Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 159 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 851ff861-474e-4063-88ff-d8d35b10e9a0 | < 1.1.6 |
HIGH | 8.8 | The BookingPress β Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable… | — | wordfence |
| 84ffb581-cd59-41df-a6c5-8b2a5923e900 | HIGH | 8.8 | The Miion | Multi-Purpose WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to missing fil… | — | wordfence | |
| 84f2afb4-f1c6-4313-8958-38f1b5140a67 | < 8.4.2 |
HIGH | 8.8 | The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. Thi… | — | wordfence |
| 84b609a5-d3d6-4a30-b55e-7f7972c64ccb | < 4.1.6 |
HIGH | 8.8 | The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… | — | wordfence |
| 8494a0f6-7079-4fba-9901-76932b002c5a | < 6.1.8 |
HIGH | 8.8 | The Awesome Support β WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Inject… | — | wordfence |
| 84936b68-923a-4da1-ae67-1d63d025342e | < 1.7 |
HIGH | 8.8 | The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitr… | — | wordfence |
| 84888ea6-122d-4480-8262-d87c33113bd7 | < 4.6.1 |
HIGH | 8.8 | The EELV Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4… | — | wordfence |
| 8475dd90-b47a-42b4-8e4e-44e8512e4fca | < 4.0.0 |
HIGH | 8.8 | The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Exe… | — | wordfence |
| 8459c436-0c4d-40e6-a30d-94b8ac50df83 | HIGH | 8.8 | The WooCommerce Custom Registration Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… | — | wordfence | |
| 8429148b-e28e-4bb3-bd18-390216b74dc4 | < 1.3 |
HIGH | 8.8 | The Request for Quote plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.3. This is d… | — | wordfence |
| 84227fd2-c322-45e3-82cd-70e1d870eceb | < 0.9.4.1 |
HIGH | 8.8 | The W3 Total Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.… | — | wordfence |
| 840e9a50-ce53-4b9a-b6ae-c5016e11373b | < 2.4.5 |
HIGH | 8.8 | The WP Maintenance Mode & Coming Soon plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… | — | wordfence |
| 83f6c9fb-4ee7-42c0-9369-a0d577dd485f | HIGH | 8.8 | The 3D Work In Progress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path vali… | — | wordfence | |
| 83f6bdda-e489-4e85-b510-7bfaa2329609 | < 1.6.6 |
HIGH | 8.8 | The Page Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… | — | wordfence |
| 83e53dc4-84fe-4835-aaea-b72dfe8f7475 | < 1.2.5.6 |
HIGH | 8.8 | Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability tha… | — | wordfence |
| 83d69f7b-0f98-43d3-baef-51216e26d357 | < 6.3.6 |
HIGH | 8.8 | The WP Travel Engine plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.3.5.… | — | wordfence |
| 83d4f114-c113-4c66-be74-2d438aa00502 | < 1.5.0 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the Add/Edit page (adminmenus.php) in the WP125 plugin before 1.5.0 f… | — | wordfence |
| 83c0e096-f054-4367-a85f-582c0771e3fe | < 1.0.5.3 |
HIGH | 8.8 | The Becustom plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5.2.… | — | wordfence |
| 83a595b7-379c-4202-abdd-d8ba4a30c6a4 | HIGH | 8.8 | The Play.ht β Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to PHP Obje… | — | wordfence | |
| 83a58119-d0ed-47fe-93d1-1aa1def2cf44 | < 4.0.2 |
HIGH | 8.8 | The Streamit theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'st_… | — | wordfence |
| 839a0cc0-a656-4107-a748-4ad85e950237 | < 1.8.2 |
HIGH | 8.8 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check … | — | wordfence |
| 839957ea-5186-4cce-971d-57eed84639d5 | < 3.8.5 |
HIGH | 8.8 | The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section. | — | wordfence |
| 8376556e-ed78-4a0e-a23f-9b2a39db94d9 | HIGH | 8.8 | The Photo Video Gallery Master plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc… | — | wordfence | |
| 835579b0-8a96-40fa-a6a3-30571a0a1d0a | < 1.13.0 |
HIGH | 8.8 | The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu… | — | wordfence |
| 832af296-7d7c-47a0-84a4-01a1fe78ff21 | < 7.8.8 |
HIGH | 8.8 | The Cornerstone plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 7.8.8 (exclusive). Thi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →