Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 13 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f15dbce4-2e94-4735-b62b-e32d923c51ce | < 1.3 |
CRITICAL | 9.8 | The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, … | — | wordfence |
| f1388322-d935-4101-a6c4-a7c99228ddec | < 3.1.3 |
CRITICAL | 9.8 | The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via… | — | wordfence |
| f10fd160-70cc-4f27-8175-830ccb90bf63 | CRITICAL | 9.8 | The VRPConnector plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.1 via … | — | wordfence | |
| f10e5eef-1ccf-4f98-b0e9-5ed05b3881a6 | < 3.1.24 |
CRITICAL | 9.8 | The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the id, and form_id param… | — | wordfence |
| f107a2be-e75b-43f3-8d41-b68c50c27f55 | CRITICAL | 9.8 | The jQuery HTML5 File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… | — | wordfence | |
| f0ec70a0-d1be-4652-b029-d8268c2667ec | < 2.8.2 |
CRITICAL | 9.8 | The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL state… | — | wordfence |
| f0ea7279-bba3-49c4-b36a-0d51c96a23cf | < 3.0 |
CRITICAL | 9.8 | importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers … | — | wordfence |
| f0e77557-f377-4752-bc5b-ec00f2520150 | CRITICAL | 9.8 | The Chocolate WP β Responsive Photography Theme for WordPress is vulnerable to Remote File Inclusion in all versions d… | — | wordfence | |
| f0cb666b-bfab-492f-a74e-11dc9b171136 | < 2.2.2 |
CRITICAL | 9.8 | The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab… | — | wordfence |
| f0accbee-8ab3-4e6a-b7c8-a204d681d8cf | < 4.0.1 |
CRITICAL | 9.8 | Social Media Widget (social-media-widget) plugin 4.0 for WordPress contains an externally introduced modification (Troja… | — | wordfence |
| f0a261e9-8b96-4065-8fd3-7be53cc3c9a2 | < 1.0.73 |
CRITICAL | 9.8 | The 10Web Map Builder for Google Maps plugin for WordPress is vulnerable to SQL Injection via the 'radius', 'lat', and '… | — | wordfence |
| f09aed55-bfe4-4199-9cf2-73cc9bfd678c | CRITICAL | 9.8 | The Butcher theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.40. This makes… | — | wordfence | |
| f091d9fa-4331-4a21-8868-e9400472524b | CRITICAL | 9.8 | The Ads Pro Plugin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.89. Th… | — | wordfence | |
| f056aee7-8e73-41b5-8dbc-aef6557c52ab | < 1.1.3 |
CRITICAL | 9.8 | The wastia theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versio… | — | wordfence |
| f04eab14-dd86-4145-b5eb-20d064bc8417 | < 3.6.1 |
CRITICAL | 9.8 | The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation in versions up … | — | wordfence |
| f016fcdc-02d1-46be-98b1-eaceb34c4ca1 | CRITICAL | 9.8 | The Altair theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.2.2 via deseria… | — | wordfence | |
| f00eeaef-f277-481f-9e18-bf1ced0015a0 | < 3.3.1 |
CRITICAL | 9.8 | The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient in… | — | wordfence |
| f00b2602-b9ab-4f4a-a19e-5c2a98c232e3 | < 1.4.10 |
CRITICAL | 9.8 | SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQ… | — | wordfence |
| f00761a7-fe24-49a3-b3e3-a471e05815c1 | < 3.9.3 |
CRITICAL | 9.8 | The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This… | — | wordfence |
| f006bb33-d017-445b-9c02-bd848c199671 | < 1.1.38 |
CRITICAL | 9.8 | The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Local File Inclusion in all v… | — | wordfence |
| eff47e59-9a2c-424f-b138-47fcf554c06b | < 1.14 |
CRITICAL | 9.8 | The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and includi… | — | wordfence |
| efbea599-3d04-42d2-9b91-6b68210d8b01 | < 1.1 |
CRITICAL | 9.8 | The Appius theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload… | — | wordfence |
| ef8bfb38-4f20-4f9f-bb30-a88f3be2d2d3 | < 0.9.69 |
CRITICAL | 9.8 | The Migration, Backup, Staging β WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' pa… | — | wordfence |
| ef8a43c7-f391-44fc-882c-26c1c8b5df78 | < 1.4 |
CRITICAL | 9.8 | SQL injection vulnerability in wp-users.php in WordPress Users plugin 1.3 and possibly earlier for WordPress allows remo… | — | wordfence |
| ef79e5a8-8bac-42b3-a064-6eea597701c9 | < 1.0.37 |
CRITICAL | 9.8 | The Woodmart Core plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.36 vi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →