Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 105 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 3a4179ef-c98b-42c9-b7e5-a42bc46eaad1 | < 10.6.6 |
CRITICAL | 9.1 | The Wp EMember plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all v… | — | wordfence |
| 3a3b8f32-f29d-4e67-8fad-202bfc8a9918 | < 1.8.20 |
CRITICAL | 9.1 | The Photo Gallery by 10Web β Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Directory Traversal i… | — | wordfence |
| 386eea84-0b86-46c8-99a2-c73696ae09be | < 1.18 |
CRITICAL | 9.1 | The WordPress RokNewsPager plugin is vulnerable to Denial of Service via the 'src' parameter in the 'thumb.php' file in … | — | wordfence |
| 38526b0c-a5d9-4f54-bd6f-30ab34d266f5 | < 3.6.16 |
CRITICAL | 9.1 | The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including, 3.6.15 … | — | wordfence |
| 38398f29-1bd7-4f15-9d7e-7ad52264f5c7 | < 4.7.5 |
CRITICAL | 9.1 | The Noo JobMonster theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation… | — | wordfence |
| 366e5302-3edc-4bc8-8d84-9e0ee7abb25a | CRITICAL | 9.1 | The WordPress RokBox plugin is vulnerable to Content Spoofing via the 'file', 'config', and 'abouttext' parameters in th… | — | wordfence | |
| 35e2f081-41ca-4465-933a-db5c30b058da | < 2.7.1 |
CRITICAL | 9.1 | The WP Easy Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 'galleryId' or 'select_gallery' … | — | wordfence |
| 34f0e5a6-0bd3-4734-b7e0-27dc825d193f | < 7.0.2.1 |
CRITICAL | 9.1 | The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,… | — | wordfence |
| 32da04ba-bee3-4fd3-b91b-57e588d5f4e4 | < 2.2.2 |
CRITICAL | 9.1 | The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab… | — | wordfence |
| 3060dbda-97f3-410c-863e-ea76a6a018fd | < 1.11.4 |
CRITICAL | 9.1 | The Z-Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … | — | wordfence |
| 2ef0ab24-ec21-4d23-980d-71a23bf20f9e | < 2.2.7 |
CRITICAL | 9.1 | The Responsive Ready Sites Importer for WordPress is vulnerable to authorization bypass due missing capability checks on… | — | wordfence |
| 2e0ca51c-0536-45ff-a5af-41ef4977179d | < 1.6.3 |
CRITICAL | 9.1 | The SearchWP Live Ajax Search plugin for WordPress is vulnerable to Directory Traversal via the 'swpengine' parameter us… | — | wordfence |
| 2ddfb494-1a63-4958-849e-392eec09615d | CRITICAL | 9.1 | The formcraft plugin for WordPress is vulnerable to Arbitrary File Deletion via the 'function.php' file. This makes it p… | — | wordfence | |
| 2d903c78-2c7e-45fb-a8b4-ae060d9a020c | < 1.4 |
CRITICAL | 9.1 | The ionCube Tester Plus plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3. … | — | wordfence |
| 2d34b675-ff66-475e-b838-657dd51fc48c | < 6.4.4 |
CRITICAL | 9.1 | The Auto Affiliate Links plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.4.3… | — | wordfence |
| 2cf2201d-6da0-4f66-9135-c6b34ef7c65f | < 2.0.7 |
CRITICAL | 9.1 | The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated "site administrator" users to exec… | — | wordfence |
| 2cb1b526-0df6-42a1-9294-90bc61730209 | < 7.8.7 |
CRITICAL | 9.1 | The Alone β Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file deleti… | — | wordfence |
| 2a56eb63-ba5c-4452-8ab9-f5aeaf53adda | < 7.27 |
CRITICAL | 9.1 | The W3SPEEDSTER plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.26 v… | — | wordfence |
| 27180d98-223a-4d86-b8ea-e47da1d61bbf | < 5.5.16 |
CRITICAL | 9.1 | The Live Streaming - Broadcast Live Video Plugin for WordPress is vulnerable to Remote Code Execution in versions up to,… | — | wordfence |
| 26e7dd3f-5bdd-47d2-a013-82db72b4eae6 | < 240325 |
CRITICAL | 9.1 | The s2Member plugin for WordPress is vulnerable to limited privilege escalation in versions up to, and including, 240315… | — | wordfence |
| 2591af6b-e057-4c17-aeba-5c31efbae622 | < 2.5 |
CRITICAL | 9.1 | The DejaVu Theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.4. This is d… | — | wordfence |
| 24a802cc-bec3-48ac-a2af-34fba3939c17 | CRITICAL | 9.1 | The Global Gateway e4 | Payeezy Gateway | plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici… | — | wordfence | |
| 245d89e5-52cc-44b1-a858-0ca0aacb4e26 | CRITICAL | 9.1 | The Custom Searchable Data Entry System plugin for WordPress is vulnerable to unauthenticated database wiping in version… | — | wordfence | |
| 242ad00b-3602-4988-ab7a-76fba2e9d4cf | < 1.3.0 |
CRITICAL | 9.1 | The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insuffi… | — | wordfence |
| 224233bc-68f3-40e4-8182-4831ccce93fb | < 1.29.3 |
CRITICAL | 9.1 | The Forminator β Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to SQL Injection … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →