Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 142 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b0907cb0-b101-4c88-9a8b-b35133e1d0a2 | < 1.0.6 |
HIGH | 8.8 | The MiwoFTP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.0.6. This makes it pos… | — | wordfence |
| b06ce1e4-5cfb-415d-ad09-db194d6b4354 | < 1.0.9 |
HIGH | 8.8 | The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeov… | — | wordfence |
| b02ca3a1-4e85-4bc3-a5f6-a02bec6bddef | < 2.0.4 |
HIGH | 8.8 | In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient n… | — | wordfence |
| b01ee276-baed-4678-894d-1407e538a0a3 | < 1.0.9 |
HIGH | 8.8 | The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF. | — | wordfence |
| aff4d42c-133e-4ca8-9664-6878a22f7058 | < 3.0.8.1 |
HIGH | 8.8 | The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF. | — | wordfence |
| afd7aeb7-2c6f-4b23-b8b1-52fb010e5aac | < 1.1.1 |
HIGH | 8.8 | The WP Dropzone plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and inc… | — | wordfence |
| afd4f2ca-9c27-4de0-ac82-3cd107b6a092 | HIGH | 8.8 | The Home Villas | Real Estate WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuff… | — | wordfence | |
| afcfacab-4847-4394-9f85-83dbaeed0857 | < 3.9 |
HIGH | 8.8 | The Red Art theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.8 via deserial… | — | wordfence |
| afc00118-e87e-475a-8ad6-b68d09ee2e44 | HIGH | 8.8 | The Custom Field Suite plugin for WordPress is vulnerable to SQL Injection via the the 'Term' custom field in all versio… | — | wordfence | |
| afa44a28-2368-4c52-b234-309476526290 | HIGH | 8.8 | The eewee admin custom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… | — | wordfence | |
| af7d935b-05a2-4eaa-af98-4e6a88abab46 | < 3.2.6 |
HIGH | 8.8 | The acx_asmw_saveorder_callback function in function.php in the acurax-social-media-widget plugin before 3.2.6 for WordP… | — | wordfence |
| af6bd2db-47a4-4381-a881-d5f97a159f8d | HIGH | 8.8 | The BAN Users plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.5.3 due to … | — | wordfence | |
| af67a544-daff-469f-a66b-e998b79b7845 | < 1.1.6 |
HIGH | 8.8 | The Embed PDF for WPForms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… | — | wordfence |
| af4b659b-6a14-46bc-9ffe-6f118c6b1e8d | < 4.3000000024 |
HIGH | 8.8 | The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to arbitrary file uploads throu… | — | wordfence |
| af2d004f-fa9e-4e26-a1e3-03fb31cb95c4 | < 8.6.2 |
HIGH | 8.8 | The Ultimate Membership Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
| af075ffe-553a-4351-a696-5c678788f3b9 | < 4.9.3.4 |
HIGH | 8.8 | The Slimstat Analytics plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in versions up … | — | wordfence |
| aee4fb6f-8ee6-4d6e-8167-876c9453f78f | < 1.2.6 |
HIGH | 8.8 | The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.2.6. This is due to m… | — | wordfence |
| aed40456-43c3-4647-9bce-e7c6139c84cd | < 2.3.5 |
HIGH | 8.8 | The BeeTeam368 Extensions plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including… | — | wordfence |
| ae81917e-0367-4c64-9254-fd74751ada48 | < 3.5.1.11 |
HIGH | 8.8 | The Smart Slider 3 plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5.1.9 … | — | wordfence |
| ae741363-b0aa-4263-bb49-d3baa213167a | < 1.14 |
HIGH | 8.8 | The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF. | — | wordfence |
| ae4c7354-b179-43d7-8a41-0f54dc855fd3 | < 4.0.13 |
HIGH | 8.8 | The Post Snippets – Custom WordPress Code Snippets Customizer plugin for WordPress is vulnerable to Remote Code Execut… | — | wordfence |
| ae4a8e70-6b94-428f-8672-407dc4cd2f3f | HIGH | 8.8 | The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. Th… | — | wordfence | |
| ae39fac4-6b65-42a6-bd34-c364922ef675 | < 2.11.16 |
HIGH | 8.8 | The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin… | — | wordfence |
| ae397949-12d2-4323-871e-4fd4f14f35c6 | < 0.5.1 |
HIGH | 8.8 | The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise an… | — | wordfence |
| ae201118-bacf-4849-92f5-569cef57ee30 | HIGH | 8.8 | The AI Mortgage Calculator plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →