Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 101 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d0567dc8-7a4c-42f4-bf45-f31a8efaa354 | < 3.53.3 |
CRITICAL | 9.1 | The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including… | — | wordfence |
| cf0265cb-d58d-4680-8d5b-9b9334f7721e | CRITICAL | 9.1 | The FW Food Menu β Responsive food menu with ordering & delivery solutions plugin for WordPress is vulnerable to arbit… | — | wordfence | |
| cecf1bcc-ed3e-430c-80d4-d940416eed9a | < 2.1.6 |
CRITICAL | 9.1 | The Import XML and RSS Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… | — | wordfence |
| cc5cee40-32a4-499a-ba34-97e07a276a36 | CRITICAL | 9.1 | The Hostme v2 - Responsive WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuffici… | — | wordfence | |
| cc046b72-692a-4980-90ad-26c8fc2a131a | < 1.3.65 |
CRITICAL | 9.1 | The Ultimate Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.64 … | — | wordfence |
| c9df788e-a92e-4519-9e23-8aed08479b68 | < 2.0 |
CRITICAL | 9.1 | The User Activity Log plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9 due to i… | — | wordfence |
| c85fa04e-477e-4ac9-b112-02b2ab18ca32 | < 1.9.1 |
CRITICAL | 9.1 | The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in versions… | — | wordfence |
| c7f1ffba-bae2-4f69-ac96-c4570d36eb73 | < 7.0.1 |
CRITICAL | 9.1 | The Openpos - WooCommerce Point Of Sale(POS) plugin for WordPress is vulnerable to arbitrary file deletion due to insuff… | — | wordfence |
| c6f3b765-396f-422f-864d-a48bee8c69cb | CRITICAL | 9.1 | The Quicksand Post Filter jQuery Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing… | — | wordfence | |
| c458e6d6-28ba-4465-ace2-5da9e99ca2c7 | < 3.9.1 |
CRITICAL | 9.1 | The DecaLog plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.9.0 due to insuf… | — | wordfence |
| c3ccde73-8b88-48f9-8bbd-0392fcc40c81 | < 4.9.5 |
CRITICAL | 9.1 | The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pa… | — | wordfence |
| bee2245b-d039-48a7-a9dc-bd6ceac6cac6 | < 1.0.7 |
CRITICAL | 9.1 | The Contact Form Extender for Divi β Submissions DB & Extra Fields plugin for WordPress is vulnerable to arbitrary fil… | — | wordfence |
| baa20290-9c01-4f8d-adeb-fbfb15b9d6a9 | CRITICAL | 9.1 | The Startklar Elementor Addons plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and incl… | — | wordfence | |
| b939ec4c-10c0-4c57-be6a-db443e59e22c | CRITICAL | 9.1 | The WordPress Upload Files Anywhere plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fi… | — | wordfence | |
| b90640d2-d6f4-4c3b-8e9b-038d57f5fd6f | < 4.5.4 |
CRITICAL | 9.1 | The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows un… | — | wordfence |
| b8034a3b-9a25-479d-b0d8-30ed4fd76333 | < 7.2.5 |
CRITICAL | 9.1 | The Broadcast Live Video β Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to arbitrary fi… | — | wordfence |
| b6b0bb48-eb61-4236-a03f-19d5d2084a75 | CRITICAL | 9.1 | The Honeypot for WP Comment plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includi… | — | wordfence | |
| b59b5c41-6173-485e-869d-4165dc18e2bd | < 22.6 |
CRITICAL | 9.1 | The Frontend File Manager Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and in… | — | wordfence |
| b50f98ca-6a51-4de8-9e89-004532ba8f96 | CRITICAL | 9.1 | The Colormix Theme for WordPress is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in all vers… | — | wordfence | |
| b3da58a5-3b07-4c53-ae20-35b3d7750023 | < 1.3.3.3 |
CRITICAL | 9.1 | The The MDTF β Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in … | — | wordfence |
| b2ef0410-3f8d-40e1-9188-43ec4e7077cd | CRITICAL | 9.1 | The Disable Comments | WPZest plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.51… | — | wordfence | |
| acb239c2-a105-4430-8451-a6ae852a690f | < 3.3.9 |
CRITICAL | 9.1 | The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Expo… | — | wordfence |
| ac37afa3-c841-44b5-9722-952c4258841d | CRITICAL | 9.1 | The KKProgressbar2 Free β advanced progress bars plugin for WordPress is vulnerable to SQL Injection in all versions u… | — | wordfence | |
| abdca93e-f68d-4a96-8bd7-443ee46ccb5a | < 1.9.0 |
CRITICAL | 9.1 | The Simple WP Events plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat… | — | wordfence |
| aa66da82-8733-41cb-a276-620577d79e44 | < 2.0.4 |
CRITICAL | 9.1 | The BWL Advanced FAQ Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.3… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →