Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 160 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 82df7569-919a-4f95-b0e2-f866133771eb | < 1.5 |
HIGH | 8.8 | The User Domain Whitelist plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence |
| 82ce66d0-dc53-4433-b499-30bfd48efaf2 | < 4.0.10 |
HIGH | 8.8 | The Divi Builder, Divi, and Divi Extra plugin and themes for WordPress are vulnerable to PHP Code Injection in versions … | — | wordfence |
| 82c9e3be-a6b8-4d3a-8e1a-cc2e29bb95b6 | HIGH | 8.8 | The Gallerio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all ver… | — | wordfence | |
| 82b87634-f740-4e4e-bc7e-f8bf7e657486 | < 3.5.4 |
HIGH | 8.8 | The Emails Catch All plugin for WordPress is vulnerable to privilege escalation via email log exposure in all versions u… | — | wordfence |
| 82960f7a-db21-4e47-a375-473e0b843250 | HIGH | 8.8 | The Hospital Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing… | — | wordfence | |
| 8281cb20-73d3-4ab5-910e-d353b2a5cbd8 | HIGH | 8.8 | The WP Popup Banners plugin for WordPress is vulnerable to SQL Injection via the 'banner_id' parameter in versions up to… | — | wordfence | |
| 826b3913-9a37-4e15-80fd-b35cefb51af8 | HIGH | 8.8 | The GMAce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This… | — | wordfence | |
| 82699a17-ea45-4493-98c4-07f62ca0b1f9 | HIGH | 8.8 | The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and i… | — | wordfence | |
| 82246b72-3c29-4574-af86-d0435eecce5d | HIGH | 8.8 | SQL injection vulnerability in the Quartz plugin 1.01.1 for WordPress allows remote authenticated users with Contributor… | — | wordfence | |
| 82137302-60ca-44d5-b087-dc96e2815fca | < 5.7.5 |
HIGH | 8.8 | The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in vers… | — | wordfence |
| 8202e9e7-b05b-4603-9ebd-8084bf17a230 | < 2.54.6 |
HIGH | 8.8 | The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks… | — | wordfence |
| 81f025da-c28c-4a80-8b4f-27dae07b2b04 | < 3.1.2 |
HIGH | 8.8 | The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing f… | — | wordfence |
| 81c80424-3ecb-4740-b458-00a983f35298 | HIGH | 8.8 | The examapp plugin 1.0 for WordPress has SQL injection via the wp-admin/admin.php?page=examapp_UserResult id parameter. | — | wordfence | |
| 81a7afc0-05be-4966-b762-081ef553d4e8 | < 1.8.7 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the Contextual Related Posts plugin before 1.8.7 for WordPress allows… | — | wordfence |
| 81939cc9-b8f7-4c40-b963-4f6f8c7043e7 | < 2.6.26 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in Smart Forms 2.6.15 and earlier allows remote attackers to hijack the … | — | wordfence |
| 8187c6eb-d962-48a7-bbe8-5949cfdefbce | < 0.4.7 |
HIGH | 8.8 | The reSmush.it Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… | — | wordfence |
| 8185c7a4-3d8e-4a24-9746-536337afbcfe | HIGH | 8.8 | The classyfrieds WordPress plugin through 3.8 does not properly check the uploaded file when an authenticated user adds … | — | wordfence | |
| 817ca119-ddaf-4525-beee-68c4e0aac544 | < 3.1.24 |
HIGH | 8.8 | The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in ver… | — | wordfence |
| 815e5b86-2d1b-4794-b761-dad770393d3e | < 4.8.7 |
HIGH | 8.8 | The WP Maps β Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulne… | — | wordfence |
| 81330ff8-25a5-403d-abaf-e7c54467abbc | < 5.6.9 |
HIGH | 8.8 | The Image Map Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and excluding, 5.6… | — | wordfence |
| 8129046a-5aa5-4644-babc-0eca9aa524d2 | < 1.9.4 |
HIGH | 8.8 | The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including… | — | wordfence |
| 8108fe83-86fd-4c57-b963-6dad9f50f3f7 | HIGH | 8.8 | The nBlocks plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.2. This mak… | — | wordfence | |
| 8107ed0c-c4eb-4704-9261-4e320e10cdb5 | < 1.2.5 |
HIGH | 8.8 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Featured Comments plugin 1.2.5 for WordPress allow rem… | — | wordfence |
| 80f39182-9835-4bd5-b3cd-41fe20983e1e | HIGH | 8.8 | The Filter Custom Fields & Taxonomies Light plugin for WordPress is vulnerable to PHP Object Injection in all versions u… | — | wordfence | |
| 80c9f2e3-afdc-4ba2-a1ef-4c1d166d0757 | < 2.8.3 |
HIGH | 8.8 | The RestroPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.2… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →