Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 148 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a20b4870-2ef0-4932-a0e3-39876ce4b10c | HIGH | 8.8 | The Blogzee theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versi… | — | wordfence | |
| a1d4df4b-ec7a-43f6-8617-161b1600d6d2 | < 1.4.3 |
HIGH | 8.8 | The Houzez CRM plugin for WordPress is vulnerable to time-based SQL Injection via the notes ‘belong_to’ parameter in… | — | wordfence |
| a1c4c632-66f2-4987-b7da-048dbe4a3044 | HIGH | 8.8 | The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the … | — | wordfence | |
| a1ae2060-5eca-47c9-a196-0ff75c3f523e | < 6.1.5.0 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the Shareaholic SexyBookmarks plugin 6.1.4.0 for WordPress allows rem… | — | wordfence |
| a18fa7e6-813d-4b48-bd4e-5232fb8382d1 | < 16.7 |
HIGH | 8.8 | The WordPress User Extra Fields plugin for WordPress is vulnerable to privilege escalation due to a missing capability c… | — | wordfence |
| a18089d8-32f1-4827-af14-c45055892fb2 | HIGH | 8.8 | The jQuery Reply to Comment WordPress plugin through 1.31 does not have any CSRF check when saving its settings, nor san… | — | wordfence | |
| a1264108-6b96-4e17-bac8-4957a615f0b9 | < 2.4.19.1 |
HIGH | 8.8 | The WP Multilang plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.19. Th… | — | wordfence |
| a11f264a-24fe-44da-b325-3fbdc4cd81d0 | < 2.8.1 |
HIGH | 8.8 | The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authentic… | — | wordfence |
| a114faf9-cada-4132-abe3-c0137b66e276 | < 7.19.1 |
HIGH | 8.8 | The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file uploads due to mis… | — | wordfence |
| a0b1e907-0c31-4b40-b3f9-0ac665f3394a | HIGH | 8.8 | The Smartkit plugin for WordPress is vulnerable to Cross-Site Request Forgery via the show_smartkit_menu() function in v… | — | wordfence | |
| a09298b3-3b5c-4a92-9332-79ff83234479 | < 3.2.0 |
HIGH | 8.8 | The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.9 via s… | — | wordfence |
| a07a643e-1a4b-47fe-9e4a-b4cc070bce74 | < 1.1.5 |
HIGH | 8.8 | The fossura-tag-miner plugin before 1.1.5 for WordPress has CSRF. | — | wordfence |
| a058e6bf-109f-4985-8aad-08858553c4c3 | HIGH | 8.8 | The WordPress Review Plugin: The Ultimate Solution for Building a Review Website plugin for WordPress is vulnerable to L… | — | wordfence | |
| a041f15c-0e30-459b-8df7-0465c0bc268a | < 6.9.1 |
HIGH | 8.8 | The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation … | — | wordfence |
| a0164123-11b0-4b3b-bc76-c6aee8ca9d34 | < 2.0.4 |
HIGH | 8.8 | The Nexter theme for WordPress is vulnerable to SQL Injection via the 'to' and 'from' parameters in versions up to, and… | — | wordfence |
| 9fe78766-0beb-4d6d-a2e6-92f79f117f50 | HIGH | 8.8 | The Pont theme for WordPress is vulnerable to arbitrary option updates due to a missing capability check on the of_ajax_… | — | wordfence | |
| 9fc4b26a-cb76-4b2c-adad-62e21263b957 | < 6.5.1 |
HIGH | 8.8 | The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to PHP Object Injection in all v… | — | wordfence |
| 9fa3f24e-3e28-4e50-8801-e4f0a089e3a1 | < 2.6.01 |
HIGH | 8.8 | The alo-easymail plugin before 2.6.01 for WordPress has CSRF with resultant XSS in pages/alo-easymail-admin-options.php. | — | wordfence |
| 9f9e5212-caed-46db-bbf2-81c4df88439f | < 3.2.7.3 |
HIGH | 8.8 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and inclu… | — | wordfence |
| 9f8575cb-0620-4db8-a5e9-0a7f115ee8fe | HIGH | 8.8 | The Question Answer plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.70 … | — | wordfence | |
| 9f33096a-dfd5-48c1-84d8-30a0faa2a7f5 | HIGH | 8.8 | The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.6.1. This is… | — | wordfence | |
| 9f07d76e-1973-4ea7-b448-666466cd688f | < 4.5.5 |
HIGH | 8.8 | The WP Meta SEO plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.5.4 due t… | — | wordfence |
| 9ecaaa86-9de1-4b90-b6cf-885621cffb19 | < 8.7 |
HIGH | 8.8 | The Ultimate Membership Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
| 9ec1aed2-d299-4fa9-add6-10b63ed6aa30 | < 3.1 |
HIGH | 8.8 | The Meta Tag Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.… | — | wordfence |
| 9ec17c72-6426-4e7e-840d-f8c050a25460 | < 6.5.0 |
HIGH | 8.8 | The Photo Engine (Media Organizer & Lightroom) plugin for WordPress is vulnerable to arbitrary file uploads due to missi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →