Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 139 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b9793793-44d5-4628-a57b-c1254645e648 | < 3.5.26 |
HIGH | 8.8 | The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in… | — | wordfence |
| b9769bc3-236f-4c9d-a4ce-544e49eee2ec | < 4.3.2 |
HIGH | 8.8 | The Astra Pro Addon plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.… | — | wordfence |
| b95ec70c-ac76-48fa-9d9d-01cf1983e504 | < 6.2.7 |
HIGH | 8.8 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i… | — | wordfence |
| b9567f63-9161-49a3-9b94-dd6dee5a5628 | < 5.4 |
HIGH | 8.8 | The democracy-poll plugin before 5.4 for WordPress has CSRF via wp-admin/options-general.php?page=democracy-poll&subpage… | — | wordfence |
| b946ee73-4cf9-48c8-b456-285b118c6b05 | < 3.8.3.5 |
HIGH | 8.8 | The Registration Forms β User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form &… | — | wordfence |
| b91f3db6-5331-48d4-9c79-9ecba0870be2 | < 1.8.6 |
HIGH | 8.8 | The Photo Gallery by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… | — | wordfence |
| b910b678-5869-43e6-8993-fcf53fe4c66f | HIGH | 8.8 | The BuddyPress Customer.io Analytics Integration pluginfor WordPress is vulnerable to Cross-Site Request Forgery in vers… | — | wordfence | |
| b8f30220-4f6e-458b-a053-8d8277150237 | < 2.8.3 |
HIGH | 8.8 | The MZ Mindbody API for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.2. T… | — | wordfence |
| b8eec2f0-1b6f-45cf-8291-019bc1d08f9b | < 26.6.3 |
HIGH | 8.8 | The Betheme theme for WordPress is vulnerable to authorization bypass in versions up to, and including, 26.6.2. This is … | — | wordfence |
| b8a41eb6-8fb2-4274-a50b-571e85ac87f8 | < 1.14.0.3 |
HIGH | 8.8 | The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF. | — | wordfence |
| b86ff40d-45dd-4cb6-9a4e-16aaf1d35196 | < 0.4.7 |
HIGH | 8.8 | WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=… | — | wordfence |
| b81c2990-68d1-4d45-9724-262ec017caf1 | < 1.6.0 |
HIGH | 8.8 | The Mapster WP Maps plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e… | — | wordfence |
| b7fe772a-542e-4c3e-b1cb-05cce3b2ec3f | < 1.2 |
HIGH | 8.8 | The "wordpress vertical image slider plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery via severa… | — | wordfence |
| b7d475d5-9c00-409c-ac07-276242540123 | < .51.1 |
HIGH | 8.8 | SQL injection vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPres… | — | wordfence |
| b7cc5b51-5fb4-470b-8d2d-581eceadde7b | < 3.7.4 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote … | — | wordfence |
| b7a57c3b-0d1b-40ad-9e55-6a1eab4e0380 | < 4.25 |
HIGH | 8.8 | The User Role Editor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the… | — | wordfence |
| b790db69-cccd-4adf-a7fa-f7db4dd96be6 | < 2.0.6 |
HIGH | 8.8 | The JS Help Desk plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.… | — | wordfence |
| b7832d37-19a9-491b-879e-4a22f2ba46ec | < 1.5.0 |
HIGH | 8.8 | The Th Shop Mania theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capab… | — | wordfence |
| b70e8bce-1793-40f0-bdb1-100cf5f431e9 | < 1.8.6 |
HIGH | 8.8 | The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… | — | wordfence |
| b6cf6390-480f-44e2-ae36-67e3398add33 | < 1.2.66 |
HIGH | 8.8 | The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65. This… | — | wordfence |
| b6b68e35-ecfb-4876-8fee-c389077b2b4a | < 2.2.2 |
HIGH | 8.8 | The Zlick Paywall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2… | — | wordfence |
| b6b0dc03-3715-41f8-8888-1cccddb39c0b | HIGH | 8.8 | The GetBookingsWP β Appointments Booking Calendar Plugin For WordPress plugin for WordPress is vulnerable to privilege… | — | wordfence | |
| b691560e-e285-467c-9d52-1620c63de1f0 | < 1.6.21 |
HIGH | 8.8 | The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence |
| b64921fe-1b09-49e7-b2ec-f708fba99c2a | < 1.4 |
HIGH | 8.8 | The 404 SEO Redirection WordPress plugin through 1.3 is lacking CSRF checks in all its settings, allowing attackers to m… | — | wordfence |
| b62fb1a8-d62d-4d1f-bcce-a081432b9e61 | HIGH | 8.8 | The Avirato hotels online booking engine plugin for WordPress is vulnerable to SQL Injection via the βidβ attribute … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →