Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 105 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f624c9a0-b48f-49f5-ba63-276805904945 | < 5.1.3 |
CRITICAL | 9.1 | The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.… | — | wordfence |
| f529b981-623f-4bd3-9155-ebfab4c65d1d | < 3.2 |
CRITICAL | 9.1 | The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all vers… | — | wordfence |
| f4831e75-dc0e-4d6f-b2cb-8498d8629319 | CRITICAL | 9.1 | The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val… | — | wordfence | |
| f28ca2dc-404d-4abf-9d44-1b1f8309e9ee | < 2.0.13 |
CRITICAL | 9.1 | The Post Grid plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.0.12. Th… | — | wordfence |
| f0c23687-2e79-460a-96eb-7d11bf883ced | CRITICAL | 9.1 | The Pk Favicon Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence | |
| ed053a6b-4163-4e82-a180-619a7841899a | < 5.8.0 |
CRITICAL | 9.1 | The WP Travel Engine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.9 due to … | — | wordfence |
| eccc47cb-9078-405b-9b09-2e14e72ee005 | < 2.0.3 |
CRITICAL | 9.1 | The Import XML and RSS Feeds plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and in… | — | wordfence |
| ecbc7f05-fc4f-4276-968e-04222a64e55a | < 4.5.5 |
CRITICAL | 9.1 | The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in ve… | — | wordfence |
| eb562efb-eb17-4366-9f6d-02653df6ece1 | < 1.8.25 |
CRITICAL | 9.1 | Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options im… | — | wordfence |
| ead5b943-731d-484a-a6b0-ca4f27eccff0 | < 4.9.6 |
CRITICAL | 9.1 | The Newsletters plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … | — | wordfence |
| eaafeadd-f44c-49b1-b900-ef40800c629e | < 10.0 |
CRITICAL | 9.1 | The Salon booking system plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and includ… | — | wordfence |
| e97c652c-f191-493d-9857-acaa4db8a49a | < 2.0.0 |
CRITICAL | 9.1 | Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0… | — | wordfence |
| e9506f84-3d33-48e0-8dce-d517e1a923e4 | < 3.9.0 |
CRITICAL | 9.1 | The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the… | — | wordfence |
| e66ae9e3-7455-4671-9fcb-f0d017ae3346 | < 1.10.30 |
CRITICAL | 9.1 | The Popup by Supsystic plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including,… | — | wordfence |
| e4fc23cb-e443-4c8e-b1a0-b8eefbb25dae | < 3.0.4 |
CRITICAL | 9.1 | The Edwiser Bridge plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.2 due to in… | — | wordfence |
| e4bfb72e-023b-4bfd-b125-91f6ac2f200f | < 3.15.4 |
CRITICAL | 9.1 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path v… | — | wordfence |
| e30fe90a-774c-41ba-b28e-8b8128fd72cc | < 2.0.1.8.2 |
CRITICAL | 9.1 | The Modal Survey plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.1.8 vi… | — | wordfence |
| e2f9b5ae-bbb9-4b1d-8762-6889a9b8a209 | < 4.14.14 |
CRITICAL | 9.1 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to mi… | — | wordfence |
| e2bb7e1b-0958-47fa-8929-a93ba28d105e | CRITICAL | 9.1 | The WPLMS Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation … | — | wordfence | |
| e074c818-8432-4ee1-a376-0abde3666bc3 | < 6.0 |
CRITICAL | 9.1 | The Simple User Registration plugin for WordPress is vulnerable to unauthorized access to the user deletion feature due … | — | wordfence |
| defb87dd-bf5f-411f-b948-699337d05d44 | < 6.10.34 |
CRITICAL | 9.1 | The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versio… | — | wordfence |
| dd42c83c-c51c-45a5-8ad5-0df2c0cc411d | < 2.2.2 |
CRITICAL | 9.1 | The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab… | — | wordfence |
| dcb73efb-496a-45eb-882b-1906f05bc3f5 | < 1.6.2 |
CRITICAL | 9.1 | The HDForms | Contact Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fil… | — | wordfence |
| dbda16f5-65c2-47cf-8b06-6aa231b8fd11 | < 3.0.8 |
CRITICAL | 9.1 | The Alphabetic Pagination plugin for WordPress is vulnerable to authorization bypass due to a missing capability check o… | — | wordfence |
| db57971b-57d8-4740-92e0-477a4368bd9b | < 2.9.3 |
CRITICAL | 9.1 | The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to arbitrary file deleti… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →