Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 169 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 6da9514c-a101-4f32-9a2f-697ca9ee1b26 | HIGH | 8.8 | The Blogistic theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all ver… | — | wordfence | |
| 6d9a3ad3-90fa-46bc-b42a-7616c02a8b50 | < 3.3.2 |
HIGH | 8.8 | The add-from-server plugin before 3.3.2 for WordPress has CSRF for importing a large file. | — | wordfence |
| 6d881f00-5985-45d5-9aab-d143a010d739 | < 2.1.4 |
HIGH | 8.8 | The WowRevenue plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check … | — | wordfence |
| 6d875c23-3d8a-4f82-bea3-1c46b5045d94 | < 2.0.17 |
HIGH | 8.8 | The My Tickets β Accessible Event Ticketing plugin for WordPress is vulnerable to Privilege Escalation in all versions… | — | wordfence |
| 6d79ebec-2a80-4b9a-b6d3-f3e9be30047a | HIGH | 8.8 | The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting … | — | wordfence | |
| 6d3b9d15-f6a9-4d1c-ada5-8c48add839a2 | < 2.8.0 |
HIGH | 8.8 | The Bit Form Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all… | — | wordfence |
| 6d3089d3-8ea4-47f7-bbcd-3408a099ae94 | HIGH | 8.8 | The Corsa Theme is vulnerable to Arbitrary File Upload in versions up to, and including, 1.5. This makes it possible for… | — | wordfence | |
| 6d27544c-97a5-42cd-ab07-358f819acbc4 | < 3.11.0 |
HIGH | 8.8 | The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to unauthorized modification … | — | wordfence |
| 6d041edb-70f3-4894-8a78-f6881541054c | < 1.1.8 |
HIGH | 8.8 | The Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation in versions up to, and… | — | wordfence |
| 6cc1d7f2-053d-42d4-afb7-6fb69fd71b91 | HIGH | 8.8 | The Banner Cycler plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.4.… | — | wordfence | |
| 6c9aaa7a-d6a7-488f-9800-7e978a765288 | < 2.0.0 |
HIGH | 8.8 | The Bulk Delete Users by Email plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… | — | wordfence |
| 6c7fe504-82b0-4a90-b3a5-cfdafdc1175d | < 1.8.8 |
HIGH | 8.8 | The WpTravelly plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.8.7. This … | — | wordfence |
| 6c718d65-eb40-43db-821f-344c6eca2384 | < 4.3.18 |
HIGH | 8.8 | The WP-Appbox plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.3.17 via th… | — | wordfence |
| 6c50568c-c0ec-43f9-bf06-7347f9cfc662 | HIGH | 8.8 | The New User Email Set Up WordPress plugin through 0.5.2 does not have CSRF check in place when updating its settings, w… | — | wordfence | |
| 6c439914-1d5a-4607-8e5c-9279fa3b462c | < 3.11 |
HIGH | 8.8 | The Ajax Search Lite plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the… | — | wordfence |
| 6c396ae6-d34c-4554-b670-28868dc136a5 | < 1.0.1 |
HIGH | 8.8 | The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sa… | — | wordfence |
| 6c338010-9281-44dc-a121-dc2ab5fd6707 | < 2.33.1 |
HIGH | 8.8 | The PowerPack for Beaver Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i… | — | wordfence |
| 6c18938b-6c0d-461e-b83e-26bc8e7bc1b3 | < 6.8.7 |
HIGH | 8.8 | The Ask Me theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, but not including, 6.8.7. … | — | wordfence |
| 6bcfc8f1-e962-4ad7-8a9d-89ce5c9022b6 | < 2.4.0 |
HIGH | 8.8 | The Garden Gnome Package plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… | — | wordfence |
| 6bcc8b84-34ac-4f8f-9a74-43b230877e92 | < 0.32 |
HIGH | 8.8 | The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the… | — | wordfence |
| 6bb785cf-9924-4b47-ac89-5273c6ba8ee6 | < 1.0.4 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in Custom CSS Pro 1.0.3 and earlier allows remote attackers to hijack th… | — | wordfence |
| 6bb1de69-7bc2-4785-9789-0a2d1cf35b9b | < 5.9.4.6 |
HIGH | 8.8 | The ProfileGrid β User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in … | — | wordfence |
| 6bb13a69-be75-48f0-9bcc-a33c5add7bd3 | HIGH | 8.8 | The Latest Tweets Widget WordPress plugin through 1.1.4 does not have CSRF check in place when updating its settings, wh… | — | wordfence | |
| 6b83e971-7e97-47e3-81a5-ff357692bca2 | < 3.6.8 |
HIGH | 8.8 | The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail… | — | wordfence |
| 6b6b6bc9-2e4b-4a50-9ecb-4311e3555abb | < 2.3.12 |
HIGH | 8.8 | The Accordion plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3.11 via de… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →