Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 106 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d8fb20fb-a795-4ab0-9614-6ae6ac4f2eda | < 2.2.1 |
CRITICAL | 9.1 | The Images Optimize and Upload CF7 plugin for WordPress is vulnerable to authorization bypass due to a missing capabilit… | — | wordfence |
| d8d6684a-5e79-4103-921d-4d997deecd23 | < 3.4.07 |
CRITICAL | 9.1 | The UiPress lite plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.4.06 due to ins… | — | wordfence |
| d7d68f43-2a57-4352-8aae-0657b386ac7c | < 4.0.2 |
CRITICAL | 9.1 | The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to… | — | wordfence |
| d7d381af-bb2a-43cb-9e5d-0b3d0e5f88f0 | < 2.8.8 |
CRITICAL | 9.1 | The Download Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the… | — | wordfence |
| d6ad49ff-85eb-4d05-ba23-51d89695add3 | < 10.8.2 |
CRITICAL | 9.1 | The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and inclu… | — | wordfence |
| d65eeb25-8c94-44e9-976d-db5d42e2d06e | < 12.7 |
CRITICAL | 9.1 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1… | — | wordfence |
| d5d23a02-11b6-4674-a13a-884de2d51ed7 | < 3.8.28 |
CRITICAL | 9.1 | The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, lead… | — | wordfence |
| d5b74a84-e418-4bd4-b36e-5bd4ba5197c9 | < 10.8 |
CRITICAL | 9.1 | The Salon booking system plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in versions up to… | — | wordfence |
| d4bbb00b-4baf-4dc1-85ab-3ca3d59eaf33 | < 6.1 |
CRITICAL | 9.1 | The Easy Forms for Mailchimp for WordPress is vulnerable to Local File Inclusion in versions before 6.1 via the vulnerab… | — | wordfence |
| d45a01e5-0e69-4d95-b609-b9002b3776da | < 28.3 |
CRITICAL | 9.1 | The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2… | — | wordfence |
| d430c863-6af1-4519-b276-3bf7e2b2d3c2 | < 3.1.7 |
CRITICAL | 9.1 | The Advanced Product Fields Extended for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due t… | — | wordfence |
| d2fdd6eb-c848-446c-abad-7d2ea93f5512 | < 4.0.8 |
CRITICAL | 9.1 | The WP User Frontend plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, … | — | wordfence |
| d1a3bc4b-cc17-4728-b242-13841b5f7660 | CRITICAL | 9.1 | The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.… | — | wordfence | |
| d0567dc8-7a4c-42f4-bf45-f31a8efaa354 | < 3.53.3 |
CRITICAL | 9.1 | The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including… | — | wordfence |
| cf0265cb-d58d-4680-8d5b-9b9334f7721e | CRITICAL | 9.1 | The FW Food Menu β Responsive food menu with ordering & delivery solutions plugin for WordPress is vulnerable to arbit… | — | wordfence | |
| cecf1bcc-ed3e-430c-80d4-d940416eed9a | < 2.1.6 |
CRITICAL | 9.1 | The Import XML and RSS Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… | — | wordfence |
| cc5cee40-32a4-499a-ba34-97e07a276a36 | CRITICAL | 9.1 | The Hostme v2 - Responsive WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuffici… | — | wordfence | |
| cc046b72-692a-4980-90ad-26c8fc2a131a | < 1.3.65 |
CRITICAL | 9.1 | The Ultimate Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.64 … | — | wordfence |
| c9df788e-a92e-4519-9e23-8aed08479b68 | < 2.0 |
CRITICAL | 9.1 | The User Activity Log plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9 due to i… | — | wordfence |
| c85fa04e-477e-4ac9-b112-02b2ab18ca32 | < 1.9.1 |
CRITICAL | 9.1 | The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in versions… | — | wordfence |
| c7f1ffba-bae2-4f69-ac96-c4570d36eb73 | < 7.0.1 |
CRITICAL | 9.1 | The Openpos - WooCommerce Point Of Sale(POS) plugin for WordPress is vulnerable to arbitrary file deletion due to insuff… | — | wordfence |
| c6f3b765-396f-422f-864d-a48bee8c69cb | CRITICAL | 9.1 | The Quicksand Post Filter jQuery Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing… | — | wordfence | |
| c458e6d6-28ba-4465-ace2-5da9e99ca2c7 | < 3.9.1 |
CRITICAL | 9.1 | The DecaLog plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.9.0 due to insuf… | — | wordfence |
| c3ccde73-8b88-48f9-8bbd-0392fcc40c81 | < 4.9.5 |
CRITICAL | 9.1 | The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pa… | — | wordfence |
| c2d6e619-c32a-450a-a4a0-1069becabff6 | < 1.4.48 |
CRITICAL | 9.1 | The Support Genix β Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is v… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →