Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,758 vulnerabilities found (page 16 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| eb075839-5669-4a5a-b225-f7ea98672490 | < 1.0.49 |
CRITICAL | 9.8 | The Newspapers X theme for WordPress contains a backdoor in versions 1.0.46 to 1.0.48. This makes it possible for unauth… | — | wordfence |
| eada519e-a647-4425-9e41-b8527b592c8a | CRITICAL | 9.8 | The custom-searchable-data-entry-system (aka Custom Searchable Data Entry System) plugin through 1.7.1 for WordPress all… | — | wordfence | |
| ea9ee672-76d3-4d6a-b309-cd0023ca6c0d | CRITICAL | 9.8 | The Daily Deal theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the /… | — | wordfence | |
| ea9e5e5d-a7fc-4159-a2ae-610bee76f818 | CRITICAL | 9.8 | The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inclu… | — | wordfence | |
| ea5f9fba-6b25-40c8-b237-361eb6365693 | CRITICAL | 9.8 | The JiangQie Free Mini Program plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… | — | wordfence | |
| ea4c0ad7-c7c0-49fd-85e4-612423e3ddb5 | CRITICAL | 9.8 | The Grand Conference plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.2 vi… | — | wordfence | |
| ea40d06e-672c-42db-9378-d382de5838d4 | < 2.4 |
CRITICAL | 9.8 | The File Manager Advanced Shortcode WordPress plugin for WordPress is vulnerable to remote code execution in versions up… | — | wordfence |
| ea3ba0f5-6bc2-455c-b4e3-891ed6b2518c | < 1.4.3 |
CRITICAL | 9.8 | Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-cont… | — | wordfence |
| ea07c3c1-95e6-4139-b4f5-67ca642f0563 | CRITICAL | 9.8 | The Developer Tools plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.… | — | wordfence | |
| ea00bcc9-6f9c-4704-8337-074d5356e9e2 | < 4.1.5 |
CRITICAL | 9.8 | The WP Activity Log plugin for WordPress is vulnerable to SQL Injection via multiple parameters in versions up to, and i… | — | wordfence |
| e9fac523-ceac-4ba2-9fcd-695afcd74308 | CRITICAL | 9.8 | The Modal Survey plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.2.0.1.… | — | wordfence | |
| e9ec79e5-9f02-4a73-9437-58821ca855ef | < 2.3.2 |
CRITICAL | 9.8 | Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to b… | — | wordfence |
| e9c81117-a9da-41bb-afc6-94196167af04 | < 2.2.7 |
CRITICAL | 9.8 | The Social Share Buttons by Supsystic plugin for WordPress is vulnerable to SQL Injection via the ‘value’ parameter … | — | wordfence |
| e9c7fb16-efbb-41e9-be13-98e96c1e9100 | < 6.3.314 |
CRITICAL | 9.8 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions… | — | wordfence |
| e988d042-147c-4782-b728-71f5a50cecd8 | < 5.7.2 |
CRITICAL | 9.8 | The Essential Addons for Elementor plugin for WordPress is vulnerable to Unauthenticated Arbitrary Password Resets to Pr… | — | wordfence |
| e95b2bfe-8675-4932-9b37-73ad15fa228e | < 2.5.1.2 |
CRITICAL | 9.8 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ p… | — | wordfence |
| e94f9cde-5e8b-4d68-8ede-12d678a370ed | < 3.12.3 |
CRITICAL | 9.8 | The Amazon Affiliate plugin for WordPress is vulnerable to Reflected File Download via image proxy in versions up to, an… | — | wordfence |
| e93c8b3a-d8d8-4d2b-9df0-ea27e33947e0 | < 4.0.2 |
CRITICAL | 9.8 | The Login & Register Customizer – Forms, Popup, Profile & WooCommerce plugin for WordPress is vulnerable to privilege … | — | wordfence |
| e920caeb-5ee6-4428-9b53-edee316ee39f | CRITICAL | 9.8 | SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote atta… | — | wordfence | |
| e901c2a0-2477-4b9a-8483-6002419e0a2f | < 1.26.5 |
CRITICAL | 9.8 | The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all version… | — | wordfence |
| e8c01984-e8ba-4671-b63c-46ea245e7efa | < 3.5.6 |
CRITICAL | 9.8 | The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by def… | — | wordfence |
| e87d7ca0-6fa3-4ca3-b308-d47e1e2e6566 | CRITICAL | 9.8 | The Eptonic theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the VALUM… | — | wordfence | |
| e8574ff9-847c-4337-8c0e-2a717b51f66c | < 3.1.4 |
CRITICAL | 9.8 | The Adifier System theme for WordPress is vulnerable to Local File Inclusion in all versions up to 3.1.4 (exclusive). Th… | — | wordfence |
| e8469ffc-477a-4ff1-853b-dcefba2b9c4e | < 1.2.3 |
CRITICAL | 9.8 | The Rockhoist Ratings plugin for WordPress is vulnerable to generic SQL Injection via several parameters in versions up … | — | wordfence |
| e83ad1b7-e7d6-41cd-87de-c98362e31879 | CRITICAL | 9.8 | The shopp_upload_file AJAX action of the Shopp WordPress plugin through 1.4, available to both unauthenticated and authe… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →