Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 127 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d7f4e710-99a2-49df-a513-725e1daaa18a | < 1.2.1 |
HIGH | 8.8 | The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… | — | wordfence |
| d7f0f654-e455-4284-ba44-35f1fbcbb3ba | HIGH | 8.8 | The Sale! Immigration law, Visa services support, Migration Agent Consulting theme for WordPress is vulnerable to Privil… | — | wordfence | |
| d7e7247f-869a-4cf0-ae03-0b36ecbc1b7e | < 3.1.3.1 |
HIGH | 8.8 | The Crocoblock JetEngine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… | — | wordfence |
| d7c98191-bf17-4e94-88cc-ad385b1fe97d | HIGH | 8.8 | The Auto Thumbnailer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… | — | wordfence | |
| d7b7b31a-2bc4-42b7-ba60-0f29fe65bbe7 | HIGH | 8.8 | Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in Mufeng's Hermit éŸ³ä¹æ’放器 plugi… | — | wordfence | |
| d79dc179-8f0e-47e3-9697-82d9c9d44be2 | HIGH | 8.8 | The WP Masquerade plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.0… | — | wordfence | |
| d764b1be-b4ae-4845-b506-846f782cf21e | HIGH | 8.8 | The Private Files WordPress plugin through 0.40 is missing CSRF check when disabling the protection, which could allow a… | — | wordfence | |
| d74efb03-4a1c-4163-bd79-ef17975a609e | < 1.9.0 |
HIGH | 8.8 | The Export Import Menus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… | — | wordfence |
| d7220537-aad0-48e0-81f1-7104ec15ffbe | < 1.3.1 |
HIGH | 8.8 | The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are … | — | wordfence |
| d6fbf684-8651-484d-9459-ed11d6d9008f | < 1.1 |
HIGH | 8.8 | The SB Random Posts Widget plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, … | — | wordfence |
| d6fb275b-dbba-46df-b170-977ef4a84c4c | < 4.1.17 |
HIGH | 8.8 | The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload … | — | wordfence |
| d6dfed14-bb6f-4418-bdd8-9c548e63dac0 | < 4.6 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.… | — | wordfence |
| d6d394af-67b0-4754-bdec-6ee89b7e8bbd | < 2.7.7 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in admin/setting.php in the Xhanch - My Twitter plugin before 2.7.7 for … | — | wordfence |
| d676700b-8c53-4e09-a654-767810b5a775 | HIGH | 8.8 | The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2.… | — | wordfence | |
| d6572568-5586-4ed9-b0e2-32509b42ed31 | < 2.8.4 |
HIGH | 8.8 | The Welcart e-Commerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence |
| d6489214-2155-47f4-83ef-0119b3c26e43 | < 1.8.3 |
HIGH | 8.8 | The tutor_quiz_builder_get_answers_by_question AJAX action from the Tutor LMS – eLearning and online course solution W… | — | wordfence |
| d6206d7e-90b9-43fd-a6cd-90e98162cd09 | < 1.2 |
HIGH | 8.8 | The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface. | — | wordfence |
| d60fb13c-cba8-466a-8881-1ed835881b79 | HIGH | 8.8 | The Flash News / Post (Responsive) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… | — | wordfence | |
| d60e1a2c-a3f1-4c39-a22f-9c09d0fed2c5 | < 1.1.1 |
HIGH | 8.8 | The stats plugin for WordPress is vulnerable to SQL Injection via the $post_ids parameter in versions up to, and includi… | — | wordfence |
| d60b5741-5496-4e87-bcb0-adaa0db07d90 | < 1.21.12 |
HIGH | 8.8 | The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vu… | — | wordfence |
| d5b110a5-4027-4c98-a348-325c8b9c8405 | < 14.1.00 |
HIGH | 8.8 | The WooCommerce Amazon Affiliates - Wordpress Plugin plugin for WordPress is vulnerable to privilege escalation in all v… | — | wordfence |
| d5a0c514-5200-47f4-9d2e-684d68946b9a | < 1.4.6.1 |
HIGH | 8.8 | The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.… | — | wordfence |
| d560f28f-899c-44cf-8640-55647c1de7dc | HIGH | 8.8 | The ScrollTo Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in version… | — | wordfence | |
| d557db81-9689-4fc1-b749-3595859048de | < 1.3.2 |
HIGH | 8.8 | The Testimonial Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence |
| d539dc3f-ebb9-40d6-9016-7d52935e2575 | < 7.3.8 |
HIGH | 8.8 | The GamiPress plugin for WordPress is vulnerable to Local File Inclusion via the gamipress_logs_shortcode() function in … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →