Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 104 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 655e6486-e35f-4e7b-b894-55606d3eba56 | < 1.5 |
CRITICAL | 9.6 | The WP Fast Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4… | — | wordfence |
| 63b67652-d10e-4a5a-97d5-04e6c848b752 | < 1.7.2 |
CRITICAL | 9.6 | The Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon WordPress plugin befo… | — | wordfence |
| 5b3f4ccb-fcc6-42ec-8e9e-03d69ae7acf2 | < 4.9.1 |
CRITICAL | 9.6 | The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as … | — | wordfence |
| 585d0368-7557-46aa-9ea3-26cd6d7df51b | < 4.57 |
CRITICAL | 9.6 | The SP Project & Document Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… | — | wordfence |
| 5717b835-7feb-4bb8-8f1b-1f44d4630cd3 | < 3.4.5 |
CRITICAL | 9.6 | The Ali2Woo Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.… | — | wordfence |
| 2fd58397-7598-4d98-a6b3-c5837cb3b73e | < 1.5.7 |
CRITICAL | 9.6 | The Armour Honeypot Anti Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce vali… | — | wordfence |
| 2be6c7d8-6dd4-4701-9baa-694496e7388a | CRITICAL | 9.6 | The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, whic… | — | wordfence | |
| 2b897790-43f7-4ca4-8abe-9dc736a7c011 | CRITICAL | 9.6 | The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which coul… | — | wordfence | |
| 25199281-5286-4d75-8d27-26ce215e0993 | < 4.9.1 |
CRITICAL | 9.6 | The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9… | — | wordfence |
| 24d08127-67b6-434a-8dbe-233a47854f9b | CRITICAL | 9.6 | The Add Post URL WordPress plugin through 2.1.0 does not have CSRF check in place when updating its settings, which coul… | — | wordfence | |
| 22b539c8-a6f1-4543-9e63-08ee4d468ee0 | < 1.0.5 |
CRITICAL | 9.6 | The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not s… | — | wordfence |
| 19b4a27d-d9de-4567-86cd-8ec821ee299a | < 2.5 |
CRITICAL | 9.6 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allow remote atta… | — | wordfence |
| 0a9b4c03-e7ec-48d6-87fe-67e8a5780703 | < 2.2.0 |
CRITICAL | 9.6 | The a3 Responsive Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
| 618f644b-a92c-4f7f-aaea-c03ee7d6e0f9 | < 2.0.46 |
CRITICAL | 9.4 | The Ultimate Member β User Profile, User Registration, Login & Membership Plugin plugin for WordPress is vulnerable to… | — | wordfence |
| f6f91414-5035-4cab-81ad-18558fe43500 | < 2.2.3 |
CRITICAL | 9.3 | The Better Search plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and in… | — | wordfence |
| ca38c423-2df8-4f20-bd95-2ecd84167a7f | < 4.0.1 |
CRITICAL | 9.3 | The Membership Plugin β Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password… | — | wordfence |
| 9729ebf5-ef78-4ef4-81d4-165f422c3847 | < 7.3.15.727 |
CRITICAL | 9.3 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to SQL injection in versions up to, and including, 7.3… | — | wordfence |
| 54a425b0-592a-433d-b9e7-776760536668 | < 3.3.1 |
CRITICAL | 9.3 | A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-d… | — | wordfence |
| 23d762e9-d43f-4520-a6f1-c920417a2436 | < 2.8.9 |
CRITICAL | 9.3 | The Post Form β Registration Form β Profile Form for User Profiles β Frontend Content Forms for User Submissions (… | — | wordfence |
| 224a2d6d-7fdc-43a8-a8c9-26213b604433 | CRITICAL | 9.3 | The WordPress Picture / Portfolio / Media Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in a… | — | wordfence | |
| fdd1359f-ce16-4cfe-a6a8-245a21ad16c9 | < 18.5 |
CRITICAL | 9.1 | The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient … | — | wordfence |
| fb85aacf-a8cf-4054-97fd-b285fcc2a7f9 | CRITICAL | 9.1 | The WP Pipes plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a… | — | wordfence | |
| faed1198-b8c4-46b1-b6a6-5fc35cd7bdf8 | < 2.0.22 |
CRITICAL | 9.1 | The Formidable Form Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including,… | — | wordfence |
| fa8f0688-8c54-43f8-acea-2aec2fcfbdce | < 3.7.43 |
CRITICAL | 9.1 | The MasterStudy LMS WordPress Plugin β for Online Courses and Education plugin for WordPress is vulnerable to Arbitrar… | — | wordfence |
| f9de8e90-5bda-4ab1-aa78-2748cd717376 | < 2.2.4 |
CRITICAL | 9.1 | The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →