Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 15 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ec7f3e0c-a07c-4082-9b6b-12d0fbe0fdc8 | < 1.5.3 |
CRITICAL | 9.8 | The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.… | — | wordfence |
| ec547a1f-d57b-4792-b9d0-38e9a9c4d0a2 | < 3.7.1.6 |
CRITICAL | 9.8 | The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPr… | — | wordfence |
| ec4c14ec-d085-42c8-9e98-4155f7fa8c10 | CRITICAL | 9.8 | The moveto plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.2. This mak… | — | wordfence | |
| ec3dd825-bee3-4d09-bc98-aff665988641 | < 3.5.2 |
CRITICAL | 9.8 | The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from t… | — | wordfence |
| ec2eec5a-7767-4215-b77d-5cfd2d148f73 | < 2.3.9 |
CRITICAL | 9.8 | The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQ… | — | wordfence |
| ec0d80f7-96fb-466d-9701-9751f71b926d | < 1.0.6 |
CRITICAL | 9.8 | The News Element Elementor Blog Magazine plugin for WordPress is vulnerable to Local File Inclusion in all versions up t… | — | wordfence |
| ebb80964-761b-410c-998f-4408439e0d48 | < 1.2.2 |
CRITICAL | 9.8 | The Patreon WordPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.2… | — | wordfence |
| ebb0e616-9a57-4a77-a9ac-a938eb9b26b8 | CRITICAL | 9.8 | The Jarvis – Night Club, Concert, Festival WordPress theme for WordPress is vulnerable to PHP Object Injection in vers… | — | wordfence | |
| ebacd411-6def-4026-a619-5e08a181507b | < 3.8.1 |
CRITICAL | 9.8 | The Custom 404 Pro plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in versions up to, and incl… | — | wordfence |
| eb629dfc-1be2-4a56-907f-0b5c64cc066e | < 0.20 |
CRITICAL | 9.8 | PHP remote file inclusion vulnerability in relocate-upload.php in Relocate Upload plugin before 0.20 for WordPress allow… | — | wordfence |
| eb58dd93-3789-46c6-bfca-7866427e077d | < 3.5.3 |
CRITICAL | 9.8 | The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and includi… | — | wordfence |
| eb271cc8-01ec-45eb-9d6f-efc55c7c3923 | < 2.5.3 |
CRITICAL | 9.8 | The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali… | — | wordfence |
| eb1dca2f-5196-4f68-9c22-e8f4b3c99742 | CRITICAL | 9.8 | The Ace User Management plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions … | — | wordfence | |
| eada519e-a647-4425-9e41-b8527b592c8a | CRITICAL | 9.8 | The custom-searchable-data-entry-system (aka Custom Searchable Data Entry System) plugin through 1.7.1 for WordPress all… | — | wordfence | |
| ea9ee672-76d3-4d6a-b309-cd0023ca6c0d | CRITICAL | 9.8 | The Daily Deal theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the /… | — | wordfence | |
| ea9e5e5d-a7fc-4159-a2ae-610bee76f818 | CRITICAL | 9.8 | The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inclu… | — | wordfence | |
| ea5f9fba-6b25-40c8-b237-361eb6365693 | CRITICAL | 9.8 | The JiangQie Free Mini Program plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… | — | wordfence | |
| ea4c0ad7-c7c0-49fd-85e4-612423e3ddb5 | CRITICAL | 9.8 | The Grand Conference plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.2 vi… | — | wordfence | |
| ea40d06e-672c-42db-9378-d382de5838d4 | < 2.4 |
CRITICAL | 9.8 | The File Manager Advanced Shortcode WordPress plugin for WordPress is vulnerable to remote code execution in versions up… | — | wordfence |
| ea3ba0f5-6bc2-455c-b4e3-891ed6b2518c | < 1.4.3 |
CRITICAL | 9.8 | Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-cont… | — | wordfence |
| ea00bcc9-6f9c-4704-8337-074d5356e9e2 | < 4.1.5 |
CRITICAL | 9.8 | The WP Activity Log plugin for WordPress is vulnerable to SQL Injection via multiple parameters in versions up to, and i… | — | wordfence |
| e9fac523-ceac-4ba2-9fcd-695afcd74308 | CRITICAL | 9.8 | The Modal Survey plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.2.0.1.… | — | wordfence | |
| e9ec79e5-9f02-4a73-9437-58821ca855ef | < 2.3.2 |
CRITICAL | 9.8 | Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to b… | — | wordfence |
| e9c81117-a9da-41bb-afc6-94196167af04 | < 2.2.7 |
CRITICAL | 9.8 | The Social Share Buttons by Supsystic plugin for WordPress is vulnerable to SQL Injection via the ‘value’ parameter … | — | wordfence |
| e9c7fb16-efbb-41e9-be13-98e96c1e9100 | < 6.3.314 |
CRITICAL | 9.8 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →