Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 106 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 21389122-cb39-45d1-a889-b830d3a55603 | < 3.1.39 |
CRITICAL | 9.1 | The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, … | — | wordfence |
| 1fe40943-d2b5-47e9-bc3b-712b5e161099 | < 2.5.2 |
CRITICAL | 9.1 | The Droip plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all … | — | wordfence |
| 1fcd44c2-5b06-4c3c-b6b2-c58771245fe2 | < 1.0.1 |
CRITICAL | 9.1 | Server-side request forgery (SSR) vulnerability in the WP Smart Import (wp-smart-import) plugin 1.0.0 for WordPress via … | — | wordfence |
| 1dd3e203-dcc4-47b5-ab65-324bcff5b91b | < 7.0.3 |
CRITICAL | 9.1 | SQL injection vulnerability in se_search_default in the Search Everything plugin before 7.0.3 for WordPress allows remot… | — | wordfence |
| 19c4d9f5-ffc4-4778-bbf8-2bb770018c3e | < 1.0.65 |
CRITICAL | 9.1 | The Oxygen MyData for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file… | — | wordfence |
| 1746da3b-397d-4027-b76d-4c57fadf32c4 | < 1.1.1 |
CRITICAL | 9.1 | Absolute path traversal vulnerability in the Image Export plugin 1.1 for WordPress allows remote attackers to read and d… | — | wordfence |
| 16dca898-1a98-4e0b-8f48-dc01ba2dc4e6 | < 1.1.9 |
CRITICAL | 9.1 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all … | — | wordfence |
| 15f3a6e1-6126-4825-b2b1-e40dc5694f43 | < 3.9.2 |
CRITICAL | 9.1 | The Atarim - Client Interface plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing c… | — | wordfence |
| 15880d3b-87de-4b59-878c-e36e73c45e8a | CRITICAL | 9.1 | The WPRecovery plugin for WordPress is vulnerable to SQL Injection via the 'data[id]' parameter in all versions up to, a… | — | wordfence | |
| 15494ccf-7c9d-4566-9e80-2da94172a3dd | < 2.4.0 |
CRITICAL | 9.1 | The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… | — | wordfence |
| 14ff5609-2345-4073-8239-0ce27fa0957c | < 1.8.11 |
CRITICAL | 9.1 | The Slider by Supsystic plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.8.10… | — | wordfence |
| 14877ff6-e393-41a3-91c1-fe7f477297cc | CRITICAL | 9.1 | The Image Resizer On The Fly plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path… | — | wordfence | |
| 13c03af2-0bd8-4e81-8ae9-2d702da71fc8 | CRITICAL | 9.1 | The Simple Photo Gallery plugin for WordPress is vulnerable to generic SQL Injection via the ‘item’ parameter in ver… | — | wordfence | |
| 12e2645c-7df1-4fbe-baa1-6b932062682b | CRITICAL | 9.1 | The real3d-flipbook-lite plugin 1.0 for WordPress has deleteBook=../ directory traversal for file deletion. | — | wordfence | |
| 120e6a19-fae3-4083-a72e-36867e7eb18a | CRITICAL | 9.1 | The Advanced XML Reader plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in versions up to, and… | — | wordfence | |
| 0ee4fe34-e6ae-4f37-a1a7-ebb153ae7a67 | CRITICAL | 9.1 | The Realia plugin for WordPress is vulnerable to Arbitrary Post Deletion in versions up to, and including, 1.4.0. This i… | — | wordfence | |
| 0e656123-cae4-4e0c-a80a-98526be293a8 | CRITICAL | 9.1 | The Database Toolset plugin is vulnerable to arbitrary file deletion due to insufficient file path validation in a funct… | — | wordfence | |
| 0cee20a7-3730-4ee8-85db-79d9d2e9e4c4 | < 3.1.1 |
CRITICAL | 9.1 | The Membership For WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pa… | — | wordfence |
| 0af80be2-b80b-4a25-9df6-a8ae75ad9cdd | CRITICAL | 9.1 | An Information Disclosure / Data Modification issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugi… | — | wordfence | |
| 0a540897-694a-43d1-bdd8-5aeb07389a51 | < 3.0 |
CRITICAL | 9.1 | SQL injection vulnerability in the videos page in the HDW Player Plugin (hdw-player-video-player-video-gallery) 2.4.2 fo… | — | wordfence |
| 097a9d0f-fa38-4fdc-9048-43dd65e7652c | < 1.10.0 |
CRITICAL | 9.1 | The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability chec… | — | wordfence |
| 07fc1249-a50d-4038-8cbe-35ff7a3d28b3 | < 0.8.9.6 |
CRITICAL | 9.1 | The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversa… | — | wordfence |
| 072b66dd-a5d3-46b5-92ec-9cc83b8ea8ef | CRITICAL | 9.1 | The WP Testimonial Widget plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.1 … | — | wordfence | |
| 04bfad0d-9c6d-41b6-8c59-516eceef9a36 | CRITICAL | 9.1 | WordPress Portable phpMyAdmin Plugin version 1.5.0 and below has an authentication bypass vulnerability. | — | wordfence | |
| 0395b775-a89d-45f5-ac38-d5786f4b4d1b | < 1.9.3.6 |
CRITICAL | 9.1 | The Gravifyforms plugin for WordPress is vulnerable to blind SQL Injection via the ‘sort_column GET’ parameter in ve… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →