Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 107 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| bee2245b-d039-48a7-a9dc-bd6ceac6cac6 | < 1.0.7 |
CRITICAL | 9.1 | The Contact Form Extender for Divi β Submissions DB & Extra Fields plugin for WordPress is vulnerable to arbitrary fil… | — | wordfence |
| bdb4468a-cd01-4f4c-9353-d77fcf7a558f | < 1.7.67 |
CRITICAL | 9.1 | The Shared Files (Free and Pro) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p… | — | wordfence |
| baa20290-9c01-4f8d-adeb-fbfb15b9d6a9 | CRITICAL | 9.1 | The Startklar Elementor Addons plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and incl… | — | wordfence | |
| b939ec4c-10c0-4c57-be6a-db443e59e22c | CRITICAL | 9.1 | The WordPress Upload Files Anywhere plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fi… | — | wordfence | |
| b90640d2-d6f4-4c3b-8e9b-038d57f5fd6f | < 4.5.4 |
CRITICAL | 9.1 | The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows un… | — | wordfence |
| b8034a3b-9a25-479d-b0d8-30ed4fd76333 | < 7.2.5 |
CRITICAL | 9.1 | The Broadcast Live Video β Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to arbitrary fi… | — | wordfence |
| b7bbeeea-3888-42a6-8d14-f5c39f5dcb70 | < 5.121.0 |
CRITICAL | 9.1 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, a… | — | wordfence |
| b6b0bb48-eb61-4236-a03f-19d5d2084a75 | CRITICAL | 9.1 | The Honeypot for WP Comment plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includi… | — | wordfence | |
| b59b5c41-6173-485e-869d-4165dc18e2bd | < 22.6 |
CRITICAL | 9.1 | The Frontend File Manager Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and in… | — | wordfence |
| b50f98ca-6a51-4de8-9e89-004532ba8f96 | CRITICAL | 9.1 | The Colormix Theme for WordPress is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in all vers… | — | wordfence | |
| b3da58a5-3b07-4c53-ae20-35b3d7750023 | < 1.3.3.3 |
CRITICAL | 9.1 | The The MDTF β Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in … | — | wordfence |
| b2ef0410-3f8d-40e1-9188-43ec4e7077cd | CRITICAL | 9.1 | The Disable Comments | WPZest plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.51… | — | wordfence | |
| ae000d8a-802d-440e-9fbf-8c3b0a4a7f02 | < 9.2.07.002 |
CRITICAL | 9.1 | The Photo Album Plus plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 9.2… | — | wordfence |
| acb239c2-a105-4430-8451-a6ae852a690f | < 3.3.9 |
CRITICAL | 9.1 | The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Expo… | — | wordfence |
| ac37afa3-c841-44b5-9722-952c4258841d | CRITICAL | 9.1 | The KKProgressbar2 Free β advanced progress bars plugin for WordPress is vulnerable to SQL Injection in all versions u… | — | wordfence | |
| abdca93e-f68d-4a96-8bd7-443ee46ccb5a | < 1.9.0 |
CRITICAL | 9.1 | The Simple WP Events plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat… | — | wordfence |
| aa66da82-8733-41cb-a276-620577d79e44 | < 2.0.4 |
CRITICAL | 9.1 | The BWL Advanced FAQ Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.3… | — | wordfence |
| a9f5eab2-09d9-4d8e-8024-abf02b0f6b86 | < 1.1.6 |
CRITICAL | 9.1 | The Movie Booking plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation… | — | wordfence |
| a8447fa0-f994-4de3-b6e7-2fe61e06bed1 | < 3.3.2 |
CRITICAL | 9.1 | The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determi… | — | wordfence |
| a555da8f-586a-4fb8-9230-9238df73cba4 | < 1.1.14 |
CRITICAL | 9.1 | The Music Store β WordPress eCommerce plugin for WordPress is vulnerable to SQL Injection in all versions up to, and i… | — | wordfence |
| a2248ba8-b7d7-4691-bf7c-8b23c24417f7 | < 3.2 |
CRITICAL | 9.1 | The WP Custom Cursors | WordPress Cursor Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_row' p… | — | wordfence |
| a147956c-a4d8-4945-997a-9b7cea60f926 | < 11.2.0 |
CRITICAL | 9.1 | The PitchPrint plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in… | — | wordfence |
| a125bbf1-8ff6-4f3d-a4fb-caaaefe1df2a | < 1.7.14 |
CRITICAL | 9.1 | The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and … | — | wordfence |
| 9e20afee-9336-458e-ab5c-b320c6887b83 | CRITICAL | 9.1 | The 10Web Map Builder for Google Maps plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… | — | wordfence | |
| 9cb7bc91-b2e9-4ede-80cf-6b961ac6dcb9 | < 0.3.0 |
CRITICAL | 9.1 | An issue was discovered in WPGraphQL up to 0.2.3 . By querying the 'users' RootQuery, it is possible, for an unauthentic… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →