Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 11 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f6f7bff6-3bc3-4572-97fd-a039d54ac0ff | < 1.6.27 |
CRITICAL | 9.8 | The WP RealEstate plugin for WordPress, used by the Homeo theme, is vulnerable to privilege escalation in all versions u… | — | wordfence |
| f6f3f82e-6b1b-4138-b8f3-82e8dcd24479 | < 2.3.2 |
CRITICAL | 9.8 | The Phlox Portfolio plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.3… | — | wordfence |
| f6e4c583-c0d5-4040-86d5-0f1b4dddcb81 | < 4.29.5 |
CRITICAL | 9.8 | Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin befo… | — | wordfence |
| f6aead8d-c136-4952-ad03-86fe0f144dea | < 0.1.0.23 |
CRITICAL | 9.8 | The InstaWP Connect β 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due … | — | wordfence |
| f691ef0e-4649-4b06-860e-8e07375a9284 | CRITICAL | 9.8 | The Smart Sections Theme Builder - WPBakery Page Builder Addon plugin for WordPress is vulnerable to PHP Object Injectio… | — | wordfence | |
| f661f19d-fdd4-4cd3-8fb3-8b6073d94596 | < 1.3.6 |
CRITICAL | 9.8 | The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… | — | wordfence |
| f655704d-70a1-40d8-ae36-39029185d262 | < 10.6.7 |
CRITICAL | 9.8 | The RSVPMarker plugin for WordPress is vulnerable to SQL Injection via the 'email' parameter in versions up to, and inc… | — | wordfence |
| f5eb066b-8ab4-47e7-b055-4a9d7a897a3c | < 1.0.24 |
CRITICAL | 9.8 | The Booking Calendar Contact Form plugin for WordPress is vulnerable to blind SQL Injection via the βidβ parameter i… | — | wordfence |
| f5b28fc2-4551-46dc-baa4-29ff19a1bf77 | < 6.1.2 |
CRITICAL | 9.8 | The Social Discussions plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 6.1… | — | wordfence |
| f5ab09ee-53d2-4d99-824b-6a7a006bb2c2 | CRITICAL | 9.8 | The Streamit theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.5.0. Thi… | — | wordfence | |
| f59891c7-db1a-4688-8616-8877d7d7960d | < 6.6.4.1 |
CRITICAL | 9.8 | The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_… | — | wordfence |
| f58d5464-b12d-4d01-985a-68854b0b2fdd | < 1.29.0 |
CRITICAL | 9.8 | The Forminator β Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file… | — | wordfence |
| f53f35c4-6825-448f-a101-1439fdd63cfe | < 4.16.18 |
CRITICAL | 9.8 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content β ProfilePr… | — | wordfence |
| f52a9da3-f8bb-4e52-9b4c-b8e5bbf077cb | CRITICAL | 9.8 | The SV100 Companion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0… | — | wordfence | |
| f51f66d7-ba47-4b7b-9b94-ea4459cf6233 | < 2.3.4 |
CRITICAL | 9.8 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authenticated bypass in all versions up to, and includi… | — | wordfence |
| f4ff4114-c1ed-47df-9e7c-f34f1a422ffe | < 2.9.2 |
CRITICAL | 9.8 | The W3 Total Cache plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.9… | — | wordfence |
| f4ea6044-bf7b-469d-89ec-a9b89ef5715e | < 3.05.1 |
CRITICAL | 9.8 | The Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin fo… | — | wordfence |
| f4bffbe6-8317-495b-b349-632c9a4f1f88 | CRITICAL | 9.8 | The Azz Anonim Posting plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence | |
| f49fba00-c576-4a1a-8b0b-9ebed3e3d090 | < 4.6.14 |
CRITICAL | 9.8 | The Shariff Wrapper plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6.13 … | — | wordfence |
| f4893d9c-e039-43df-80b9-dbe42374caed | < 1.2.17 |
CRITICAL | 9.8 | The WP CarDealer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.16… | — | wordfence |
| f44b9e6d-2f84-45f6-9f74-3f23b03c5a49 | < 0.0.16 |
CRITICAL | 9.8 | The Password Reset with Code for WordPress REST API is vulnerable to a Weak Password Recovery Mechanism in versions up t… | — | wordfence |
| f4494a0f-57fb-4ed7-8fdc-85b5dcee6549 | < 3.1.3 |
CRITICAL | 9.8 | The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF c… | — | wordfence |
| f441477e-35b8-42ae-b71c-3fdba126021b | < 1.2.4 |
CRITICAL | 9.8 | The TrueBooker β Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via i… | — | wordfence |
| f4393526-6357-40ee-a024-f461d0430a62 | < 2.0.6 |
CRITICAL | 9.8 | WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query,… | — | wordfence |
| f41eecf8-dad9-4f98-91f5-c6ac472b8810 | CRITICAL | 9.8 | The Email Newsletter plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 20.15… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →