Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 157 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 89a7a717-dac3-490e-89dd-268be8eb7bf5 | < 1.3.0 |
HIGH | 8.8 | The BuddyPress Xprofile Custom Field Types plugin for WordPress is vulnerable to arbitrary file deletion due to insuffic… | — | wordfence |
| 89a44d42-a110-4f55-ad27-2be4ccb41a16 | < 2.9.55.2 |
HIGH | 8.8 | The Ninja Forms Contact Form plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.5… | — | wordfence |
| 895f2db1-a2ed-4a17-a4f6-cd13ee8f84af | < 1.4.5 |
HIGH | 8.8 | The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includin… | — | wordfence |
| 89218de3-7bb9-42f5-86d8-48d28c380231 | < 2.0.32 |
HIGH | 8.8 | The bBlocks – Essential Gutenberg Blocks & Patterns Collection plugin for WordPress is vulnerable to privilege escalat… | — | wordfence |
| 89183a72-5b35-4c11-81d7-0a735ebce884 | < 4.5.5 |
HIGH | 8.8 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to arbitrary file upl… | — | wordfence |
| 88dc08ff-3966-4606-855c-57c25552599e | < 2.2.0 |
HIGH | 8.8 | The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in al… | — | wordfence |
| 88d9f0b1-040d-4f95-95dd-021ceb0cdb39 | < 1.4.4 |
HIGH | 8.8 | The Login As Users plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the g… | — | wordfence |
| 88d0d6b7-f33f-4c7b-9006-d54578fbe003 | < 5.6.9 |
HIGH | 8.8 | The Image Map Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and excluding, 5.6… | — | wordfence |
| 88c496df-a5c0-4ac9-8fc1-37fcddfa13d3 | HIGH | 8.8 | The Exclusive Content Password Protect plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… | — | wordfence | |
| 88508dbd-b7a0-441d-918b-f4cb7a7cd000 | < 1.33.25 |
HIGH | 8.8 | The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to modification of data due to a missin… | — | wordfence |
| 8827f882-3c3b-4362-ac90-a1b61364f5c7 | < 1.1.4 |
HIGH | 8.8 | The Dynamic Product Category Grid, Slider for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in … | — | wordfence |
| 87eaa518-44fb-48ae-b700-ac65141905b3 | < 1.63 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the options admin page in the WP-PostViews plugin before 1.63 for Wor… | — | wordfence |
| 87e3dd5e-0d77-4d78-8171-0beaf9482699 | < 6.3 |
HIGH | 8.8 | The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… | — | wordfence |
| 87b7bc4a-4d2f-4bcb-a9d5-72e31c95c09e | < 4.9 |
HIGH | 8.8 | The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8… | — | wordfence |
| 87b26fcf-d0b3-4ab3-92d8-8f1ba72af0a3 | < 9.1.1 |
HIGH | 8.8 | The BuddyPress plugin for WordPress is vulnerable to information disclosure via REST API in versions up to, and includin… | — | wordfence |
| 879c0a85-ed94-430c-8e8e-6389294b432b | < 2.9.2 |
HIGH | 8.8 | The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF. | — | wordfence |
| 878f27d3-bb57-46b4-aee4-03720d695504 | HIGH | 8.8 | Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 fails to sanitize input from the 'Manufacturer[]' paramet… | — | wordfence | |
| 8773fa6e-6e81-4565-a9be-36ad0ea6ac88 | < 1.8.0.0 |
HIGH | 8.8 | The Corona Virus (COVID-19) Banner & Live Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in versi… | — | wordfence |
| 8731565f-4d8a-49e6-9c38-6d4f5e51d68c | < 5.39 |
HIGH | 8.8 | The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for Wor… | — | wordfence |
| 871e5091-bb20-4a53-83e2-85ed6f26247a | < 6.4.2.1 |
HIGH | 8.8 | The Advanced Page Visit Counter plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.… | — | wordfence |
| 8714f5cc-56c7-4976-b021-956883a2bc73 | < 1.2.2 |
HIGH | 8.8 | The BP Group Documents plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence |
| 8706c3f6-64e0-440e-a802-5c80d9cc3643 | < 4.8.3 |
HIGH | 8.8 | The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.8… | — | wordfence |
| 86ff2412-23c6-450e-b351-ba994d68aae6 | < 7.4.2.2 |
HIGH | 8.8 | The Directorist plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including… | — | wordfence |
| 86ebb886-ad30-44e0-bed1-32d2ffefd50b | < 2.0.9 |
HIGH | 8.8 | The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to Remote Cod… | — | wordfence |
| 86dab8e6-b9fd-45ca-bdd1-8665f3bb75f2 | < 1.2.1 |
HIGH | 8.8 | The Smart Auto Upload Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →