Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 137 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| bf11aed9-8782-4579-95a5-e88b19641ae8 | < 1.4.3 |
HIGH | 8.8 | The Falang multilanguage for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,… | — | wordfence |
| beb47081-ad9c-4ecb-bbcd-2ae916e55baf | < 5.2.6 |
HIGH | 8.8 | The Media File Renamer β Auto & Manual Rename plugin for WordPress is vulnerable to authorization bypass due to a miss… | — | wordfence |
| be6c08b9-bba7-4780-99b9-4b80e6b4872a | < 1.5.3 |
HIGH | 8.8 | Multiple SQL injection vulnerabilities in admin.php in the Collne Welcart plugin before 1.5.3 for WordPress allow remote… | — | wordfence |
| be60b765-3bd6-43dd-8cdc-d9c493a503e5 | HIGH | 8.8 | The accurate-form-data-real-time-form-validation plugin 1.2 for WordPress has CSRF with resultant XSS via wp-admin/optio… | — | wordfence | |
| be5142f6-36da-4715-91d2-7d6665c0efa6 | < 1.3.8 |
HIGH | 8.8 | The WP Travel Engine β Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor plugin for Word… | — | wordfence |
| be4061ef-849a-4797-aeee-07da2afc1a40 | < 1.3.0 |
HIGH | 8.8 | A Cross-Site Request Forgery leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.… | — | wordfence |
| be0e0e79-00c3-4237-ac65-9c5df625dd89 | HIGH | 8.8 | The gSlideShow plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.1. T… | — | wordfence | |
| be0d4cf1-db98-4388-9d88-27746ef239ee | < 1.0.10 |
HIGH | 8.8 | The Vite Coupon plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.9… | — | wordfence |
| be098ee9-b749-4908-85e8-e717d019609a | < 4.6.5 |
HIGH | 8.8 | The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and inc… | — | wordfence |
| bde2a8a5-2d18-4659-bb35-dff4f521dbb4 | < 1.6.2.1 |
HIGH | 8.8 | The Xserver Migrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… | — | wordfence |
| bdd9045e-5869-446b-9a6e-4c6766b91d05 | HIGH | 8.8 | The Sync Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '… | — | wordfence | |
| bdd70819-57dd-4a60-9398-68d6b87da3ca | < 1.0.47 |
HIGH | 8.8 | The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user… | — | wordfence |
| bdc946ed-8891-4f97-af7e-2034760eef5b | HIGH | 8.8 | The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to Cross-Site… | — | wordfence | |
| bdb35f31-60a6-40b5-aed3-102a1c8c4fd1 | < 2.4.1 |
HIGH | 8.8 | The WordPress REST API Authentication plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… | — | wordfence |
| bda2f3f6-b036-4feb-bb38-1d4eaf965c24 | < 5.30.3 |
HIGH | 8.8 | The YARRP plugin for WordPress is vulnerable to SQL Injection via the 'limit' parameter set via a shortcode in versions … | — | wordfence |
| bd715375-6bf8-4602-9554-b1f81aa5afa2 | < 2.2.1 |
HIGH | 8.8 | SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL co… | — | wordfence |
| bd478bb7-f0d7-4a29-8236-96ad69b5ae67 | < 3.3.1 |
HIGH | 8.8 | The Vitepos β Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to … | — | wordfence |
| bd42c89e-57db-458f-910c-404a5615f280 | < 3.9.9.3 |
HIGH | 8.8 | The Eventer - WordPress Event & Booking Manager Plugin plugin for WordPress is vulnerable to SQL Injection via the reg_i… | — | wordfence |
| bd3c1e65-fcb2-4e31-973b-8271a833c6ba | < 5.6 |
HIGH | 8.8 | The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter … | — | wordfence |
| bd38b5f2-f13e-4433-9a8a-2f42cc1782c6 | < 1.6.0 |
HIGH | 8.8 | The MWB HubSpot for WooCommerce β CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics plugin for Wo… | — | wordfence |
| bd302d8e-bba1-4fa1-bcbc-591d894ca1d6 | < 5.7.0 |
HIGH | 8.8 | The Simple Link Directory plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5… | — | wordfence |
| bd1838c4-00df-4177-84be-1f8c19ceae4e | < 9.3 |
HIGH | 8.8 | The wp-championship plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9… | — | wordfence |
| bced4547-3264-43dc-8bb1-89a06f74ccbd | HIGH | 8.8 | Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check … | — | wordfence | |
| bcd40c75-9c27-46b3-9ab8-dc8aad45c74c | HIGH | 8.8 | The Mimoos plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2 due to insufficient… | — | wordfence | |
| bc69ec54-b30f-402e-ad3b-24fd680ea72b | < 2.0.8 |
HIGH | 8.8 | The Groundhogg plugin for WordPress is vulnerable to generic SQL Injection via the '/wp-content/plugins/groundhogg/inclu… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →