Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 125 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ddf4ec13-bca3-4994-9e11-11fbbead371a | < 1.5.7 |
HIGH | 8.8 | Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin be… | — | wordfence |
| ddd37b7a-3ef8-4269-ba3b-665ae34bde26 | < 2.9.14 |
HIGH | 8.8 | The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence |
| ddd06190-d0c1-445d-8c6f-4c7df3248db4 | < 3.7.40 |
HIGH | 8.8 | WordPress Core is vulnerable to Cross-Site Request Forgery via wp-trackback.php in versions up to 6.0.3. This is due to … | — | wordfence |
| ddb7b668-f023-427e-9ab5-90dc6d481028 | < 3.3.24 |
HIGH | 8.8 | Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_… | — | wordfence |
| dda2c437-8f41-480a-8816-2c07ab0eafa7 | < 2.5 |
HIGH | 8.8 | The Apus Framework plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege es… | — | wordfence |
| dd7a5a36-0e78-4fdc-b159-b4cc89cd3ffb | < 4.4 |
HIGH | 8.8 | The My Page Order plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting via t… | — | wordfence |
| dd776106-2ec6-4813-946c-36e62a32d7df | < 11.12.6 |
HIGH | 8.8 | The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to arbitrary file uploads due to missing … | — | wordfence |
| dd6df4fa-01b8-460f-b414-bb07fbc0436a | HIGH | 8.8 | The slickquiz plugin through 1.3.7.1 for WordPress allows SQL Injection by Subscriber users, as demonstrated by a /wp-ad… | — | wordfence | |
| dd129829-9682-4def-a07f-66f9178eeb77 | < 2.5.2 |
HIGH | 8.8 | The Droip plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the make_g… | — | wordfence |
| dd1248b2-21ae-449e-acf8-3e5d6353f593 | < 1.2.6 |
HIGH | 8.8 | Unrestricted File Upload vulnerability in Photo Gallery 1.2.5. | — | wordfence |
| dd02becd-77e5-46b9-acc9-dba6c5caba27 | < 2.2 |
HIGH | 8.8 | Several LWS Plugins for WordPress are vulnerable to authorization bypass due to making admin settings pages available to… | — | wordfence |
| dd0054b5-537b-412f-8b10-8bbc9f2ea256 | HIGH | 8.8 | The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with r… | — | wordfence | |
| dcddb0f3-41d5-4635-88ac-556ee3eec49a | < 0.3.12 |
HIGH | 8.8 | The Track The Click plugin for WordPress is vulnerable to time-based SQL Injection in versions up to, and including, 0.3… | — | wordfence |
| dc9dcd42-bec1-4323-b5bf-6c0518ae546d | < 1.1.8 |
HIGH | 8.8 | The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF. | — | wordfence |
| dc314c13-4be4-40fc-a035-5de0acb36c91 | < 0.3.7 |
HIGH | 8.8 | The WP Simple Spreadsheet Fetcher for Google plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… | — | wordfence |
| dc2d6986-fe9f-4776-b00f-35dd20687742 | HIGH | 8.8 | The WPCHURCH - Church Management System for Wordpress plugin for WordPress is vulnerable to Privilege Escalation in all … | — | wordfence | |
| dc023c1b-7ec6-45b6-b50a-f0d823065843 | < 2.4.41 |
HIGH | 8.8 | The Brizy β Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… | — | wordfence |
| dbf32808-b5d7-4f12-ada5-0578e0bef321 | < 5.2.6 |
HIGH | 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer β Auto & Manual Rename plugin (version… | — | wordfence |
| dbee312d-a7a1-4a75-9847-a9c6a108e149 | HIGH | 8.8 | The GitSync plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.0. Th… | — | wordfence | |
| dbd4a482-7176-446f-804d-e0cd0764a2cb | < 1.5.8 |
HIGH | 8.8 | The Store Toolkit for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and incl… | — | wordfence |
| db70b37c-707a-47b8-a3a2-5a2b7d30de89 | < 8.3.10 |
HIGH | 8.8 | The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… | — | wordfence |
| db6bb000-4f46-4a5a-b118-dcd3e78e4029 | HIGH | 8.8 | The User Meta Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence | |
| db6616b5-4c4e-4cc7-83eb-22fac94f47f2 | < 2.0.1 |
HIGH | 8.8 | The Themeflection Numbers plugin for WordPress is vulnerable to unauthorized data modification due to a missing capabili… | — | wordfence |
| db4dbbbe-1edb-47a6-8d11-8a019e05dfae | < 1.6 |
HIGH | 8.8 | The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring… | — | wordfence |
| db4616f7-e685-4dc7-947c-23c378a9bdd6 | < 3.5.2 |
HIGH | 8.8 | The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →