Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 477 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 1caa8baa-0783-4bc9-af03-46a3a2cf3538 | < 8.0.4 |
MEDIUM | 6.5 | The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.… | — | wordfence |
| 1c874d4a-7ec0-4024-bc05-80160388507c | MEDIUM | 6.5 | The The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to arbitrary shortcode execution in all ver… | — | wordfence | |
| 1c225bea-78db-4f4c-a201-833436c1df78 | < 4.29991 |
MEDIUM | 6.5 | The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to Directory Traversal in versi… | — | wordfence |
| 1bfc5467-6610-4516-8c50-d47d05e2677d | < 2.1.3 |
MEDIUM | 6.5 | The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `s… | — | wordfence |
| 1be68c82-c22c-4d45-8c7f-a7aa21fe3ddf | < 1.0.27.1 |
MEDIUM | 6.5 | The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.p… | — | wordfence |
| 1bcb675e-bd69-4003-9adc-45a2e0d66347 | MEDIUM | 6.5 | The Cool fade popup plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 10.1 due to in… | — | wordfence | |
| 1bc19bfa-ce44-4654-b074-c8126b60a155 | < 1.4.7 |
MEDIUM | 6.5 | The Hybrid Composer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the … | — | wordfence |
| 1baa7b7a-49b5-48bd-b45f-31fae707c199 | < 1.0.9 |
MEDIUM | 6.5 | The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to unauthorized modification o… | — | wordfence |
| 1b786e22-9fbe-4d84-9139-3d18f9339d2f | MEDIUM | 6.5 | The Wp tabber widget plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0 due to in… | — | wordfence | |
| 1b3df470-d0b7-49e8-bcb2-ac999e0b71d1 | < 1.4.2 |
MEDIUM | 6.5 | The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, an… | — | wordfence |
| 1ab4dc20-ce50-4ad0-aff4-9fc529d1911f | < 3.3.2 |
MEDIUM | 6.5 | Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripti… | — | wordfence |
| 1aab38ba-ade7-48c9-ac7c-dff1237a9d89 | < 8.2.8 |
MEDIUM | 6.5 | The Recipe Cards For Your Food Blog from Zip Recipes plugin for WordPress is vulnerable to SQL Injection in versions up … | — | wordfence |
| 1a8b194c-371f-4adc-98fa-8f4e47a38ee7 | < 3.3.2 |
MEDIUM | 6.5 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf' shortcode … | — | wordfence |
| 1a74d5f4-1dd8-4d49-b4ce-8ba7ac9cbcc7 | MEDIUM | 6.5 | The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthorized modification of data due to a missin… | — | wordfence | |
| 1a4414b1-6a49-42f8-9927-93763d1502ce | < 6.0.7 |
MEDIUM | 6.5 | The Kirki β Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization by… | — | wordfence |
| 1a23ee5c-275f-4d51-8199-1cc2b0086f73 | < 12.4.06 |
MEDIUM | 6.5 | The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to blind SQL Injection via the 'search' parameter in a… | — | wordfence |
| 1a081788-007e-463b-b757-afefcf4c6e17 | < 4.8 |
MEDIUM | 6.5 | All In One Favicon plugin for WordPress is vulnerable to Directory Traversal via the 'aioFaviconUpdateSettings' function… | — | wordfence |
| 19f94c4f-145b-4058-aabd-06525fce3cea | < 2.2.8 |
MEDIUM | 6.5 | The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of… | — | wordfence |
| 19ac688c-d07c-40fa-8155-e3ae45e17b5b | < 1.2.4 |
MEDIUM | 6.5 | The WP Subscription Forms plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.3 du… | — | wordfence |
| 1983cc82-c527-47d9-84ba-f903dda1b1ca | < 1.3 |
MEDIUM | 6.5 | The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any… | — | wordfence |
| 193f0a25-4400-40e0-8070-94fbf9c28c11 | < 1.9.9.5.3 |
MEDIUM | 6.5 | The WPLMS plugin for WordPress is vulnerable to SQL Injection in versions up to 1.9.9.5.3 due to insufficient escaping o… | — | wordfence |
| 191f5bc3-9b8e-4ec7-b8b3-91572ef97911 | < 2.10.1.5 |
MEDIUM | 6.5 | The Beaver Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.10.1.2 due to… | — | wordfence |
| 19062e84-7ce5-400e-a404-2bb4286cc09e | < 2.1.6 |
MEDIUM | 6.5 | The miniOrange Discord Integration plugin for WordPress is vulnerable to authorization bypass due to a missing capabilit… | — | wordfence |
| 18e51b35-90fa-4ea0-95f9-644ab864b406 | < 2.14.2 |
MEDIUM | 6.5 | The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CS… | — | wordfence |
| 18daa19e-81f8-4ea8-837b-3f1fce26d2b2 | MEDIUM | 6.5 | The Responsive HTML5 Audio Player PRO With Playlist plugin for WordPress is vulnerable to SQL Injection in versions up t… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →