Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 112 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| fbda7670-179a-41ed-8ec9-ae7f5102e645 | HIGH | 8.8 | The ToolBar to Share plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence | |
| fbb601ce-a884-4894-af13-dab14885c7eb | < 5.1.1 |
HIGH | 8.8 | The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. Th… | — | wordfence |
| fb900810-23a2-4920-a5e8-4388c4474de0 | < 2.6.04 |
HIGH | 8.8 | The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including… | — | wordfence |
| fb61159a-e501-4c55-a384-b6049e0f0bc8 | < 2.2.8 |
HIGH | 8.8 | The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on t… | — | wordfence |
| fb4dc258-a1b2-4e7c-8bba-1b3162b8954b | HIGH | 8.8 | The Social Link Groups plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.0 due t… | — | wordfence | |
| fb4b6d33-82cd-4c41-ba54-dbc7fe5f6ac6 | < 10.4.5 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to h… | — | wordfence |
| fb310bdb-fc74-47b2-9371-3d10abd287fb | < 1.7 |
HIGH | 8.8 | The Animation Addons for Elementor Pro plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation … | — | wordfence |
| fafd0159-25ab-430d-88ef-c4d09d23baa7 | < 3.2.5 |
HIGH | 8.8 | The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fil… | — | wordfence |
| faf3fb76-847f-447f-b6c6-49bd0d30d3c7 | < 1.5.1 |
HIGH | 8.8 | SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and earlier allows remote attackers to execute arbitrar… | — | wordfence |
| faf020d0-62a2-41cc-ad3b-da3b56ed0d97 | HIGH | 8.8 | The Apa Banner Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence | |
| fae1b795-8939-4229-8f89-fedf6f320ec1 | < 5.1.1 |
HIGH | 8.8 | The All In One WP Security & Firewall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… | — | wordfence |
| fac81cc0-c6c9-4009-aacb-52adc70c0261 | < 1.0.5 |
HIGH | 8.8 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the han… | — | wordfence |
| fac308c6-780d-44ea-ba78-d15e1ee260e4 | < 1.2.4 |
HIGH | 8.8 | Multiple cross-site request forgery (CSRF) vulnerabilities in the IP Ban (simple-ip-ban) plugin 1.2.3 for WordPress allo… | — | wordfence |
| fab0a42e-fa99-4451-91fd-c924a33d33c8 | < 2.2.7 |
HIGH | 8.8 | The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnera… | — | wordfence |
| faac24e5-94f2-40e5-932e-93ddc2c8af7c | < 7.5.15 |
HIGH | 8.8 | The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to Cross… | — | wordfence |
| fa9450a4-2b96-45e4-b2dc-9a4b26449d19 | < 1.3.12 |
HIGH | 8.8 | The Contact Form Email plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence |
| fa86bcb9-e558-4b60-9473-65cd6f9663fd | HIGH | 8.8 | The Embedder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalati… | — | wordfence | |
| fa7ca972-ddb0-416b-8c5a-b4e9648ca957 | < 6.0.0 |
HIGH | 8.8 | The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
| fa586468-d6ff-46a3-97f3-e2e1d365e5b1 | < 2.9.0 |
HIGH | 8.8 | The Contact Form Generator plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up t… | — | wordfence |
| fa53c5ee-fe7f-4fb2-baaa-2c1a151d4b2c | HIGH | 8.8 | The WP Enable WebP plugin for WordPress is vulnerable to arbitrary file uploads due to improper file type validation in … | — | wordfence | |
| fa52ecbf-9c8d-4103-acce-255f36c57d0b | HIGH | 8.8 | The Institutions Directory plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includi… | — | wordfence | |
| fa1d953f-6a5c-46af-a1a5-2c4f90da679a | < 3.0.3 |
HIGH | 8.8 | The Folders Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … | — | wordfence |
| fa0881ab-d731-4e57-8323-c49b9306bf50 | < 2.0.40 |
HIGH | 8.8 | A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress a… | — | wordfence |
| f9fe858e-5c89-4cc2-8b66-5c86965f7889 | HIGH | 8.8 | The Travel Light for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This i… | — | wordfence | |
| f9d70f5c-e05f-47c9-994c-0e1da5b2fe01 | < 1.3 |
HIGH | 8.8 | The WP Super Cache plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.2. Th… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →