Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 129 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d245dc6c-c579-4e28-a953-9227261911d4 | HIGH | 8.8 | The Custom Content Shortcode plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… | — | wordfence | |
| d2278347-d961-47d7-b89d-61a82441597c | HIGH | 8.8 | The WZone - Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.… | — | wordfence | |
| d225dee1-305c-4378-bc07-192347a0c838 | < 4.7.0 |
HIGH | 8.8 | The WP ULike β Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to SQL Injection via the '… | — | wordfence |
| d22013e5-896a-4dcb-bbe4-e6be7d697816 | < 3.42.10 |
HIGH | 8.8 | The WP Fusion Lite β Marketing Automation and CRM Integration for WordPress plugin for WordPress is vulnerable to Remo… | — | wordfence |
| d21bebcc-8dba-407d-8a3a-b91d3cddd38f | < 6.4.1 |
HIGH | 8.8 | The WP Ultimate CSV Importer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… | — | wordfence |
| d20ffc7c-0e12-45ec-940f-a42655093021 | < 5.1.5 |
HIGH | 8.8 | The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_s… | — | wordfence |
| d2031289-eaf3-4a1b-8771-769c08d99ca3 | < 1.3.56 |
HIGH | 8.8 | The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| d1d21339-3a86-4bee-be86-2d2ab9190b26 | < 1.5.2 |
HIGH | 8.8 | The WooCommerce Report plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence |
| d1b3d4d5-9d2b-4924-a830-27c07fa1ba98 | < 1.5.4 |
HIGH | 8.8 | The Salient Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, … | — | wordfence |
| d18c17f1-7b85-46d6-a92e-948be98adf87 | < 2.0.9 |
HIGH | 8.8 | The MZ MBO Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0… | — | wordfence |
| d151c9a1-d47e-4155-8539-133f6abd57a5 | < 2.1.1 |
HIGH | 8.8 | The hndtst_action_instance_callback AJAX call of the Handsome Testimonials & Reviews WordPress plugin before 2.1.1, avai… | — | wordfence |
| d143cefc-e387-47bd-aff6-a2099f704d20 | < 1.6.0 |
HIGH | 8.8 | The Creative Mail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5… | — | wordfence |
| d10a0372-1ab3-474e-8d5c-33f71fddfe06 | < 2.1.4 |
HIGH | 8.8 | The Mail Subscribe List WordPress plugin before 2.1.4 does not have CSRF check in place when deleting subscribed users, … | — | wordfence |
| d10336c2-656f-40f7-a95a-dbf829c2ce38 | < 1.2 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in Browser and Operating System Finder versions prior to 1.2 allows a re… | — | wordfence |
| d0d8d660-4f8f-4fd5-b001-b182219cf327 | HIGH | 8.8 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Post to Twitter plugin 0.7 and earlier for WordPress a… | — | wordfence | |
| d0c72033-ab9b-49bb-be28-e09a810137fe | < 2.3 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the FeedBurner FeedSmith 2.2 plugin for WordPress allows remote attac… | — | wordfence |
| d0b1fa88-2fc6-41af-bd39-12af92dc6533 | < 9.3 |
HIGH | 8.8 | The Message ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and… | — | wordfence |
| d0999244-4097-4e8c-8f7e-4accd7727d69 | < 4.0.14 |
HIGH | 8.8 | The Dropshix plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several func… | — | wordfence |
| d056eeea-6ed2-4139-ba32-727a95f29aaf | < 2.5.1 |
HIGH | 8.8 | The Polylang plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5. Thi… | — | wordfence |
| d0506137-82e3-4988-9b23-370465a866c0 | < 4.7.2 |
HIGH | 8.8 | The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vu… | — | wordfence |
| d038f1a2-4755-417f-965d-508b57c05738 | HIGH | 8.8 | The WP Easy Post Types plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.… | — | wordfence | |
| d03459d8-b1f2-4270-a294-403754db1f2f | < 3.2.0 |
HIGH | 8.8 | The User Registration β Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress i… | — | wordfence |
| d0301141-bbc6-4a9e-b816-888554600b57 | < 3.3.3 |
HIGH | 8.8 | The iubenda plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.2. Th… | — | wordfence |
| d0177510-cd7d-4cc5-96c3-78433aa0e3f6 | < 1.1.6 |
HIGH | 8.8 | The BookingPress β Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable… | — | wordfence |
| CVE-2026-8365 | < 2.1.35. |
HIGH | 8.8 | The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_… | — | nvd |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →