Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,758 vulnerabilities found (page 12 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f4494a0f-57fb-4ed7-8fdc-85b5dcee6549 | < 3.1.3 |
CRITICAL | 9.8 | The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF c… | — | wordfence |
| f441477e-35b8-42ae-b71c-3fdba126021b | < 1.2.4 |
CRITICAL | 9.8 | The TrueBooker β Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via i… | — | wordfence |
| f4393526-6357-40ee-a024-f461d0430a62 | < 2.0.6 |
CRITICAL | 9.8 | WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query,… | — | wordfence |
| f41eecf8-dad9-4f98-91f5-c6ac472b8810 | CRITICAL | 9.8 | The Email Newsletter plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 20.15… | — | wordfence | |
| f41a3141-e232-40f2-b800-e089a19c52fa | CRITICAL | 9.8 | The BodyCenter - Gym, Fitness WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in v… | — | wordfence | |
| f3fe07df-3589-4767-a81d-a6b72c5ab1a8 | < 4.2.0 |
CRITICAL | 9.8 | The LearnPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.7.3.2 vi… | — | wordfence |
| f3eb1cb5-71ca-44c5-9434-e86301543357 | < 3.3.4 |
CRITICAL | 9.8 | The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, departmen… | — | wordfence |
| f3e618cf-dd77-45a7-ab57-5732fd329883 | CRITICAL | 9.8 | The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user re… | — | wordfence | |
| f3bddb69-9c63-49e8-9c04-08361423b1c3 | < 3.5 |
CRITICAL | 9.8 | SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthentica… | — | wordfence |
| f3b727ba-b39c-4a98-a6a6-ea33785079f6 | < 2.7.6 |
CRITICAL | 9.8 | The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ… | — | wordfence |
| f39d1f86-17d7-4b22-ba42-e88e96111bd6 | < 1.7.1 |
CRITICAL | 9.8 | The Firebase Authentication plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 1.7.1 (excl… | — | wordfence |
| f374b3d1-820b-473f-8d2b-c3267e6d23d9 | < 5.1.7 |
CRITICAL | 9.8 | The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. Thi… | — | wordfence |
| f33e8906-c607-40de-8c2a-93ca12519da5 | < 1.11.4 |
CRITICAL | 9.8 | The OAuth 2.0 client for SSO plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin… | — | wordfence |
| f33d080c-6d64-46d1-b01c-ef859106159f | < 2.0.1 |
CRITICAL | 9.8 | The Themesflat Addons For Elementor plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and in… | — | wordfence |
| f2ed5e51-8783-4b7f-9177-c116bf0fad44 | < 3.8 |
CRITICAL | 9.8 | The Frontend File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… | — | wordfence |
| f2c6a377-216f-4d61-8fae-ec5bc2793cdf | < 1.6.21 |
CRITICAL | 9.8 | The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t… | — | wordfence |
| f28dc553-32de-459e-a0e9-2fd428ef42a0 | CRITICAL | 9.8 | The Magnitudo theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ph… | — | wordfence | |
| f27bf9d3-f517-4739-914d-fe3ed13331e0 | < 3.8.9 |
CRITICAL | 9.8 | The Support Board plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 3.8.9 (exclusive). Th… | — | wordfence |
| f271c2e7-9d58-4dea-95d3-3ffc4ec7c3b2 | < 2.3 |
CRITICAL | 9.8 | The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation vi… | — | wordfence |
| f24e711b-0b16-4948-97c9-807703a9baaf | < 1.3.2 |
CRITICAL | 9.8 | The WordPress SMTP Service, Email Delivery Solved! β MailHawk plugin for WordPress is vulnerable to Local File Inclusi… | — | wordfence |
| f24af4f2-bb05-4833-a2bc-771143970e00 | < 1.8 |
CRITICAL | 9.8 | The HD FLV Player plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… | — | wordfence |
| f2488eb7-5c80-48d5-8f39-736883207937 | CRITICAL | 9.8 | The Directorist Social Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu… | — | wordfence | |
| f20ee38e-6af0-48d7-8ac9-2972f3c4c679 | CRITICAL | 9.8 | The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to … | — | wordfence | |
| f203f30c-998b-4719-9268-0a78e1dc84be | CRITICAL | 9.8 | The Asset Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ve… | — | wordfence | |
| f1d26326-c5c5-4993-aadf-298759eb873d | CRITICAL | 9.8 | A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →