Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,412 vulnerabilities found (page 164 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 788bf199-bf09-4076-b5f1-129b6287096a | < 0.9 |
HIGH | 8.8 | The Most Popular Posts Widget plugin for WordPress is vulnerable to SQL Injection via the 'PostID' variable in versions … | — | wordfence |
| 7886708a-8daa-465b-b820-53bf409e682c | < 4.2.1 |
HIGH | 8.8 | The Tidio Live Chat plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4… | — | wordfence |
| 78669d4f-3c1e-49e6-af8d-56f105f99d01 | < 1.5.1.2 |
HIGH | 8.8 | SQL injection vulnerability in template-functions-category.php in WordPress 1.5.1 allows remote attackers to execute arb… | — | wordfence |
| 784593ec-b635-4f59-9afb-ab506f786d21 | < 2.1.3 |
HIGH | 8.8 | The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… | — | wordfence |
| 782d0920-08dd-4df7-958c-3ed7128f3d55 | < 1.5.2 |
HIGH | 8.8 | The orbisius-child-theme-creator plugin before 1.5.2 for WordPress allows CSRF via orbisius_ctc_theme_editor_manage_file… | — | wordfence |
| 77e4e516-8a12-48ee-9124-27f941b68b13 | < 4.1.1 |
HIGH | 8.8 | The Advanced Database Cleaner β Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, … | — | wordfence |
| 77de0955-d6e4-4da0-8a71-772c404e5dc2 | < 4.3.0 |
HIGH | 8.8 | The WP OAuth Server plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4… | — | wordfence |
| 77b7fb02-1b79-4b0b-99ab-fa042e86391a | < 2.2.8 |
HIGH | 8.8 | The Meta Data Filter & Taxonomies Filter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions ve… | — | wordfence |
| 77a2d64f-852f-4cc2-9905-98c8f0930817 | < 1.2.2 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the aut… | — | wordfence |
| 778f7d9b-6376-4026-a291-1fedeabe8c99 | HIGH | 8.8 | The Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3 via des… | — | wordfence | |
| 7762fe69-9bd4-4e4e-a6c5-1263fad352a0 | HIGH | 8.8 | The Hacklog DownloadManager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence | |
| 775e9f94-b66d-4c22-81ef-c335c0654f08 | < 3.4.1 |
HIGH | 8.8 | wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order… | — | wordfence |
| 774afb96-4385-4693-a446-c87f81b39feb | < 2.3.4 |
HIGH | 8.8 | In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could… | — | wordfence |
| 772e17d6-2819-4e66-88f2-0c7a6c0aaff0 | < 2.23.1 |
HIGH | 8.8 | The Quform - WordPress Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ… | — | wordfence |
| 77189684-b794-41a0-8fc0-3320032c2f69 | < 3.1 |
HIGH | 8.8 | The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence |
| 76fb7f1d-4f41-4a73-acbf-c0f49f0123b4 | < 1.3.13 |
HIGH | 8.8 | Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote atta… | — | wordfence |
| 76f9d37e-1339-4267-aaf6-38a591e97fa2 | < 4.3.6 |
HIGH | 8.8 | The WP Database Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence |
| 76eff464-69f0-47c1-bdcb-f8caa28a1280 | < 0.9.5 |
HIGH | 8.8 | In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upl… | — | wordfence |
| 76e4bde3-e815-49c1-9098-c09a54e2274a | HIGH | 8.8 | The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.1. This ma… | — | wordfence | |
| 76c39a00-b40a-4d06-96bc-864624e0ef8b | < 7.1.10 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in WP Spell Check 7.1.9 and earlier allows remote attackers to hijack th… | — | wordfence |
| 76c31190-9db9-4d14-83e0-cbfca812e8ea | < 2.1.4 |
HIGH | 8.8 | The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up t… | — | wordfence |
| 76b7a946-71ad-46da-95f6-a02703812938 | HIGH | 8.8 | The EM Beer Manager plugin for WordPress is vulnerable to arbitrary file upload leading to remote code execution in all … | — | wordfence | |
| 76ad6d21-f277-496f-aa6b-f9d5cb8a3801 | < 3.12.9 |
HIGH | 8.8 | The WPFunnels β Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to … | — | wordfence |
| 767bd8dd-993f-48d3-92f1-669d2329f1ab | HIGH | 8.8 | The Universal Star Rating plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence | |
| 766e3966-157a-4db3-9179-813032343f76 | < 5.3.1.0 |
HIGH | 8.8 | The RegistrationMagic β Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →