Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ff32cb12-f010-45ae-97d7-f36ce2003f3c | < 4.9.21 |
CRITICAL | 10.0 | The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 4.9.20. This is… | — | wordfence |
| fdb3c672-0ac4-42e8-951b-e41dc8bd6231 | CRITICAL | 10.0 | The SendGrid for WordPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4 due… | — | wordfence | |
| fbba822b-172f-4167-bccf-4697a298178e | < 6.3.2 |
CRITICAL | 10.0 | The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to SQ… | — | wordfence |
| f87019bd-4e33-4832-a9f3-4a93157386f8 | CRITICAL | 10.0 | The BuddyPress Cover plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… | — | wordfence | |
| f70a3776-947f-4322-9e78-100475ed3d7c | < 2.5.4 |
CRITICAL | 10.0 | The JobSearch WP Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi… | — | wordfence |
| f23d80ae-a686-4e89-a8c0-648289521c58 | < 1.10 |
CRITICAL | 10.0 | The All-in-One Events Calendar plugin for WordPress is vulnerable to SQL Injection via the “ai1ec_cat_idsâ€, “ai1ec… | — | wordfence |
| ef2ac5c8-9e76-40b8-a2a4-8cb4291871f2 | < 2.1.12 |
CRITICAL | 10.0 | An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalat… | — | wordfence |
| e84d50e1-65fe-4323-981f-e2ae6da0ddab | < 1.1.5 |
CRITICAL | 10.0 | The CRM Perks Forms plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.4 due to i… | — | wordfence |
| e495507d-7eac-4f38-ab6f-b8f0809b2be4 | < 4.2.7.1 |
CRITICAL | 10.0 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' para… | — | wordfence |
| df4dabd8-b676-4449-ab28-34d73fe0c39a | < 2.4.5 |
CRITICAL | 10.0 | The Chatbot with ChatGPT WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to, and includ… | — | wordfence |
| dd718d44-4921-4deb-af5a-43e5f3926914 | < 2.6.8 |
CRITICAL | 10.0 | The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… | — | wordfence |
| d9de41de-f2f7-4b16-8ec9-d30bbd3d8786 | < 3.11.0 |
CRITICAL | 10.0 | The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and in… | — | wordfence |
| d1429549-2e73-4db3-bc83-98c722a80903 | < 7.5.18 |
CRITICAL | 10.0 | The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to SQL Injection via the 'form_id' parameter … | — | wordfence |
| cfbc7f74-89c6-4418-9e1e-12650e179912 | < 8.7.01.002 |
CRITICAL | 10.0 | The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… | — | wordfence |
| cedc575c-ee8f-4c62-bc44-95252a0c8b6f | < 0.1.0.39 |
CRITICAL | 10.0 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due … | — | wordfence |
| ca88c62d-0f27-40e0-9dd2-21d3d133fda3 | < 14.0.31 |
CRITICAL | 10.0 | The WZone plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 14.0.10 due to insuffici… | — | wordfence |
| c2b2671e-0db7-4ba9-b574-a0122959e8fc | < 4.2.7.1 |
CRITICAL | 10.0 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter… | — | wordfence |
| bcc59efb-5ecd-4822-998c-6c79fbeb4c3a | < 1.6.2 |
CRITICAL | 10.0 | SQL injection vulnerability in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute… | — | wordfence |
| b8205bfe-4586-42e9-b4f7-e46947396b6b | < 2.4 |
CRITICAL | 10.0 | The I LOVE IT! theme is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in versions up to, and… | — | wordfence |
| b5a7ddea-76db-4009-83a0-92d9ccfe1da4 | CRITICAL | 10.0 | The CZ Loan Management plugin for WordPress is vulnerable to SQL Injection via the 'selectedperiod' parameter of the 'cz… | — | wordfence | |
| ac167257-c34e-45a2-8647-ed5cdb8dd64d | < 1.9.5 |
CRITICAL | 10.0 | The WBW Product Table Pro plugin for WordPress is vulnerable to unauthorized arbitrary SQL Execution due to a missing ca… | — | wordfence |
| ab8bf2d1-1af4-4ea0-bba9-e65ea1ed5978 | < 2.0.10 |
CRITICAL | 10.0 | The Opti Marketing plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.9 due t… | — | wordfence |
| a562a213-9c63-4236-8c2c-c7fadffb5ac4 | < 1.2.2 |
CRITICAL | 10.0 | The Viral Quiz Maker - OnionBuzz plugin for WordPress is vulnerable to blind SQL Injection via the ‘ob_get_results' aj… | — | wordfence |
| a303c798-c206-426a-9a96-263c8c069bdb | < 1.3.9 |
CRITICAL | 10.0 | The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files… | — | wordfence |
| a2bda5d0-9589-4925-baa6-6e207e6fc978 | < 3.3.0 |
CRITICAL | 10.0 | The WP Dummy Content Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 3.3.0 (… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →