Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 114 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f813f1f3-4494-4899-93d1-fa6f786e94cd | HIGH | 8.8 | The APA Register Newsletter Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… | — | wordfence | |
| f7ed6255-d8df-4f57-961b-1a0c21e352ac | < 1.3 |
HIGH | 8.8 | The WP-Orphanage Extended plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… | — | wordfence |
| f7d5a077-8836-4c28-8884-5047585a99e5 | < 1.5.5 |
HIGH | 8.8 | The Wallet for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'search[value]' parameter in all … | — | wordfence |
| f7b24b7c-1a15-4b38-b59e-bcad39cc4340 | < 2.0.10 |
HIGH | 8.8 | The PropertyHive plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.9 … | — | wordfence |
| f7b24a89-816d-4021-b8de-d1ca14ce3cb9 | < 1.1.0 |
HIGH | 8.8 | The WP Multiple Meta Box plugin for WordPress is vulnerable to blind SQL Injection via the ‘id’ parameter in version… | — | wordfence |
| f7ad9f8c-9b76-4b3e-987c-ed99beeb2937 | HIGH | 8.8 | The WP Email Users WordPress plugin through 1.7.6 does not escape the data_raw parameter in the weu_selected_users_1 AJA… | — | wordfence | |
| f7acbb6f-99e0-483a-95ed-c60905dcbd50 | < 1.4.5 |
HIGH | 8.8 | The WishSuite plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.4. This m… | — | wordfence |
| f796b282-0012-4d86-914d-72c7707dce42 | < 1.3.1 |
HIGH | 8.8 | The bbPress Members Only plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
| f795a46c-ba0c-45d5-9ff7-638752f1681b | < 3.4.7 |
HIGH | 8.8 | The User Meta Manager plugin for WordPress is vulnerable to blind SQL Injection via the ‘umm_user’ parameter in vers… | — | wordfence |
| f77cc1ed-d30e-4651-af23-29d34d76dc92 | HIGH | 8.8 | The Occasions plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. Th… | — | wordfence | |
| f7686b11-97a8-4f09-bbfa-d77120cc35b7 | < 3.4 |
HIGH | 8.8 | The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to PHP Object Injection in versi… | — | wordfence |
| f75936d7-12bc-47cc-b901-17fd42c05d66 | < 1.2.0 |
HIGH | 8.8 | The Login rebuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.2.0. This is du… | — | wordfence |
| f753b536-6ccd-4f79-83da-48cabb15b72a | < 2.5.0 |
HIGH | 8.8 | The Twitter Cards Meta plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence |
| f745652d-12d6-46cd-8599-0a42696cb45a | < 2.8.6 |
HIGH | 8.8 | The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an … | — | wordfence |
| f727d82e-8295-4440-90fa-dc41b1d02f8f | HIGH | 8.8 | The MyTweetLinks plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.1 due to insu… | — | wordfence | |
| f71fc65f-cdc1-4f20-b37e-849ade49ee41 | < 7.3.21 |
HIGH | 8.8 | The Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress is vulnerable to Privilege Escalation in… | — | wordfence |
| f70ec123-fff3-4f03-a424-37e0e579b765 | < 3.0.9 |
HIGH | 8.8 | The Customer Reviews Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| f70a2a58-d9b8-456d-ae4f-9c60b3d6b8a5 | < 1.0.4 |
HIGH | 8.8 | The plugins 'Integration for Billingo & Gravity Forms' up to version 1.0.3, 'Integration for Szamlazz.hu & Gravity Form… | — | wordfence |
| f6f0fb78-ad6b-4a9e-ae1a-5793f3426379 | < 1.4 |
HIGH | 8.8 | Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that … | — | wordfence |
| f6c94024-20fb-4cc1-a093-1b9974e61220 | HIGH | 8.8 | The Address Autocomplete plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence | |
| f690e67c-119f-4ea6-9505-101e7f7a3dea | < 2.9.5 |
HIGH | 8.8 | The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence |
| f67ce101-3b4f-45be-9aed-d9055cc09fd3 | < 1.9.9.149 |
HIGH | 8.8 | The Better Messages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… | — | wordfence |
| f66457a1-7406-46f9-9a14-4ce6d77c4b84 | < 2.2.9 |
HIGH | 8.8 | The WP Job Portal plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.8. Th… | — | wordfence |
| f65fdde9-1133-4e29-a70a-be977f96acce | < 1.1.13 |
HIGH | 8.8 | The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to privilege escalation in… | — | wordfence |
| f648e7f3-d93a-4a46-ae77-81a94880869c | HIGH | 8.8 | The SoJ SoundSlides plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →