Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 140 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b5fd7bca-7754-4f83-8e51-5278e6e8cc78 | HIGH | 8.8 | The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeov… | — | wordfence | |
| b59ef0f8-3186-48f8-ade3-a7afe9e4f8ff | < 0.9.0 |
HIGH | 8.8 | The Kids Online Store theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… | — | wordfence |
| b5818587-0a52-4734-8f75-263b4ab5020e | < 2.1.0 |
HIGH | 8.8 | The ForumWP β Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure … | — | wordfence |
| b55128e9-f79f-4872-931f-c6f4d1d12032 | < 1.9.19 |
HIGH | 8.8 | The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter. | — | wordfence |
| b536563f-b978-4ba6-8a28-d8ee6b87964a | < 3.3.1 |
HIGH | 8.8 | The acf-better-search (aka ACF: Better Search) plugin before 3.3.1 for WordPress allows wp-admin/options-general.php?pag… | — | wordfence |
| b536028d-4e11-4bda-8097-b37857a28309 | HIGH | 8.8 | The Thumbnail For Excerpts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence | |
| b530d1a3-dd3c-4efb-9cff-39b6908f11c9 | < 1.0.4 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the Disable Comments plugin before 1.0.4 for WordPress allows remote … | — | wordfence |
| b4ff715e-056e-48d8-bb82-d4f89047384f | < 5.16.6 |
HIGH | 8.8 | Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[… | — | wordfence |
| b4eb5833-25cd-4a6c-9240-37a9f8c1b120 | < 2.0.0 |
HIGH | 8.8 | The WP Brutal AI plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions before 2.0.0 d… | — | wordfence |
| b4e0ee4f-fc45-4682-9ed4-aa1301205bb4 | < 3.3.5 |
HIGH | 8.8 | The Rate my Post plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.… | — | wordfence |
| b4de2c22-4d8f-45b1-bccb-c536eefd58a8 | HIGH | 8.8 | The WordPress BasePress Migration Tools plugin for WordPress is vulnerable to arbitrary file uploads due to missing file… | — | wordfence | |
| b4d33e69-3620-42d9-adb3-267a5ed02a58 | < 1.9 |
HIGH | 8.8 | WP Maintenance Mode & Site Under Construction Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versio… | — | wordfence |
| b4accf10-710e-4cba-8d61-04e422324f9d | < 12.1 |
HIGH | 8.8 | The WP fade in text news plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up t… | — | wordfence |
| b4599c7f-5e5d-4571-97d9-54d6fd0c9c63 | < 2.12.1 |
HIGH | 8.8 | The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of dat… | — | wordfence |
| b3f75424-b9f3-42ee-a96c-ff0ed30cbd2f | < 1.4.6.1 |
HIGH | 8.8 | The WPS Limit Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… | — | wordfence |
| b3ce53e5-8666-4227-83d3-58f35db0ce68 | < 3.0.12 |
HIGH | 8.8 | The Ultimate WordPress Toolkit β WP Extended plugin for WordPress is vulnerable to Remote Code Execution in version 3.… | — | wordfence |
| b3bb31c8-b1d9-4189-a27f-ac62d19532b2 | < 8.7.4 |
HIGH | 8.8 | The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versi… | — | wordfence |
| b3adfe9e-ebdf-4a50-b60f-03a606a84ec0 | HIGH | 8.8 | The Realty Portal β Agent plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization with… | — | wordfence | |
| b37e6b44-810a-49c8-8903-30a9e228027d | < 4.5 |
HIGH | 8.8 | The Simple Share Buttons Adder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… | — | wordfence |
| b3758f06-2b69-458f-a7c8-f604f0fbda31 | < 6.60 |
HIGH | 8.8 | The StopBadBots WordPress plugin before 6.60 did not validate or escape the order and orderby GET parameter in some of i… | — | wordfence |
| b2cf3b85-2e2d-43dc-9877-9a740d4fd2fb | < 3.7.3.6 |
HIGH | 8.8 | The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner β Groundhogg plugin for WordPress is vuln… | — | wordfence |
| b2cea890-b131-47cd-9050-a484fb1895f6 | < 1.1 |
HIGH | 8.8 | The 5 Star Hotel theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… | — | wordfence |
| b2c83287-13ca-4fdc-95b6-97da150b0c09 | < 4.5.3 |
HIGH | 8.8 | The WP Meta SEO plugin for WordPress is vulnerable to SQL Injection via the βidsβ parameter in the bulkImageCopy fun… | — | wordfence |
| b2a98c69-5f76-41f4-8a12-0523285647fb | < 4.1.0.2 |
HIGH | 8.8 | The All in One SEO β Best WordPress SEO Plugin β Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticat… | — | wordfence |
| b29113d6-7a9a-4e10-a446-147ec146ac93 | < 9.1.0 |
HIGH | 8.8 | The News Announcement Scroll plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →