Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 107 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 02b24735-0310-4b00-9acc-a05557238697 | CRITICAL | 9.1 | The Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … | — | wordfence | |
| 0298f5e6-36b6-4005-b6ef-d38f2f86f0b1 | CRITICAL | 9.1 | The ENL Newsletter plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and… | — | wordfence | |
| 0227cc13-8f19-43a2-95a1-f6e729baf256 | < 1.4.3 |
CRITICAL | 9.1 | The WP Pipes plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation via … | — | wordfence |
| 021bd566-1663-46ba-a616-ab554b691cbb | < 4.3.3 |
CRITICAL | 9.1 | The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the… | — | wordfence |
| 00bcfd8f-9785-449a-a0ea-16e2583d684a | < 6.4.0.2 |
CRITICAL | 9.1 | The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6… | — | wordfence |
| e32a2644-df8a-4aea-8e70-49ab3075be9e | < 1.5.4 |
CRITICAL | 9.0 | PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ… | — | wordfence |
| d7e81331-0b39-4490-8624-38078b3d5420 | < 4.23.56 |
CRITICAL | 9.0 | The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Remote Code Execution in all ve… | — | wordfence |
| d1e5131a-9e72-441d-971c-8b9af35cf3f7 | < 4.5 |
CRITICAL | 9.0 | The CoDesigner WooCommerce Builder for Elementor β Customize Checkout, Shop, Email, Products & More plugin for WordPre… | — | wordfence |
| CVE-2026-9082 KEV | CRITICAL | 9.0 | Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution v… | — | cisa_kev | |
| CVE-2026-63030 KEV | CRITICAL | 9.0 | WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection a… | — | cisa_kev | |
| CVE-2026-60137 KEV | CRITICAL | 9.0 | WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. Th… | — | cisa_kev | |
| CVE-2026-56290 KEV | CRITICAL | 9.0 | Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via u… | — | cisa_kev | |
| CVE-2026-54420 KEV | CRITICAL | 9.0 | LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP… | — | cisa_kev | |
| CVE-2026-48907 KEV | CRITICAL | 9.0 | Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and … | — | cisa_kev | |
| CVE-2026-48172 KEV | CRITICAL | 9.0 | LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, whic… | — | cisa_kev | |
| CVE-2026-41940 KEV | CRITICAL | 9.0 | WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the… | — | cisa_kev | |
| CVE-2026-34486 KEV | CRITICAL | 9.0 | Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterce… | — | cisa_kev | |
| CVE-2026-34197 KEV | CRITICAL | 9.0 | Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection. | — | cisa_kev | |
| CVE-2025-24813 KEV | CRITICAL | 9.0 | Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose informat… | — | cisa_kev | |
| CVE-2024-4577 KEV | CRITICAL | 9.0 | PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arb… | — | cisa_kev | |
| CVE-2024-45195 KEV | CRITICAL | 9.0 | Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access. | — | cisa_kev | |
| CVE-2024-38856 KEV | CRITICAL | 9.0 | Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy paylo… | — | cisa_kev | |
| CVE-2024-38475 KEV | CRITICAL | 9.0 | Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map U… | — | cisa_kev | |
| CVE-2024-32113 KEV | CRITICAL | 9.0 | Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution. | — | cisa_kev | |
| CVE-2024-27348 KEV | CRITICAL | 9.0 | Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute … | — | cisa_kev |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →