Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 158 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 86d2aa56-c543-4cb6-aa9f-715879c18f83 | < 3.2 |
HIGH | 8.8 | The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized modification of data that can le… | — | wordfence |
| 86cdbfec-b1af-48ec-ae70-f97768694e44 | HIGH | 8.8 | The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, a… | — | wordfence | |
| 86b4b0d6-bda2-47f3-a0b5-9733cb7a11f6 | < 6.4.0 |
HIGH | 8.8 | The Uncanny Automator β Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable t… | — | wordfence |
| 86b2123f-9616-4dcc-904f-c7be802a8f8c | < 3.1.3 |
HIGH | 8.8 | wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors relat… | — | wordfence |
| 8699142d-4ddd-4ca1-9886-9b2d905a36cd | < 5.6.0 |
HIGH | 8.8 | The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up… | — | wordfence |
| 86908097-a5b2-427a-85c9-fbe29b519883 | < 1.6.5 |
HIGH | 8.8 | The Short URL plugin for WordPress is vulnerable to SQL Injection via the 'idLink' parameter of the reset_link() functio… | — | wordfence |
| 86566819-ec2e-4d56-87f6-4cd4b6de6192 | < 2.0 |
HIGH | 8.8 | The Quasar Theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the rock_build… | — | wordfence |
| 8641aa6d-e865-46cd-91f5-faec81a7bb55 | HIGH | 8.8 | The Youtube Feeder WordPress plugin is vulnerable to Cross-Site Request Forgery via the printAdminPage function found in… | — | wordfence | |
| 861da9ac-fd73-4bb5-bc39-baf9efe71899 | < 3.1.3 |
HIGH | 8.8 | The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous… | — | wordfence |
| 85e68071-47e3-45a0-8c38-801f125331ba | HIGH | 8.8 | The Rating by BestWebSoft plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1… | — | wordfence | |
| 85d8bfaa-db94-4c15-8f55-eeefe5882f90 | HIGH | 8.8 | The Backup Scheduler plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence | |
| 85cea6b5-d57b-495e-a504-a0c1ba691637 | < 0.2.5.2 |
HIGH | 8.8 | The NewsBlogger theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the new… | — | wordfence |
| 85bd9922-3316-4fd0-b31e-c3ca5ab8a79d | < 1.8.2 |
HIGH | 8.8 | The Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass due to insufficient v… | — | wordfence |
| 859fe629-701e-4d47-8e90-59860f7c6b82 | < 0.9.5 |
HIGH | 8.8 | The WP Fastest Cache plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions before 0.9.5… | — | wordfence |
| 8593b14e-672d-43b8-b516-d068cbd735b7 | HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPr… | — | wordfence | |
| 85790564-811c-4087-ad36-345e443ae9f8 | HIGH | 8.8 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Private Only plugin 3.5.1 for WordPress allow remote a… | — | wordfence | |
| 85730e9b-c5da-473c-a324-891c5c9f7ba3 | < 3.4.12 |
HIGH | 8.8 | The WCFM Marketplace plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up t… | — | wordfence |
| 856e3e77-d330-4fa0-9f07-f77a56dbb5bd | < 5.3.9 |
HIGH | 8.8 | The XStore Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.3.8. … | — | wordfence |
| 8564fc82-ff23-44b6-91b0-d63e6afb1a73 | < 1.1.3 |
HIGH | 8.8 | The Icons Font Loader plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to… | — | wordfence |
| 8558cd96-3b2a-4282-950b-6d9753698291 | < 1.4.5 |
HIGH | 8.8 | The Job Manager & Career β Manage job board listings, and recruitments plugin for WordPress is vulnerable to Cross-Sit… | — | wordfence |
| 8555b662-f1c8-418a-896e-1558e6e34c14 | < 2.3.10 |
HIGH | 8.8 | The WP Google Map plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature. | — | wordfence |
| 8551ae2f-4be4-4dc6-952d-1d25ae127150 | < 2.0.4 |
HIGH | 8.8 | The Jeeng Push Notifications plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… | — | wordfence |
| 853516b2-ec50-4937-89d3-d16042a6f71c | < 2.3.3 |
HIGH | 8.8 | The Vimeography: Vimeo Video Gallery WordPress Plugin plugin for WordPress is vulnerable to PHP Object Injection in all … | — | wordfence |
| 8530affb-0b6e-4b71-acab-3561cccc1855 | < 3.2.2 |
HIGH | 8.8 | The Advanced Access Manager plugin for WordPress does not use capability checks on any of its registered AJAX actions. T… | — | wordfence |
| 852959d1-f8e0-4c1f-8a5c-5923bedc4889 | HIGH | 8.8 | The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and i… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →