Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 144 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| aa972bbc-2123-45d4-b313-1e53397a5dc1 | < 5.6.83 |
HIGH | 8.8 | The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to unauthorized arbitrary pl… | — | wordfence |
| aa916029-b526-4ff3-ba70-2875b62d33a6 | HIGH | 8.8 | The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which c… | — | wordfence | |
| aa8f75dc-7ecd-498d-b41a-e788b4d4bcdd | HIGH | 8.8 | Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote adm… | — | wordfence | |
| aa6b63bc-6e5f-498e-83e1-45e8e6c72df4 | HIGH | 8.8 | The Task Manager Pro plugin for WordPress is vulnerable to blind SQL Injection via the 'task' parameter in versions up t… | — | wordfence | |
| aa64d6b4-5673-4d88-b5c7-d3441eaa0706 | HIGH | 8.8 | The WP Popup Banners plugin for WordPress is vulnerable to a time-based SQL Injection via the 'value' parameter of the g… | — | wordfence | |
| aa55dfe1-7ee8-4d25-a9f6-cbefeebb1376 | < 5.7.3 |
HIGH | 8.8 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to boolean-based SQL Injection via the ‘model_n… | — | wordfence |
| a9cc4dcf-7485-458c-8376-a19b2c32f8d6 | HIGH | 8.8 | The iBryl Switch User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1… | — | wordfence | |
| a9b3b6cc-faaa-46c2-ab82-00c7138a8f27 | HIGH | 8.8 | The WP Dispatcher plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, … | — | wordfence | |
| a9af89a7-7d02-4656-a7b1-89f7a3555334 | < 4.23.0 |
HIGH | 8.8 | The KALLYAS - Creative eCommerce Multi-Purpose WordPress Theme theme for WordPress is vulnerable to arbitrary file uploa… | — | wordfence |
| a971c80b-c71a-4c58-8291-c8918af034d9 | < 2.0.4 |
HIGH | 8.8 | A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks W… | — | wordfence |
| a95e98e4-97a7-436f-9ceb-6ff6fecd860f | HIGH | 8.8 | The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu… | — | wordfence | |
| a9461354-0e69-47d9-a11c-838cfa94be67 | < 1.3 |
HIGH | 8.8 | SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for Wo… | — | wordfence |
| a929efaf-80a1-45c1-9426-6c5b45a66530 | < 2.3.3 |
HIGH | 8.8 | The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerabl… | — | wordfence |
| a928247a-3eb5-4889-bd42-b0263f4cd140 | < 5.2.2 |
HIGH | 8.8 | The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file… | — | wordfence |
| a908ac17-666f-4725-86f4-c9af4589fb69 | < 2.8.22 |
HIGH | 8.8 | The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the order data edit page in versions up t… | — | wordfence |
| a8f31b4b-c8d8-4028-b419-f8396a5cb2a9 | < 1.0.34 |
HIGH | 8.8 | The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitr… | — | wordfence |
| a8eb3ec8-0784-4702-86bf-a621b288e7a0 | HIGH | 8.8 | The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all ve… | — | wordfence | |
| a8e8d724-60fe-4333-8c55-cb7df0d4345d | < 3.3.3 |
HIGH | 8.8 | The ubenda plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.3.2. This is d… | — | wordfence |
| a8b10d0c-e2fc-47a3-9df9-8df58eee964c | < 4.0.7 |
HIGH | 8.8 | The MStore API plugin for WordPress is vulnerable to SQL Injection via the $name and $search variables in versions up to… | — | wordfence |
| a8a67cad-b52d-4294-9c27-13b1dc1f2e59 | < 1.6.0 |
HIGH | 8.8 | The Creative Mail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5… | — | wordfence |
| a895e2cf-9eba-4c46-b19f-d008e1058f64 | < 10.8.2 |
HIGH | 8.8 | The AcyMailing plugin for WordPress is vulnerable to privilege escalation in all versions From 9.11.0 up to, and includi… | — | wordfence |
| a88e8853-3a52-462b-bde8-658a794545dc | < 1.4.0 |
HIGH | 8.8 | The Comment License WordPress plugin before 1.4.0 does not have CSRF check in place when updating its settings, which co… | — | wordfence |
| a8742e30-e49c-46c9-92d5-216d32d00d51 | HIGH | 8.8 | The YDS Support Ticket System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… | — | wordfence | |
| a86d196f-9613-4352-8a96-87ea147eb1c8 | HIGH | 8.8 | The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform an… | — | wordfence | |
| a868226f-4ca1-4ec1-b55e-3029e3ed2d5b | < 2.3.4 |
HIGH | 8.8 | The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →