Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 12 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f41a3141-e232-40f2-b800-e089a19c52fa | CRITICAL | 9.8 | The BodyCenter - Gym, Fitness WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in v… | — | wordfence | |
| f3fe07df-3589-4767-a81d-a6b72c5ab1a8 | < 4.2.0 |
CRITICAL | 9.8 | The LearnPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.7.3.2 vi… | — | wordfence |
| f3eb1cb5-71ca-44c5-9434-e86301543357 | < 3.3.4 |
CRITICAL | 9.8 | The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, departmen… | — | wordfence |
| f3e618cf-dd77-45a7-ab57-5732fd329883 | CRITICAL | 9.8 | The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user re… | — | wordfence | |
| f3bddb69-9c63-49e8-9c04-08361423b1c3 | < 3.5 |
CRITICAL | 9.8 | SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthentica… | — | wordfence |
| f3b727ba-b39c-4a98-a6a6-ea33785079f6 | < 2.7.6 |
CRITICAL | 9.8 | The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ… | — | wordfence |
| f374b3d1-820b-473f-8d2b-c3267e6d23d9 | < 5.1.7 |
CRITICAL | 9.8 | The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. Thi… | — | wordfence |
| f33e8906-c607-40de-8c2a-93ca12519da5 | < 1.11.4 |
CRITICAL | 9.8 | The OAuth 2.0 client for SSO plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin… | — | wordfence |
| f33d080c-6d64-46d1-b01c-ef859106159f | < 2.0.1 |
CRITICAL | 9.8 | The Themesflat Addons For Elementor plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and in… | — | wordfence |
| f2ed5e51-8783-4b7f-9177-c116bf0fad44 | < 3.8 |
CRITICAL | 9.8 | The Frontend File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… | — | wordfence |
| f2c6a377-216f-4d61-8fae-ec5bc2793cdf | < 1.6.21 |
CRITICAL | 9.8 | The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t… | — | wordfence |
| f28dc553-32de-459e-a0e9-2fd428ef42a0 | CRITICAL | 9.8 | The Magnitudo theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ph… | — | wordfence | |
| f27bf9d3-f517-4739-914d-fe3ed13331e0 | < 3.8.9 |
CRITICAL | 9.8 | The Support Board plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 3.8.9 (exclusive). Th… | — | wordfence |
| f271c2e7-9d58-4dea-95d3-3ffc4ec7c3b2 | < 2.3 |
CRITICAL | 9.8 | The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation vi… | — | wordfence |
| f24e711b-0b16-4948-97c9-807703a9baaf | < 1.3.2 |
CRITICAL | 9.8 | The WordPress SMTP Service, Email Delivery Solved! β MailHawk plugin for WordPress is vulnerable to Local File Inclusi… | — | wordfence |
| f24af4f2-bb05-4833-a2bc-771143970e00 | < 1.8 |
CRITICAL | 9.8 | The HD FLV Player plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… | — | wordfence |
| f2488eb7-5c80-48d5-8f39-736883207937 | CRITICAL | 9.8 | The Directorist Social Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu… | — | wordfence | |
| f20ee38e-6af0-48d7-8ac9-2972f3c4c679 | CRITICAL | 9.8 | The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to … | — | wordfence | |
| f203f30c-998b-4719-9268-0a78e1dc84be | CRITICAL | 9.8 | The Asset Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ve… | — | wordfence | |
| f1d26326-c5c5-4993-aadf-298759eb873d | CRITICAL | 9.8 | A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in … | — | wordfence | |
| f1c5ce2b-9ac4-4fd2-9e49-ccb8538ba100 | CRITICAL | 9.8 | Vulnerability in wordpress plugin surveys v1.01.8, The code in survey_form.php does not sanitize the action variable bef… | — | wordfence | |
| f1b6fe67-cbd8-438f-8e06-d0f25eddc81a | < 0.9.8.9 |
CRITICAL | 9.8 | The Custom Content Type Manager plugin for WordPress was injected with a malicious backdoor in versions 0.9.8.7 to 0.9.8… | — | wordfence |
| f188c032-6f36-45a9-9ca8-39bfe91c97d4 | CRITICAL | 9.8 | The Konzept theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'uplo… | — | wordfence | |
| f17c4748-2a95-495c-ad3b-86b272855791 | < 1.7.0 |
CRITICAL | 9.8 | The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to time-based blind SQL Injection via th… | — | wordfence |
| f15f85c6-0bba-4bbd-b097-d205b9e0a075 | < 1.0.19 |
CRITICAL | 9.8 | The Build App Online plugin for WordPress is vulnerable to SQL Injection via an AJAX action available to unprivileged us… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →