Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 116 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f33a13dc-ebff-4033-9b8d-10076b1c2d0d | HIGH | 8.8 | The Mmm Simple File List plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 2.3… | — | wordfence | |
| f30f5251-54ba-4a8c-b849-2a4ea11637a1 | < 4.3.2 |
HIGH | 8.8 | The ReachShip WooCommerce Multi-Carrier & Conditional Shipping plugin for WordPress is vulnerable to arbitrary file uplo… | — | wordfence |
| f2ef8ee4-7388-4263-ad6a-bb043b09c97c | < 2.7.5 |
HIGH | 8.8 | The Elementor Website Builder plugin for WordPress is vulnerable to arbitrary file upload by subscriber level users and … | — | wordfence |
| f2e981ae-4958-45c5-9f5f-6298223fac46 | < 1.0.4 |
HIGH | 8.8 | The Togo β Travel & Tour Booking WordPress Theme theme for WordPress is vulnerable to Privilege Escalation in all vers… | — | wordfence |
| f2c88c5a-ea87-4aab-a0ce-8246e5cb540a | < 7.3.7 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attack… | — | wordfence |
| f29b905c-57cf-4fb8-b6af-eb0c367cd3e4 | < 5.17.8 |
HIGH | 8.8 | The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and includin… | — | wordfence |
| f28826e7-913e-4a88-a48a-3b8dd5623d39 | < 1.9.7 |
HIGH | 8.8 | The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_a… | — | wordfence |
| f2862cee-0412-42ba-9a8e-e5722bece775 | < 3.6.4 |
HIGH | 8.8 | The Redirection plugin suffers from a critical Cross-Site Request Forgery vulnerability that allows remote attackers to … | — | wordfence |
| f270c73f-ccdb-4575-ab9b-014c65873607 | < 2.5.18 |
HIGH | 8.8 | The Slideshow SE plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.17… | — | wordfence |
| f25a5b1a-9a33-4e61-8a32-ecebfa64e4bb | < 2.3.12 |
HIGH | 8.8 | The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,… | — | wordfence |
| f24f0673-b5c8-4086-8795-692228a413af | HIGH | 8.8 | The WordPress Awesome Import & Export Plugin - Import & Export WordPress Data plugin for WordPress is vulnerable arbitra… | — | wordfence | |
| f248b116-b4b7-43ba-8fbf-3de86935582d | < 5.3.0 |
HIGH | 8.8 | The EduAdmin Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.2.0.… | — | wordfence |
| f234f05f-e377-4e89-81e1-f47ff44eebc5 | < 1.3.11 |
HIGH | 8.8 | The Podlove Subscribe button plugin for WordPress is vulnerable to UNION-based SQL Injection via the 'button' attribute … | — | wordfence |
| f21f757b-43f8-4371-886c-b9f7fd79c715 | < 2.3 |
HIGH | 8.8 | WordPress Pricing Table Plugin Plugin 2.2 has a Cross-Site Request Forgery vulnerability via in the core/views/arprice_i… | — | wordfence |
| f21cbe18-77e1-4a9a-96a0-74edaef0db3e | < 2.0.7 |
HIGH | 8.8 | The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via des… | — | wordfence |
| f215e320-8563-4d25-9963-ed3664b4901d | < 2.4.17 |
HIGH | 8.8 | The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4… | — | wordfence |
| f208ca5a-a404-4664-80f5-643e713f600a | < 1.1.0 |
HIGH | 8.8 | The NewsPlugin WordPress plugin is vulnerable to Cross-Site Request Forgery via the handle_save_style function found in … | — | wordfence |
| f1de4899-532a-4558-bff0-f4610bfdd49d | HIGH | 8.8 | The Easy Elements for Elementor β Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalatio… | — | wordfence | |
| f1cbe675-4c0f-430a-b2db-85ba8605d172 | HIGH | 8.8 | The Deeper Comments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … | — | wordfence | |
| f1c2cb3f-2f9e-40c5-9e5f-5b85a53e5868 | < 1.33.25 |
HIGH | 8.8 | The WordPress Webinar Plugin β WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a mis… | — | wordfence |
| f1add368-81d2-455f-a95a-c13566c58d39 | HIGH | 8.8 | The Web Invoice plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.3 due to insuf… | — | wordfence | |
| f1a75a95-e61e-4786-b882-8ca186843d57 | HIGH | 8.8 | The Genemy - Creative Minimal Landing Page Builder for Digital Startup Design Studio Agency in Marketing theme for WordP… | — | wordfence | |
| f18be13a-1b16-40f8-85a7-bd77b49e243c | < 2.2.6 |
HIGH | 8.8 | The Otter - Gutenberg Blocks plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fallback'… | — | wordfence |
| f15415aa-b820-4697-8360-b526312c89d3 | < 10.12.0.3 |
HIGH | 8.8 | The ICS Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 10.12.0.2. T… | — | wordfence |
| f107496b-020b-4222-91f3-49caba1a39db | < 1.3.8 |
HIGH | 8.8 | The Advanced Import plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →