Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 117 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f0b60313-042b-4e85-a117-9abd95824402 | < 1.1.7 |
HIGH | 8.8 | The Deny All Firewall plugin before 1.1.7 for WordPress allows wp-admin/options-general.php?page=daf_settings&daf_remove… | — | wordfence |
| f098d66f-43a6-44e9-b836-2994d2c97782 | < 2.0 |
HIGH | 8.8 | lib/core.php in the Cool Video Gallery plugin 1.9 for WordPress allows remote attackers to execute arbitrary code via sh… | — | wordfence |
| f082ff4a-2adb-461e-875a-b3701cfea074 | < 1.8.1 |
HIGH | 8.8 | Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, … | — | wordfence |
| f068abb4-cbe6-4698-b547-78503b2a455e | < 5.9.1 |
HIGH | 8.8 | The AdRotate Banner Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
| f0644fc5-6b37-4730-a051-f36dec650649 | < 1.0.33 |
HIGH | 8.8 | Multiple SQL injection vulnerabilities in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPres… | — | wordfence |
| f02945e0-6214-46c4-ada8-49e8161d2ce4 | < 2.16.1 |
HIGH | 8.8 | The Seriously Simple Podcasting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … | — | wordfence |
| f00a12ed-d8c2-40b2-b0c8-71507469ee95 | < 1.2.3 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the Easy Social Icons plugin before 1.2.3 for WordPress allows remote… | — | wordfence |
| efff81ea-b88e-4f51-b8db-1f8255e7736a | < 4.2 |
HIGH | 8.8 | The ARPrice plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.1.3 via deser… | — | wordfence |
| effd72d2-876d-4f8d-b1e4-5ab38eab401b | < 1.8.2 |
HIGH | 8.8 | The AdSanity plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aj… | — | wordfence |
| efe9ca48-b6df-4a2d-8713-d8b21f6c9701 | < 0.1.5 |
HIGH | 8.8 | The Point Maker plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.1.4. This… | — | wordfence |
| efe86e10-c7ac-456b-b324-7e028562ff9f | < 1.24 |
HIGH | 8.8 | The Ona theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions … | — | wordfence |
| efc7ad9f-714e-474c-87e8-ecbbdfabd550 | < 4.2.2 |
HIGH | 8.8 | The WPFront User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… | — | wordfence |
| efc2a21d-b6f9-405d-a9a0-779a736e5d94 | < 2.1.1 |
HIGH | 8.8 | admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPre… | — | wordfence |
| efb48ce2-23e6-4c48-a35b-1c42e5fb0aa5 | HIGH | 8.8 | The Advanced What should we write next about plugin for WordPress is vulnerable to SQL Injection in versions up to, and … | — | wordfence | |
| ef998d5e-e03b-4012-9576-d90dee3adec4 | < 4.1.1 |
HIGH | 8.8 | The Widget Options β The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Remote Code … | — | wordfence |
| ef86b1f2-d5aa-4e83-a792-5fa35734b3d3 | < 2.11.11 |
HIGH | 8.8 | The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… | — | wordfence |
| ef818472-d4ba-4ca9-b7ed-fe563107c3bd | < 5.5.2 |
HIGH | 8.8 | The LatePoint β Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege es… | — | wordfence |
| ef7f1209-c0e9-4958-aa92-fb2cb2a431e1 | HIGH | 8.8 | The WP Options Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence | |
| ef7aff85-e1ca-47ce-86e9-a0fe356993a1 | < 6.0.9.2 |
HIGH | 8.8 | The RegistrationMagic β User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forger… | — | wordfence |
| ef7727e5-fb20-4d9b-baaa-c123a0100ee0 | < 0.6.3 |
HIGH | 8.8 | The WP Code Highlight.js plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
| ef46b08f-455a-4c61-81ac-10af19b16980 | HIGH | 8.8 | The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e… | — | wordfence | |
| ef45fa78-7005-483e-a708-5aab0f7ba07b | < 7.8.2 |
HIGH | 8.8 | The Avada theme for WordPress is vulnerable to Cross-Site Request forgery in versions up to, and including, 7.8.1 in cla… | — | wordfence |
| ef4134a1-e2c6-495a-bc00-cc8cd783cd7a | < 1.5.59 |
HIGH | 8.8 | The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload. | — | wordfence |
| ef1d1ae6-3019-4e48-911e-5f805f8089ca | < 5.7.0 |
HIGH | 8.8 | The RD Station plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.6.0. … | — | wordfence |
| eee88bc6-b7e3-4eff-afc7-59b9a1cc9d2c | < 3.1.0 |
HIGH | 8.8 | The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actio… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →