Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 171 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 68d9aeac-2c01-4afd-8307-906f1bc595d7 | < 1.4.5 |
HIGH | 8.8 | The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions… | — | wordfence |
| 68c1776e-8e29-4eea-87d0-cf7318a64f7d | < 5.7 |
HIGH | 8.8 | There is functionality in the Store Locator Plus for WordPress plugin through 5.5.15 that made it possible for authentic… | — | wordfence |
| 68a80ca3-45f4-4446-af7a-e582c94ccb52 | HIGH | 8.8 | The TotalPoll for Polls and Contests plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, … | — | wordfence | |
| 6897a8fe-c32e-430a-847c-23d1add2355d | HIGH | 8.8 | Various Orange themes for WordPress are vulnerable to arbitrary file uploads due to a Cross-Site Request Forgery vulnera… | — | wordfence | |
| 6881b0ad-7f11-4709-8c17-37aa505bad4c | HIGH | 8.8 | The తెలుగు బైబిల్ వచనములు WordPress plugin through 1.0 is lacking any CSRF check w… | — | wordfence | |
| 687cd0ac-5f78-4429-b6b5-dd1113143a4d | HIGH | 8.8 | The Mobile browser color select plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … | — | wordfence | |
| 68679ff9-48a8-4146-a37f-5f844dc86c92 | HIGH | 8.8 | The JKDEVKIT plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t… | — | wordfence | |
| 68366105-996c-4069-978c-c6ff222acd55 | HIGH | 8.8 | The CF7 Reply Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… | — | wordfence | |
| 682b40ad-ca62-47eb-9abc-fd43122d11c8 | HIGH | 8.8 | SQL injection vulnerability in the InLinks plugin through 1.1 for WordPress allows authenticated users to execute arbitr… | — | wordfence | |
| 68250b6c-22c8-494f-b0b0-62b80cc4de0c | < 3.3.4 |
HIGH | 8.8 | The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress… | — | wordfence |
| 680746a3-8a72-4ec2-9f58-d744f40168ed | < 1.2 |
HIGH | 8.8 | The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder theme for WordPress is vulnerable to Remote Cod… | — | wordfence |
| 68023557-fc92-4cf6-96b4-405ff5a5fd5a | < 5.3.3 |
HIGH | 8.8 | The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vu… | — | wordfence |
| 67fe46cd-a6c4-4d0a-842a-f61334559731 | < 2.3.2 |
HIGH | 8.8 | The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Requ… | — | wordfence |
| 67ca3305-9a04-421f-a38e-66b69d2bbd38 | < 1.1.3 |
HIGH | 8.8 | The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to arbitrary file uploads … | — | wordfence |
| 67c86b04-fdbd-4782-a362-fdec5e1f7c92 | HIGH | 8.8 | The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwan… | — | wordfence | |
| 67ae29ee-ec3d-41d2-8691-ba1c615d243d | < 4.2.0 |
HIGH | 8.8 | The Meow Gallery plugin for WordPress is vulnerable to Arbitrary Options Update via the REST API in versions up to, and … | — | wordfence |
| 675c86fb-e01f-4957-a49c-31b96383304f | < 1.5.2 |
HIGH | 8.8 | SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin be… | — | wordfence |
| 6754ba34-0dc7-40a5-9548-a5f77db0df53 | < 3.5.05 |
HIGH | 8.8 | The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthoriz… | — | wordfence |
| 673eb0ec-89c2-4d36-91fb-c18a110fe6c4 | < 2.4.5 |
HIGH | 8.8 | The Restaurant Menu by MotoPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inclu… | — | wordfence |
| 6717adb0-27bc-4cd4-8c34-bea59bc0e016 | < 3.5.08 |
HIGH | 8.8 | The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to Remote Cod… | — | wordfence |
| 66f71de2-055d-42f0-9eb1-145c64f44d5b | < 2.4 |
HIGH | 8.8 | The Google Analytics MU plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 2.4. This is… | — | wordfence |
| 66bd0a9f-66ec-42a5-a123-0a468bb43ed8 | < 4.5.0.1 |
HIGH | 8.8 | The Advanced Coupons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| 66b91fe9-ceb3-485c-bf5f-a672656d4e86 | < 2.0.3 |
HIGH | 8.8 | The All-in-One WP Migration plugin for WordPress is vulnerable to authorization bypass due to a missing capability check… | — | wordfence |
| 66b7d455-0959-4a7a-b37c-02d1ecac666b | HIGH | 8.8 | The Rotating Posts WordPress plugin through 1.11 does not have CSRF check in place when updating its settings, which cou… | — | wordfence | |
| 66afddee-a136-4c71-9e5d-3cc1552010cf | < 5.99 |
HIGH | 8.8 | Cross-Site Request Forgery (CSRF) vulnerability leading to Database Reset in WordPress WP Reset PRO Premium plugin (vers… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →