Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 101 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 05a81b0e-2d25-44b5-b791-5b2aed94bbab | CRITICAL | 9.8 | The MyFTP plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 1.1 due to insuf… | — | wordfence | |
| 0578f4d1-5953-4fbe-8bc3-0569bee57a1a | < 2.7.2 |
CRITICAL | 9.8 | The Houzez theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.7.1. This is du… | — | wordfence |
| 05776ec2-b432-40f6-bd75-4e6ec103c497 | CRITICAL | 9.8 | The Arlo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.0.3. This makes i… | — | wordfence | |
| 056d26da-6e43-4cc6-b2fd-13a5947a814e | CRITICAL | 9.8 | The SAICO theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the php.ph… | — | wordfence | |
| 05544f69-bc9b-4270-80c9-96afe4793cb6 | < 1.6.2 |
CRITICAL | 9.8 | PHP remote file inclusion vulnerability in firestats-wordpress.php in the FireStats plugin before 1.6.2-stable for WordP… | — | wordfence |
| 054da118-b268-4dbf-80d3-5ff885f00500 | CRITICAL | 9.8 | The login-social plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, … | — | wordfence | |
| 05431aaa-5d8f-422c-b7ce-955a778f7f55 | CRITICAL | 9.8 | The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive. | — | wordfence | |
| 053bb01c-9e87-4836-ae1c-567272b21118 | < 2.0.16 |
CRITICAL | 9.8 | The Registration Forms β User Profile, Custom Registration Form, Login Form, Invitation-Based Registrations plugin for… | — | wordfence |
| 05178bf3-3040-41aa-ba43-779376d30298 | < 1.7.6 |
CRITICAL | 9.8 | The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5… | — | wordfence |
| 0502c622-975f-4218-8b53-efd776fe9d99 | < 1.0.6 |
CRITICAL | 9.8 | The newstatpress plugin before 1.0.6 for WordPress has SQL injection related to an IMG element. | — | wordfence |
| 04d8b1bf-d514-4908-a30e-6ff7b8e03f82 | < 1.2.2 |
CRITICAL | 9.8 | The sharebar plugin before 1.2.2 for WordPress has SQL injection via id parameter. | — | wordfence |
| 04bc8101-2676-4695-a498-f79be8221617 | < 2.6.8 |
CRITICAL | 9.8 | The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includi… | — | wordfence |
| 04b7a2ba-e299-4781-8ee6-644938bf9629 | < 3.4.5 |
CRITICAL | 9.8 | The MStore API plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization via the api/flu… | — | wordfence |
| 0491b8b3-014e-4ef2-b3b6-9570063fffc5 | < 3.8.3.3 |
CRITICAL | 9.8 | The Pie Register Premium plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to 3.8.3.3 (exc… | — | wordfence |
| 0486fca3-49d4-4edb-9b32-952a20ffa59f | < 2.4 |
CRITICAL | 9.8 | The DSK theme for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 2.4. This makes it p… | — | wordfence |
| 0451a7b8-7657-4b73-9ef1-cc3791349e59 | < 1.1.1 |
CRITICAL | 9.8 | The Selio - Real Estate Directory theme for WordPress is vulnerable to generic SQL Injection via the βisβ parameter … | — | wordfence |
| 04033a28-b58a-4584-926b-f43036b23247 | CRITICAL | 9.8 | The Multi Purpose Mail Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… | — | wordfence | |
| 04003542-fd62-4587-9834-70e7fe8f08ef | < 2.0.7 |
CRITICAL | 9.8 | The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, … | — | wordfence |
| 03e853be-510f-4957-a227-17ca9f825b12 | < 1.6.1 |
CRITICAL | 9.8 | The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all ver… | — | wordfence |
| 03be4344-d388-4357-8a2e-c3b9c8b83017 | < 1.5.6.8 |
CRITICAL | 9.8 | The e-signature plugin for WordPress is vulnerable to Remote Code Execution in versions before 1.5.6.8. This allows unau… | — | wordfence |
| 03b9187e-022a-48c1-a79c-c4629357de5a | CRITICAL | 9.8 | Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/delete.php user input isn't sanitized via the contac… | — | wordfence | |
| 038deaeb-633f-49de-92d8-e593ceb47b1e | < 1.0.5 |
CRITICAL | 9.8 | The RewardsWP β Loyalty Points & Referral Program for WooCommerce plugin for WordPress is vulnerable to Privilege Esca… | — | wordfence |
| 038ddfcd-093b-4234-a0b8-a3bf9a3d329f | CRITICAL | 9.8 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclus… | — | wordfence | |
| 0386ed09-296d-4f33-9fe0-964c0c0a9652 | < 1.7.0 |
CRITICAL | 9.8 | The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation wi… | — | wordfence |
| 037a8b06-18be-4443-b54c-22f50c89d5b4 | < 4.0.9 |
CRITICAL | 9.8 | The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues. | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →