Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,758 vulnerabilities found (page 15 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ed738dc5-7848-4b04-a3fd-317cc366acfa | < 5.7 |
CRITICAL | 9.8 | The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… | — | wordfence |
| ed4854f3-b991-4133-acb9-12d99c399c90 | < 1.7.2 |
CRITICAL | 9.8 | The Wanderland theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.1. This m… | — | wordfence |
| ed3ad791-4d4d-41df-bf14-2aef77d6fecb | < 1.8 |
CRITICAL | 9.8 | The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection. | — | wordfence |
| ed19835f-2718-41d8-95af-47c8b9589529 | < 8.5.0 |
CRITICAL | 9.8 | The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all version… | — | wordfence |
| ed038d39-9389-49d3-bfdd-b97fadb8e29b | CRITICAL | 9.8 | The Exam Matrix plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5. Th… | — | wordfence | |
| ecfdf7b1-9bb8-4c1d-a00a-ca1e44440cab | < 1.3.6.1 |
CRITICAL | 9.8 | The HUSKY β Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injectio… | — | wordfence |
| ecec3eb4-04db-47af-974f-bacc530a7c70 | CRITICAL | 9.8 | The Adding drop down roles in registration plugin for WordPress is vulnerable to privilege escalation in all versions up… | — | wordfence | |
| ecd35d5a-5270-4132-bc62-d75da5141313 | < 1.4.3 |
CRITICAL | 9.8 | The Floating Social Media Links plugin for WordPress is vulnerable to Remote File Inclusion in versions before 1.4.3 via… | — | wordfence |
| ec9cd4a8-286e-43d7-8cb6-6cc363800e20 | < 1.4.4 |
CRITICAL | 9.8 | The MailerLite Signup Forms plugin for WordPress is vulnerable to SQL Injection via the 'form_id' parameter in versions … | — | wordfence |
| ec866ff1-cce1-4f39-b22f-2d4780cb85f0 | CRITICAL | 9.8 | The One-Login plugin for WordPress is vulnerable to Privilege Escalation n all versions up to, and including, 1.4. This … | — | wordfence | |
| ec8666d4-042e-4cf4-86f5-474a69d90ff6 | < 2.3.23 |
CRITICAL | 9.8 | The Post Grid and Gutenberg Blocks β ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection … | — | wordfence |
| ec7f3e0c-a07c-4082-9b6b-12d0fbe0fdc8 | < 1.5.3 |
CRITICAL | 9.8 | The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.… | — | wordfence |
| ec547a1f-d57b-4792-b9d0-38e9a9c4d0a2 | < 3.7.1.6 |
CRITICAL | 9.8 | The Registration Forms β User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPr… | — | wordfence |
| ec4c14ec-d085-42c8-9e98-4155f7fa8c10 | CRITICAL | 9.8 | The moveto plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.2. This mak… | — | wordfence | |
| ec3dd825-bee3-4d09-bc98-aff665988641 | < 3.5.2 |
CRITICAL | 9.8 | The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from t… | — | wordfence |
| ec2eec5a-7767-4215-b77d-5cfd2d148f73 | < 2.3.9 |
CRITICAL | 9.8 | The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQ… | — | wordfence |
| ec1ce091-7aac-4ec6-8f6f-6d961e2073cb | < 2.4 |
CRITICAL | 9.8 | The wpShopGermany IT-RECHT KANZLEI plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, an… | — | wordfence |
| ec0d80f7-96fb-466d-9701-9751f71b926d | < 1.0.6 |
CRITICAL | 9.8 | The News Element Elementor Blog Magazine plugin for WordPress is vulnerable to Local File Inclusion in all versions up t… | — | wordfence |
| ebb80964-761b-410c-998f-4408439e0d48 | < 1.2.2 |
CRITICAL | 9.8 | The Patreon WordPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.2… | — | wordfence |
| ebb0e616-9a57-4a77-a9ac-a938eb9b26b8 | CRITICAL | 9.8 | The Jarvis β Night Club, Concert, Festival WordPress theme for WordPress is vulnerable to PHP Object Injection in vers… | — | wordfence | |
| ebacd411-6def-4026-a619-5e08a181507b | < 3.8.1 |
CRITICAL | 9.8 | The Custom 404 Pro plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in versions up to, and incl… | — | wordfence |
| eb629dfc-1be2-4a56-907f-0b5c64cc066e | < 0.20 |
CRITICAL | 9.8 | PHP remote file inclusion vulnerability in relocate-upload.php in Relocate Upload plugin before 0.20 for WordPress allow… | — | wordfence |
| eb58dd93-3789-46c6-bfca-7866427e077d | < 3.5.3 |
CRITICAL | 9.8 | The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and includi… | — | wordfence |
| eb271cc8-01ec-45eb-9d6f-efc55c7c3923 | < 2.5.3 |
CRITICAL | 9.8 | The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali… | — | wordfence |
| eb1dca2f-5196-4f68-9c22-e8f4b3c99742 | CRITICAL | 9.8 | The Ace User Management plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →