Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 103 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ffaf7a75-de27-4361-ba04-ff17151b7eb5 | CRITICAL | 9.6 | The Site Offline or Coming Soon WordPress plugin through 1.6.6 does not have CSRF check in place when updating its setti… | — | wordfence | |
| fc9dfe96-2d43-4b7b-a91a-87cdaaab8e49 | < 1.7.2 |
CRITICAL | 9.6 | The Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX act… | — | wordfence |
| f908837d-2bba-45db-b005-f685a33cd71e | CRITICAL | 9.6 | The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could a… | — | wordfence | |
| f8bcf51a-36ee-4d4d-b9d6-d9db0dafd791 | < 2.32.11 |
CRITICAL | 9.6 | The 10Web Booster β Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to arb… | — | wordfence |
| f4703ca7-0677-4128-b9b7-31132ff1804d | < 4.2 |
CRITICAL | 9.6 | The Jetpack β WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to CSV Injection in versions up … | — | wordfence |
| ef5028a0-6a5a-40ad-92df-ffc988cad389 | < 4.09.05 |
CRITICAL | 9.6 | The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img… | — | wordfence |
| d8e23501-9fc4-484b-b308-a9c51494bc9d | CRITICAL | 9.6 | The LaTeX for WordPress plugin through 3.4.10 does not have CSRF check in place when updating its settings, which could … | — | wordfence | |
| cacd31bd-ccc6-49fa-89f1-09f3c5cd9072 | < 4.4.5 |
CRITICAL | 9.6 | The Captcha plugin for WordPress contained a backdoor that injected SEO spam into unsuspecting users WordPress sites in … | — | wordfence |
| c8abcc7b-6c68-4fc8-81af-e88624e417dd | < 5.1.0 |
CRITICAL | 9.6 | The AutomatorWP β Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for Wor… | — | wordfence |
| c79a173d-b9c3-4554-95e7-2a4b87382079 | CRITICAL | 9.6 | The OpenBook Book Data WordPress plugin through 3.5.2 does not have CSRF check in place when updating its settings, whic… | — | wordfence | |
| b5490dd9-20d5-4cd6-bc09-5da94d3e702f | < 4.1.5.3 |
CRITICAL | 9.6 | The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discov… | — | wordfence |
| a50531df-e876-463c-a06b-16b2f30aeefe | < 3.7.29 |
CRITICAL | 9.6 | WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated use… | — | wordfence |
| 9e6365ab-30c5-4bec-a5f3-b0812ae8a609 | < 2.4.1 |
CRITICAL | 9.6 | The New User Approve WordPress plugin before 2.4.1 does not have CSRF check in place when updating its settings and addi… | — | wordfence |
| 9e3f199b-b75d-43a2-a20c-957fb1b512e1 | CRITICAL | 9.6 | The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache image… | — | wordfence | |
| 92d59dd4-7338-40ac-9a73-37e9e85351d7 | < 3.1.1 |
CRITICAL | 9.6 | Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.1.0 and earlier allow remote attacker… | — | wordfence |
| 8f4ae82c-f249-4094-a0ef-568c3a30d16b | CRITICAL | 9.6 | The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, wh… | — | wordfence | |
| 8df77bb7-4453-403d-8d35-66251f6d399c | CRITICAL | 9.6 | The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allo… | — | wordfence | |
| 8b776a8a-b071-4caf-9e67-6f08ace4da2a | < 2.5 |
CRITICAL | 9.6 | The ND Booking plugin for WordPress is vulnerable to arbitrary options update in versions up to, and including 2.4, due … | — | wordfence |
| 82acefe0-a839-4721-858d-120326e45664 | < 3.1.4 |
CRITICAL | 9.6 | The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make… | — | wordfence |
| 812d99bc-8d86-44a9-bafa-be8ce979229c | < 3.7.10 |
CRITICAL | 9.6 | Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers t… | — | wordfence |
| 7ffac29d-d1cc-4d5d-aff8-0cb639a1e3d7 | < 2.8.5 |
CRITICAL | 9.6 | EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving … | — | wordfence |
| 7ea13a80-c744-4de3-ac19-178b67e1afc4 | CRITICAL | 9.6 | The MyAnime Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… | — | wordfence | |
| 7817a840-325a-4709-8374-84bb32d98d0e | < 1.25.0 |
CRITICAL | 9.6 | The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.… | — | wordfence |
| 6eb3ad80-3510-4018-91af-b733ef62e28f | < 2.1 |
CRITICAL | 9.6 | The Favicon Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence |
| 65b2b72a-5c76-463e-9513-26b400b40a65 | CRITICAL | 9.6 | The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its setting… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →