Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 104 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 682a7439-d10a-48b7-84c5-60ac00cf7879 | < 3.0.6 |
CRITICAL | 9.1 | The Paid Memberships Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.5 due… | — | wordfence |
| 66af88ab-716f-43c9-8c05-148c3f14f676 | CRITICAL | 9.1 | The PT Luxa Addons plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validatio… | — | wordfence | |
| 654b28a2-36e7-4226-abda-5c666e54c2de | CRITICAL | 9.1 | The E-xact | Hosted Payment | plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pat… | — | wordfence | |
| 63922c28-0cb5-4abe-85ee-20b2cc6f015d | < 0.0.9 |
CRITICAL | 9.1 | The Demi β One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory… | — | wordfence |
| 6215fa9f-06bc-4dc8-b1f5-a3bb75749f1d | < 4.9.9.1 |
CRITICAL | 9.1 | The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a… | — | wordfence |
| 5feb08ff-3e1a-4a5c-88d9-1c07409d0c8c | < 7.3.1 |
CRITICAL | 9.1 | The Paid Videochat Turnkey Site β HTML5 PPV Live Webcams plugin for WordPress is vulnerable to arbitrary file deletion… | — | wordfence |
| 5bb962bd-9b23-4820-885e-d8095250c3c7 | < 2.5.3 |
CRITICAL | 9.1 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletio… | — | wordfence |
| 594c9b09-6abc-4028-889d-46b5394b368a | < 3.1 |
CRITICAL | 9.1 | The Litho theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all v… | — | wordfence |
| 5731b971-4408-4c64-809c-e95fba33009e | CRITICAL | 9.1 | The Attachment Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid… | — | wordfence | |
| 554fb91b-35eb-43c4-b949-4f07143e013f | < 6.2.1 |
CRITICAL | 9.1 | The Broadcast Live Video β Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to arbitrary fi… | — | wordfence |
| 53adbab6-953a-4a6f-bbfc-89efdbdd28e0 | < 3.28.26 |
CRITICAL | 9.1 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modifi… | — | wordfence |
| 511f64df-4389-4ad7-b2a4-12dc57714631 | CRITICAL | 9.1 | The Advanced Page Visit Counter plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.… | — | wordfence | |
| 4e6b9ced-b303-43fe-8622-a32685f0a4ea | < 2.10.1 |
CRITICAL | 9.1 | The Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation… | — | wordfence |
| 49fcd2cb-d880-4152-a736-33fd90f07083 | < 1.1.3 |
CRITICAL | 9.1 | The WP Child Theme Generator plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and inc… | — | wordfence |
| 47cf9b2c-6857-4dbc-b321-1a84c3e5d11f | CRITICAL | 9.1 | The FW Gallery β Photo, video, audio media presentation and management system with players and slideshow plugin for Wo… | — | wordfence | |
| 46ab2615-a1eb-4740-836c-781e961252e7 | CRITICAL | 9.1 | The Product Feed on WooCommerce for Google plugin for WordPress is vulnerable to SQL Injection in versions up to, and in… | — | wordfence | |
| 46093b88-2f3c-4e06-833c-6a073cafda0f | < 2.7.8.4 |
CRITICAL | 9.1 | The Participants Database plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path va… | — | wordfence |
| 446522ea-7cf1-449b-b05c-58eb815142a4 | CRITICAL | 9.1 | The The School Management Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, … | — | wordfence | |
| 41fd12b8-8269-484e-a137-a2c9341b27fe | < 3.0.0 |
CRITICAL | 9.1 | The CM Download Manager β Simplify file sharing with powerful download management plugin for WordPress is vulnerable t… | — | wordfence |
| 4183c3f7-7794-45f3-8fad-b87ffec3639c | < 1.4.12 |
CRITICAL | 9.1 | The Prisna GWT β Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions … | — | wordfence |
| 417186ba-36ef-4d06-bbcd-e85eb9219689 | < 5.6.24 |
CRITICAL | 9.1 | The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 v… | — | wordfence |
| 3e1f64f5-090a-4961-8490-d34f458a8d44 | < 1.1.9 |
CRITICAL | 9.1 | The JS Job Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the j… | — | wordfence |
| 3d7af96a-5a3c-4291-a369-f6ed78f72a3f | < 4.1.3 |
CRITICAL | 9.1 | The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insuffi… | — | wordfence |
| 3d4cf93d-61af-4721-9751-9891e08ce7b8 | < 11.7 |
CRITICAL | 9.1 | The WPO365 | LOGIN plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This le… | — | wordfence |
| 3aaa9c58-87da-4221-b687-f365c6bde167 | < 7.0 |
CRITICAL | 9.1 | The Chauffeur Taxi Booking System for WordPress plugin for WordPress is vulnerable to authenticated bypass in all versio… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →