Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 103 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 885dd550-4c80-4e36-8dae-cb47c1500ea5 | CRITICAL | 9.1 | The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-gui… | — | wordfence | |
| 8834d017-04e8-4748-9acc-3f2213fc8592 | CRITICAL | 9.1 | The CarZone - A Complete Car Dealer HTML Wire-Frame theme for WordPress is vulnerable to arbitrary file deletion due to … | — | wordfence | |
| 86d5af9f-ffe9-4d22-885d-e117da7687de | < 3.4.5 |
CRITICAL | 9.1 | The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up… | — | wordfence |
| 86218eaa-916b-4197-8fa4-62b527bd29a4 | CRITICAL | 9.1 | The Anona - Pest Control WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficien… | — | wordfence | |
| 84ed666c-3154-4f26-beae-aba190f7a2f4 | < 10.1.5 |
CRITICAL | 9.1 | The Import Spreadsheets from Microsoft Excel plugin for WordPress is vulnerable to arbitrary file uploads due to missing… | — | wordfence |
| 813532fd-0613-47df-a4d0-54d6b33f37b3 | CRITICAL | 9.1 | The Zynith SEO plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of serv… | — | wordfence | |
| 80303684-5e10-474b-b6be-a63327015826 | CRITICAL | 9.1 | The Forms to Zapier, Integromat, IFTTT, Workato, Automate.io, elastic.io, Built.io, APIANT, Webhook plugin for WordPress… | — | wordfence | |
| 7eada9b7-8d53-4e95-858e-aa706f74b2a1 | < 6.1.10 |
CRITICAL | 9.1 | The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including, 6.1… | — | wordfence |
| 7c387a20-47dd-42d9-bf22-a28c613c5bde | < 2.2.0 |
CRITICAL | 9.1 | The Comic Book Management System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2… | — | wordfence |
| 78072f78-1c87-4ce0-b712-e10a25096316 | < 4.0.2 |
CRITICAL | 9.1 | The Media folder Addon plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4… | — | wordfence |
| 77db9906-ff6f-400c-bb02-8c64eb016a77 | < 2.2 |
CRITICAL | 9.1 | The Method Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.1. This is d… | — | wordfence |
| 7612b680-fb4a-4c5a-aa46-fb3473da78b4 | < 3.2.4 |
CRITICAL | 9.1 | The Count Per Day plugin for WordPress is vulnerable to Path Disclosure and Denial of Service in versions up to, and inc… | — | wordfence |
| 746ed5d5-983f-40b1-b12b-f7cbe231597c | < 1.7.12 |
CRITICAL | 9.1 | The Workscout Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validatio… | — | wordfence |
| 74403688-06a0-453f-ac44-bd731c389892 | < 2.7.2 |
CRITICAL | 9.1 | The JS Help Desk plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an unkn… | — | wordfence |
| 73efd9ad-9515-4ca8-bfb3-1d478f39c2b9 | < 3.2.3 |
CRITICAL | 9.1 | The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuffi… | — | wordfence |
| 73b78d92-5a91-4db7-ab8b-0867e4464516 | CRITICAL | 9.1 | The Database Toolset plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat… | — | wordfence | |
| 738eb021-1166-4fbe-a502-2db12c6533c3 | < 1.4.11 |
CRITICAL | 9.1 | The OSS Aliyun plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.10 due to insuf… | — | wordfence |
| 71aa14b8-39bc-4b91-a7cf-9d203fdf44ea | < 1.7 |
CRITICAL | 9.1 | The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing … | — | wordfence |
| 7167a731-8677-4ae2-a790-00a8295c9191 | < 6.1.5 |
CRITICAL | 9.1 | The Fancy Product Designer plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.1… | — | wordfence |
| 70a14d11-6525-465c-8fc6-0920af748027 | < 1.4.1 |
CRITICAL | 9.1 | The Squeeze plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all vers… | — | wordfence |
| 6c8720bc-7431-416a-8da3-62c49e2f2afd | < 3.1.0 |
CRITICAL | 9.1 | The BuddyPress XProfile Custom Image Field plugin for WordPress is vulnerable to arbitrary file deletion due to insuffic… | — | wordfence |
| 6c01f098-5fd6-4c4b-9744-c902108ed72a | < 3.1.3 |
CRITICAL | 9.1 | The WP-BusinessDirectory β Business directory plugin for WordPress plugin for WordPress is vulnerable to arbitrary fil… | — | wordfence |
| 6b839c7d-76fb-465e-9f27-1882cf0099fa | < 2.12.0 |
CRITICAL | 9.1 | The WooCommerce Chained Products plugin for WordPress is vulnerable to authorization bypass due to a missing capability … | — | wordfence |
| 6b3a0ceb-f42b-42dd-9308-cd66122ebb7f | < 2.1.0 |
CRITICAL | 9.1 | The Plug your WooCommerce into the largest catalog of customized print products from Helloprint plugin for WordPress is … | — | wordfence |
| 6a061553-c988-4a31-a0a2-7a2608faa33f | < 1.3.5 |
CRITICAL | 9.1 | The Backuply β Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →