Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 161 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 80a258a6-634c-4d7d-981f-bcbc0bb044f7 | < 1.0.1 |
HIGH | 8.8 | The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to a… | — | wordfence |
| 80997d2f-3e16-48f6-969b-58844cb83d53 | < 3.8122 |
HIGH | 8.8 | The CRM WordPress Plugin β RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover… | — | wordfence |
| 808e5246-30b1-4706-b11f-27fb74b117ed | < 1.8.2 |
HIGH | 8.8 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site… | — | wordfence |
| 805f18e2-9a5a-48cf-81f4-825da4bfd8ef | < 1.2.4 |
HIGH | 8.8 | The User Toolkit plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.3. Th… | — | wordfence |
| 80510ade-cb58-45b3-89f2-2cbbc5640cae | < 1.5.5 |
HIGH | 8.8 | The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capabilit… | — | wordfence |
| 803e9059-7606-42eb-9193-1a18d57153b1 | < 1.1.7 |
HIGH | 8.8 | The Booking Ultra Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence |
| 801b593c-2822-4ac4-8411-29ef1e1484b1 | < 1.5.5 |
HIGH | 8.8 | The Quick Restaurant Reservations plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… | — | wordfence |
| 800fa098-b29f-4979-b7bd-b1186a4dafcb | < 2.1.8 |
HIGH | 8.8 | The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deseria… | — | wordfence |
| 7ff39b8f-ef87-4b1c-888e-00c9599c7b07 | < 2.7.3 |
HIGH | 8.8 | The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all vers… | — | wordfence |
| 7fad30c8-fd8a-4cf2-a3aa-16a374231b87 | < 7.8 |
HIGH | 8.8 | The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu… | — | wordfence |
| 7fa57b92-3a3e-418c-bfc2-7ed2602004e4 | < 3.4.2 |
HIGH | 8.8 | The OceanWP theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.4. This allow… | — | wordfence |
| 7f8cc393-4d6f-4d15-ad95-d4a89dfe433c | < 1.5.1 |
HIGH | 8.8 | The StoreEngine β Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for W… | — | wordfence |
| 7f5bc5cc-fe96-48f6-b9c9-a2b9d83406b6 | HIGH | 8.8 | The Custom TinyMCE Shortcode Button WordPress plugin through 1.1 does not sanitise and escape the PHP_SELF variable befo… | — | wordfence | |
| 7f4f188f-ca84-44df-9738-d61094c2e695 | HIGH | 8.8 | The Find and Replace All plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence | |
| 7f119b98-9c42-40e2-b4f3-c26bed3cc213 | < 10.15 |
HIGH | 8.8 | The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable … | — | wordfence |
| 7eed1ae6-ee59-4616-9564-9aa5ec302ea9 | < 1.2.2 |
HIGH | 8.8 | Multiple SQL injection vulnerabilities in the yawpp plugin 1.2.1 for WordPress allow remote authenticated users with Con… | — | wordfence |
| 7ee267ff-b650-44a5-994b-3a22d34722e8 | < 1.0.3 |
HIGH | 8.8 | The WordPress Backup and Migrate Plugin β Backup Guard plugin for WordPress is vulnerable to arbitrary file uploads du… | — | wordfence |
| 7eb7d499-28ba-48ef-9798-b7c8cbb7aa3e | < 7.0.8 |
HIGH | 8.8 | The Conversios β Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPre… | — | wordfence |
| 7eaa0117-5320-431f-b3d2-05a867901528 | < 1.0.8 |
HIGH | 8.8 | The Pubnews theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability … | — | wordfence |
| 7ea4ca2d-6a67-43ad-817d-960cad3030b8 | < 3.6.4.2 |
HIGH | 8.8 | The Uncanny Toolkit for LearnDash plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… | — | wordfence |
| 7ea3e243-8deb-4fd7-a5db-a7a1294373b7 | < 1.7 |
HIGH | 8.8 | The Post Grid, Slider & Carousel Ultimate plugin for WordPress is vulnerable to Local File Inclusion in versions up to, … | — | wordfence |
| 7ea0cfbc-4494-4170-af59-3218e636e2fe | HIGH | 8.8 | The Sparkle Elementor Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2… | — | wordfence | |
| 7e589327-110b-4ede-9496-888d1bc31fc2 | HIGH | 8.8 | The Final User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.5. T… | — | wordfence | |
| 7e4e1afd-604d-45c2-ab6b-fa9ccac0c361 | < 4.1.2 |
HIGH | 8.8 | The All Import Pro Plugin for WordPress is vulnerable to blind SQL Injection via the unknown parameter in versions up to… | — | wordfence |
| 7e3fd472-c8ea-42dc-93df-872361ec97f3 | HIGH | 8.8 | The Attachment File Icons (AF Icons) plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →