Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 111 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| fe25bfef-34f0-4d57-9cba-9dcbf58281c6 | < 4.0 |
HIGH | 8.8 | The Click to Chat β HoliThemes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i… | — | wordfence |
| fe1f8c51-d3f1-456b-bf73-362ff33ee879 | < 3.6.8 |
HIGH | 8.8 | The wp-timelines plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.7.… | — | wordfence |
| fe0fedc1-d4bd-40bf-8d8f-953db4bf2120 | < 3.14 |
HIGH | 8.8 | The WP RSS Multi Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 3.14. This … | — | wordfence |
| fe02377a-8d09-4d86-a049-3002516cf933 | < 2.1.0 |
HIGH | 8.8 | The YITH WooCommerce Compare plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including… | — | wordfence |
| fe00b89f-b475-4aec-8df8-89d842d92e4f | < 26.6 |
HIGH | 8.8 | The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via des… | — | wordfence |
| fdeaf745-9a1b-4377-b9de-0d03e709a21b | < 1.1.1 |
HIGH | 8.8 | The WPMozo Addons Lite for Elementor plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and i… | — | wordfence |
| fdc18341-135b-4522-a9db-510e4c4d9704 | < 1.8.6 |
HIGH | 8.8 | The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… | — | wordfence |
| fdba439d-90ee-413c-842d-19704b08c33e | < 3.4.27.1 |
HIGH | 8.8 | The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration. This makes it possible for at… | — | wordfence |
| fdacd8b2-ef34-424d-bc05-bc059f6ab3b0 | < 7.1 |
HIGH | 8.8 | The WP Yelp Review Slider plugin for WordPress is vulnerable to SQL Injection via the $tid value in versions up to, and … | — | wordfence |
| fda10117-b562-496e-8a17-88ee350ce8f2 | < 4.1.12 |
HIGH | 8.8 | The "Popup Builder β Create highly converting, mobile friendly marketing popups." plugin for WordPress is vulnerable … | — | wordfence |
| fd97ef7d-80c7-4987-be79-23eb380fa460 | < 7.1.0 |
HIGH | 8.8 | The CAPTCHA 4WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.0.6… | — | wordfence |
| fd56e59b-3879-4ab6-ae9a-7a301ee6aa20 | < 2.3.12 |
HIGH | 8.8 | The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a locati… | — | wordfence |
| fd216743-ce8d-4632-9fd1-d63502c2dfcd | < 2.1.42 |
HIGH | 8.8 | The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_… | — | wordfence |
| fd15f5c3-f4c3-40d3-b0ae-eee7ed9ed434 | < 1.0.9 |
HIGH | 8.8 | The Spider Facebook plugin for WordPress is vulnerable to generic SQL Injection via the βidβ parameter in versions u… | — | wordfence |
| fd154b26-985b-4e72-976f-1858a783c667 | < 4.5.1 |
HIGH | 8.8 | Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.5.0 allows a remote attack… | — | wordfence |
| fce15e1c-e2eb-4bd9-8b07-78d87a6ae1cc | < 4.9.3.3 |
HIGH | 8.8 | The Slimstat Analytics plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in versions up … | — | wordfence |
| fcdeba37-ba65-400d-9c07-36503a03e857 | < 4.70 |
HIGH | 8.8 | The SP Project & Document Manager plugin for WordPress is vulnerable to SQL Injection via the sp_cdm_display_project_sh… | — | wordfence |
| fca9bd3a-2489-4672-95c1-9e00d60d6525 | < 1.2.1 |
HIGH | 8.8 | The Availability Calendar WordPress plugin before 1.2.1 does not escape the category attribute from its shortcode before… | — | wordfence |
| fca3d106-49df-49fc-a90d-e0cb26bd34b6 | < 1.5.3 |
HIGH | 8.8 | The Modal Popup Box β Popup Builder, Show Offers And News in Popup plugin for WordPress is vulnerable to PHP Object In… | — | wordfence |
| fca3259b-bf0e-4b4a-815f-1eb399b8b674 | < 3.5.26 |
HIGH | 8.8 | The ConvertPlug plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.25 … | — | wordfence |
| fc64c550-0d19-42d4-aa2b-829e74b166bc | < 2.5.3 |
HIGH | 8.8 | The WP Coder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. T… | — | wordfence |
| fc2a0723-52cf-4b46-ab1c-52275537c1b5 | < 7.9.0 |
HIGH | 8.8 | The SUMO Memberships for WooCommerce plugin for WordPress is vulnerable to privilege escalation in all versions up to, a… | — | wordfence |
| fbf85cbc-88fa-4430-b005-a1f1e141241b | < 5.5.0 |
HIGH | 8.8 | The Icegram Express plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.4.19 due to… | — | wordfence |
| fbedf0da-699e-429d-9ec7-6803f3c77a84 | HIGH | 8.8 | The options.php file of the WP-Board WordPress plugin through 1.1(Beta) accepts a postid parameter which is not sanitise… | — | wordfence | |
| fbe42214-0a01-4b9c-8149-68c47082d9d9 | < 1.5.2 |
HIGH | 8.8 | Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP co… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →