Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 143 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| adfd506e-7b47-4aeb-a21e-034624210574 | HIGH | 8.8 | The WPAMS - Apartment Management System for wordpress plugin for WordPress is vulnerable to arbitrary file uploads due t… | — | wordfence | |
| adf51c03-b0bb-4864-b64d-6b0cba4b0130 | HIGH | 8.8 | The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin… | — | wordfence | |
| adeb4e0b-13fe-4f80-9b24-62bf2a057ead | < 2.0.5 |
HIGH | 8.8 | The Password Policy Manager | Password Manager plugin for WordPress is vulnerable to privilege escalation via account ta… | — | wordfence |
| ada52ae9-7d14-405d-9efc-b993ea273a26 | < 2.7.2 |
HIGH | 8.8 | The Woody Code Snippets β Insert PHP, CSS, JS, and Header/Footer Scripts plugin for WordPress is vulnerable to Remote … | — | wordfence |
| ad8dff1e-b9f8-4383-8efb-8bceaa8c86c6 | < 3.0 |
HIGH | 8.8 | The Mediamatic β Media Library Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… | — | wordfence |
| ad66015d-7831-4590-9583-3abf7ca43c3b | < 3.2.5 |
HIGH | 8.8 | The JetEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.2.4. Th… | — | wordfence |
| ad5aeea0-ba5a-488a-9087-9b7567f31c70 | < 8.1.4 |
HIGH | 8.8 | The WP Customer Area plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| ad2e1d91-03bd-4e47-b679-81c42414238b | < 4.6.4 |
HIGH | 8.8 | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and incl… | — | wordfence |
| acff00f2-586d-474c-8dec-f27c488e9045 | < 15.0.2 |
HIGH | 8.8 | The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field. | — | wordfence |
| acf1e98a-9e9d-453d-afce-6e47fce3a2d2 | < 4.3.1 |
HIGH | 8.8 | The wp-database-backup plugin before 4.3.1 for WordPress has CSRF. | — | wordfence |
| acbea2eb-fa87-4117-b347-049c819599c7 | < 2.4.1 |
HIGH | 8.8 | The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() functi… | — | wordfence |
| aca8482e-7a5b-4f2d-965c-a1184fb6a374 | < 2.0.0 |
HIGH | 8.8 | The Voice Feedback β Voice Recorder for Audio Feedback plugin for WordPress is vulnerable to Privilege Escalation in a… | — | wordfence |
| ac53f2b6-85fe-4475-975f-6dbd15fa87f4 | HIGH | 8.8 | The PDF 2 Post plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.0. … | — | wordfence | |
| ac4de440-a446-4b96-ba9b-115e3186ce1c | HIGH | 8.8 | TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the d… | — | wordfence | |
| ac4c6bd8-179f-4553-b1b4-549300bae374 | < 2.2.1 |
HIGH | 8.8 | Unrestricted file upload vulnerability in WordPress before 2.2.1 and WordPress MU before 1.2.3 allows remote authenticat… | — | wordfence |
| ac23cd7d-193d-4fa1-8c1c-79ca92da98d7 | HIGH | 8.8 | The User Management plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2… | — | wordfence | |
| ac1c4818-6384-48cf-a1e3-a8ced6884749 | < 2.2.4 |
HIGH | 8.8 | The Social Share Buttons by Supsystic WordPress plugin before 2.2.4 does not perform CSRF checks in it's ajax endpoints … | — | wordfence |
| abb10680-6208-44c8-8cf0-8d2531465a04 | < 1.0.27 |
HIGH | 8.8 | The WP-Matomo Integration (WP-Piwik) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… | — | wordfence |
| ab796de7-2bc6-4e25-be00-25d0941045fb | < 1.5.5 |
HIGH | 8.8 | The WordPress Post Grid Layouts with Pagination β Sogrid plugin for WordPress is vulnerable to Cross-Site Request Forg… | — | wordfence |
| ab770acd-9420-4201-9e67-dfea86dba168 | < 12.2 |
HIGH | 8.8 | The WP Review Slider plugin for WordPress is vulnerable to SQL Injection via the $tid value in versions up to, and inclu… | — | wordfence |
| ab520bcb-5739-4b99-ad93-73416ab39084 | < 1.2.2 |
HIGH | 8.8 | The WP Frontend Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence |
| ab248283-e331-4159-9fe4-249243772c9b | HIGH | 8.8 | The Orange Form WordPress plugin through 1.0.1 does not have any authorisation and CSRF checks in all of its AJAX calls,… | — | wordfence | |
| aadf1f4c-c852-4167-9b09-7e679a953725 | < 8.3.5 |
HIGH | 8.8 | The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file pat… | — | wordfence |
| aab16b6f-4daf-4eb1-9526-dd05b2b41dee | < 2.85.5 |
HIGH | 8.8 | The MapPress Maps for WordPress plugin for WordPress is vulnerable to SQL Injection via the get_maps function in version… | — | wordfence |
| aa9ba135-3b08-4ee9-9a06-3c9880bfdd18 | HIGH | 8.8 | The Insurance theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5 via deseri… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →