Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 126 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| db251792-cbad-41e1-aaca-4cd39a25b444 | < 3.32.1 |
HIGH | 8.8 | The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … | — | wordfence |
| dae2d028-6976-468a-9e93-ec712887d657 | < 10.5 |
HIGH | 8.8 | The LionScripts: IP Blocker Lite plugin for WordPress is vulnerable to arbitrary file uploads via Cross-Site Request For… | — | wordfence |
| dad288b3-e599-460d-9b99-3bce04489557 | < 5.2.1 |
HIGH | 8.8 | The RD Station plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2.0.… | — | wordfence |
| da9b1132-fb02-443d-8d56-9e89658aad89 | < 1.20 |
HIGH | 8.8 | The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction … | — | wordfence |
| da24aad2-ae6b-411e-a229-0df585215731 | < 2.9 |
HIGH | 8.8 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit F… | — | wordfence |
| da025593-ad11-4a48-97e1-d31c6f0e62ea | < 1.2.7.31 |
HIGH | 8.8 | The Breezing Forms plugin for WordPress is vulnerable to generic SQL Injection via the ‘page’ parameter in versions … | — | wordfence |
| d9fbd7ee-cfd0-4621-9eb9-df0202657ce9 | < 1.3.5 |
HIGH | 8.8 | The crelly-slider plugin before 1.3.5 for WordPress has arbitrary file upload via a PHP file inside a ZIP archive to wp_… | — | wordfence |
| d97b6f64-a596-4c83-8ab5-98b4b246897f | < 2.0 |
HIGH | 8.8 | The Formidable Form Builder plugin for WordPress is vulnerable to blind SQL Injection via the ‘orderby’ parameter in… | — | wordfence |
| d96c9b04-6850-40ab-8006-81cca8a9dffe | < 1.7.8 |
HIGH | 8.8 | The CM Ad Changer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Banner Title field in versio… | — | wordfence |
| d9606d92-8061-4dfc-a6e2-509b54613277 | < 3.7.10 |
HIGH | 8.8 | The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrust… | — | wordfence |
| d93de33b-1715-4e86-9df0-c20625d455d1 | HIGH | 8.8 | The IF AS Shortcode plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.… | — | wordfence | |
| d922fdf8-8bbb-4722-ad16-a013264085f2 | < 2.0.3 |
HIGH | 8.8 | The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to Privilege Escalati… | — | wordfence |
| d91ea0c9-ee41-4c8f-a16b-8b36c7f0a72e | < 3.6.1 |
HIGH | 8.8 | wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which … | — | wordfence |
| d9108d5f-7b8b-478d-ba9d-f895bdb7dbf2 | < 2.7.31.2 |
HIGH | 8.8 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode … | — | wordfence |
| d8ba4a74-6649-4566-b9d5-19662539158b | < 5.0.1.6 |
HIGH | 8.8 | The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action befo… | — | wordfence |
| d8b544ba-8530-4c00-a8a8-b24d8b68a33a | < 2.1.0 |
HIGH | 8.8 | The Double Opt-In for Download Plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in… | — | wordfence |
| d872ec33-6284-495c-b894-41fe7b40b63c | HIGH | 8.8 | The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing f… | — | wordfence | |
| d85b98c3-c912-4467-962c-eb64465266b2 | HIGH | 8.8 | The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a S… | — | wordfence | |
| d847e26b-8c11-4612-84d7-ff319ca374dc | < 1.8.0 |
HIGH | 8.8 | The Elementor Website Builder plugin for WordPress is vulnerable to missing authorization in versions up to, and includi… | — | wordfence |
| d83d1fd0-6e21-406e-a7c0-89d26eabbb32 | HIGH | 8.8 | The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.2… | — | wordfence | |
| d831fa81-4714-4757-b75d-0a8f5edda910 | < 1.6.9 |
HIGH | 8.8 | The Web Directory Free for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, a… | — | wordfence |
| d82efaa3-ea61-476c-ad1a-60585450c63a | < 2.0 |
HIGH | 8.8 | The Contact Form 7 Email Add on plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in… | — | wordfence |
| d81ed8d9-4a7a-4b75-aab4-8e4dbd554f32 | HIGH | 8.8 | The Mediamatic – Media Library Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… | — | wordfence | |
| d80d583f-42c8-48fb-b757-88346c740b0e | HIGH | 8.8 | The eExamhall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0. Th… | — | wordfence | |
| d8029737-f3ad-4025-948a-ba0298c0869d | < 1.26.2 |
HIGH | 8.8 | The WP Job Manager plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check and mi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →