordPress Theme plugin for WordPress is vulnerable to Path Traversal in all versi… | — | wordfence |
| 26c4008a-9043-4293-aaf3-8e72de667ad8 | MEDIUM | 6.5 | The Simple Signup Form plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'ssf' shortcode… | — | wordfence | |
| 26a82493-a6a5-4d8e-8322-942925a54cc3 | < 6.7.17 |
MEDIUM | 6.5 | The WCFM β Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress … | — | wordfence |
| 266b1004-a374-4770-9659-bac3d167b585 | < 1.22.3 |
MEDIUM | 6.5 | The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the re… | — | wordfence |
| 263f7a72-8887-42c3-a1df-3dee904f957e | < 3.2.1 |
MEDIUM | 6.5 | The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… | — | wordfence |
| 260d1418-e489-43af-b28a-a44abf6b9f93 | MEDIUM | 6.5 | The Share Buttons β Social Media plugin for WordPress is vulnerable to SQL Injection in versions up to, and including,… | — | wordfence | |
| 25e0c269-55c2-49f0-96bb-ae2696e2cea8 | MEDIUM | 6.5 | The Connections Business Directory plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficien… | — | wordfence | |
| 2591f473-44ff-4319-8b17-b0f793a29d66 | < 5.7.0 |
MEDIUM | 6.5 | The MyRewards β Loyalty Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization… | — | wordfence |
| 2586662d-c80b-4b6f-85eb-fb472655ea34 | < 1.7.0 |
MEDIUM | 6.5 | The Docket (WooCommerce Collections / Wishlist / Watchlist) plugin for WordPress is vulnerable to unauthorized access du… | — | wordfence |
| 255cdf64-93cd-434c-9a3c-3b8e49593ffe | < 2.1.15 |
MEDIUM | 6.5 | The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection. | — | wordfence |
| 249caa5b-c1b0-4b72-98f3-31bbb574c834 | < 2.9.6 |
MEDIUM | 6.5 | Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exp… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →