Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 100 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 081f2603-229b-42f2-b5b1-f89d105a31d5 | < 2.9.5 |
CRITICAL | 9.8 | The ListingPro Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2… | — | wordfence |
| 07eb71fc-6588-490d-8947-3077ec4a9045 | < 3.28.30 |
CRITICAL | 9.8 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i… | — | wordfence |
| 07eab536-6f20-45ec-9f9e-70ab35555db2 | < 6.0.0 |
CRITICAL | 9.8 | The WappPress β Create Mobile App for any WordPress site with our Mobile App Builder in just 1 minute plugin for WordP… | — | wordfence |
| 07ac1921-6d3b-44b3-ad8d-66e18698c025 | < 0.1.2 |
CRITICAL | 9.8 | The Note Press plugin for WordPress before 0.1.2 has a SQL injection vulnerability via the s parameter. This can be expl… | — | wordfence |
| 079d60c1-a15a-4d3e-b295-8c1e024b74ef | < 3.0.0 |
CRITICAL | 9.8 | The Web3 β Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authenticated bypass in all ve… | — | wordfence |
| 073a3b48-7c21-4511-a8e4-3443ef05fd0b | CRITICAL | 9.8 | The MainWP Broken Link Checker plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up… | — | wordfence | |
| 0728e7ac-2091-41de-90a0-e231c4b99ab0 | < 1.3.2 |
CRITICAL | 9.8 | The WooFramework, used for all WooThemes for WordPress, is vulnerable to Remote Code Execution in versions up to, and in… | — | wordfence |
| 071195d6-3452-4241-a8d3-92efc84e4850 | < 5.1.17 |
CRITICAL | 9.8 | The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner… | — | wordfence |
| 07067eb5-d15e-4342-914f-5e2a08ea8bb4 | < 4.4.0 |
CRITICAL | 9.8 | The WP Live Chat Support plugin for WordPress is vulnerable to blind SQL Injection via the 'cid' and 'status' parameter … | — | wordfence |
| 06eaf624-aedf-453d-8457-d03a572fac0d | < 3.1.4 |
CRITICAL | 9.8 | The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… | — | wordfence |
| 06e90f64-f64e-4871-9106-1d7af02f13d2 | CRITICAL | 9.8 | The Nuance theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'VALUM… | — | wordfence | |
| 06dfc3da-6f61-433c-a1e1-48749b654fcd | < 2.8.1 |
CRITICAL | 9.8 | The Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versio… | — | wordfence |
| 06b92517-5431-43ed-ad3b-80bfd0981b93 | < 4.0.7 |
CRITICAL | 9.8 | The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues. | — | wordfence |
| 06a7ff0b-ec6b-490c-9bb0-fbb5c1c337c4 | < 3.19.4 |
CRITICAL | 9.8 | The GiveWP β Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in al… | — | wordfence |
| 068da172-629d-422a-bcd5-1b73af2a5933 | < 1.1.8 |
CRITICAL | 9.8 | The Recip.ly Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence |
| 068d9502-705e-45dc-a7fb-e75866226fdd | CRITICAL | 9.8 | The Videos sync PDF plugin for WordPress is vulnerable to Local File Inclusion in versions up to an equal to 1.7.4 via t… | — | wordfence | |
| 06881386-3c92-426b-948d-58e8a8bee624 | CRITICAL | 9.8 | The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valid… | — | wordfence | |
| 0685abc6-eac6-46c5-87ae-52e2af9301c2 | CRITICAL | 9.8 | The WP REST API FNS Plugin plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and inclu… | — | wordfence | |
| 06382aab-8a92-43a2-a4fa-7bbd21967326 | < 2.2.3 |
CRITICAL | 9.8 | The miniOrange Discord Integration plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inc… | — | wordfence |
| 063826cc-7ff3-4869-9831-f6a4a4bbe74c | < 18.5.10 |
CRITICAL | 9.8 | The Shield Security β Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local F… | — | wordfence |
| 061f022b-b922-4499-bb34-8ea91ba5ace3 | CRITICAL | 9.8 | The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via accoun… | — | wordfence | |
| 05ea5a3c-084a-458f-b0b1-8a9b82e4656a | CRITICAL | 9.8 | The Comment Rating plugin for WordPress is vulnerable to generic SQL Injection via the 'ck_ips' parameter in versions up… | — | wordfence | |
| 05d32a0f-b299-4dfd-8d92-4bd0a9872a0b | CRITICAL | 9.8 | The ABC APP CREATOR plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1… | — | wordfence | |
| 05c68377-feb6-442d-a3a0-1fbc246c7cbf | < 3.10 |
CRITICAL | 9.8 | The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in vers… | — | wordfence |
| 05c40628-b8fc-48ff-8819-c0955d69fce0 | < 4.8.0 |
CRITICAL | 9.8 | The Pipdig Power Pack(p3) plugin for WordPress is contained a backdoor in versions before 4.8.0. Obfuscated code was pre… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →