Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 110 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b8613acf-d6e8-434f-820b-d854ed1f6299 | < 1.3.5 |
CRITICAL | 9.0 | The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exp… | — | wordfence |
| 9d0c144b-609b-4b4a-bfb2-de38b5969a9e | < 4.6 |
CRITICAL | 9.0 | The BP Profile Search plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.5.3… | — | wordfence |
| 79e2011c-5e4d-4d02-831f-6b4dcfcaa51e | < 18.3 |
CRITICAL | 9.0 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up… | — | wordfence |
| 6b2e210b-e5e3-46f1-b730-64d970160a5e | < 3.8.8 |
CRITICAL | 9.0 | SQL injection vulnerability in the All In One WP Security & Firewall plugin before 3.8.8 for WordPress allows remote att… | — | wordfence |
| 5412fd87-49bc-445c-8d16-443e38933d1e | < 1.2.0 |
CRITICAL | 9.0 | The Ads by datafeedr.com plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1… | — | wordfence |
| 50e4e070-8f68-4bac-8011-ac9d3b99a24f | < 7.9 |
CRITICAL | 9.0 | The SEOPress β On-site SEO plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu… | — | wordfence |
| 4deb128d-0163-4a8e-9591-87352f74c3ef | < 2.13.10 |
CRITICAL | 9.0 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil… | — | wordfence |
| 4b159d4f-494e-4ab4-8ed7-3421b437597e | CRITICAL | 9.0 | The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which … | — | wordfence | |
| 12ea26be-93e4-43de-bb32-21cdc2f80569 | < 3.9.5 |
CRITICAL | 9.0 | The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputti… | — | wordfence |
| fff8dfbc-fd59-47db-85bb-de2a7c6a9a5f | < 1.3.5.3 |
HIGH | 8.8 | The HUSKY β Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to SQL Injection via the '… | — | wordfence |
| ffd6e18d-9173-4911-af64-5d54c6d2e052 | < 2.9.0 |
HIGH | 8.8 | The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to unauthorized loss of data due to a missing cap… | — | wordfence |
| ffd438ea-ddc2-4d97-b187-4cd54b6f638d | < 8.6.13 |
HIGH | 8.8 | The MapSVG plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and excluding, 8.6.13. This… | — | wordfence |
| ffcc85a1-fc79-4bc6-b50e-c87988d4cad3 | HIGH | 8.8 | The Nifty Newsletters WordPress plugin is vulnerable to Cross-Site Request Forgery via the sola_nl_wp_head function foun… | — | wordfence | |
| ffac779c-c17f-46bd-9276-a1ce2db4e95c | < 2.4.0 |
HIGH | 8.8 | The WooCommerce One Page Checkout plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and incl… | — | wordfence |
| ff9364a9-18f8-47d3-b992-e39c8d99d6ea | < 2.0.9 |
HIGH | 8.8 | The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privil… | — | wordfence |
| ff65e2cc-2052-45b6-bb42-58b8ce73adee | HIGH | 8.8 | The Hospital Doctor Directory plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and incl… | — | wordfence | |
| ff29e160-993b-422c-b49b-a216db5a0765 | < 1.6.0 |
HIGH | 8.8 | The CM Pop-Up banners plugin for WordPress is vulnerable to generic SQL Injection via the getStatistics function in vers… | — | wordfence |
| ff21e539-8ba0-4edd-a90c-27a4cd1cdbc7 | < 2.9.9 |
HIGH | 8.8 | The Translate WordPress with GTranslate <= 2.9.8 & Translate WordPress β Google Language Translator <= 6.0.13 WordPr… | — | wordfence |
| ff09292b-c8a6-4cd8-a8dd-d79b4c713d6f | HIGH | 8.8 | The WP donimedia carousel plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… | — | wordfence | |
| fef6c603-2beb-44df-8895-10ad0a9ef644 | HIGH | 8.8 | Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter. | — | wordfence | |
| feecd1f9-a933-43f5-971b-459bb27340d4 | < 0.2.18 |
HIGH | 8.8 | The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features,… | — | wordfence |
| fee18df2-75ea-416a-8aa6-139018016b9a | < 1.1.4 |
HIGH | 8.8 | The Bulk Page Creator WordPress plugin before 1.1.4 does not protect its page creation functionalities with nonce checks… | — | wordfence |
| fea96f84-f75b-4f02-9ca8-f8fda439d565 | < 3.1.1 |
HIGH | 8.8 | The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in… | — | wordfence |
| fe99d636-bb71-431e-88d6-130767341c83 | HIGH | 8.8 | The INK Official plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all… | — | wordfence | |
| fe8b6a16-0a39-42fd-bb0f-9114ec08a885 | HIGH | 8.8 | The Axle Demo Importer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →