Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 172 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 669df758-0c7d-41c9-a9bd-9b3697898c77 | < 20180826 |
HIGH | 8.8 | The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta… | — | wordfence |
| 6677aa22-3248-41d5-a257-5330455d5bcc | < 8.18.19 |
HIGH | 8.8 | The Book Your Travel theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 8.1… | — | wordfence |
| 667023f9-9c45-4182-b1f1-9d85d17aaf58 | HIGH | 8.8 | The id GET parameter of one of the Video Embed WordPress plugin through 1.0's page (available via forced browsing) is no… | — | wordfence | |
| 666c02bd-d3e2-4e40-b189-b73e1136610b | < 1.1.2 |
HIGH | 8.8 | An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vuln… | — | wordfence |
| 664eb488-649e-4914-bd3c-cb7395893c6f | < 4.2.0 |
HIGH | 8.8 | The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vu… | — | wordfence |
| 6635db72-8302-421d-9011-7eabb57c43a2 | < 3.2.7 |
HIGH | 8.8 | The Contempo Real Estate Custom Posts plugin for WordPress is vulnerable to unauthorized file uploads due to a missing c… | — | wordfence |
| 66182fc4-863a-4a7b-92a8-2f43717b8579 | < 2.8 |
HIGH | 8.8 | The Captcha Code plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.… | — | wordfence |
| 65c72e79-f0a9-4293-98be-956d8e4afb83 | < 2.1.3 |
HIGH | 8.8 | SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated… | — | wordfence |
| 65869722-1147-4fdd-a844-944c51a07f2e | HIGH | 8.8 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Redirection Page plugin 1.2 for WordPress allow remote… | — | wordfence | |
| 657b1b7b-eac2-4935-a50f-0849c4e96b16 | < 4.8.4 |
HIGH | 8.8 | The Download Monitor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation an… | — | wordfence |
| 655b3a54-34b1-4c1a-a1b5-51d87e3134d4 | < 1.9.15 |
HIGH | 8.8 | The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_in… | — | wordfence |
| 6536d19f-a042-4404-b0c9-91aacd7768f7 | HIGH | 8.8 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions u… | — | wordfence | |
| 65189c49-600d-4a69-a687-0ff9e327783e | < 1.4.0 |
HIGH | 8.8 | The TeraWallet plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.24… | — | wordfence |
| 64fd32a1-da2a-42db-9597-06366a34f543 | HIGH | 8.8 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Lightbox Photo Gallery plugin 1.0 for WordPress allow … | — | wordfence | |
| 64e28272-722d-4a4d-98f6-84e6b29981e3 | < 3.1 |
HIGH | 8.8 | The BlindMatrix e-Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includi… | — | wordfence |
| 64e21c1c-6c52-4bc8-a399-fa010db60fe9 | HIGH | 8.8 | The Just Post Preview Widget plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… | — | wordfence | |
| 64db63e5-ff76-494a-be4f-d820f0cc9ab0 | < 10.1 |
HIGH | 8.8 | The Information Reel plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, a… | — | wordfence |
| 64c72788-a8fa-4f5b-a5b0-8754e952a14d | < 1.1.3 |
HIGH | 8.8 | The WP Mail Log plugin for WordPress is vulnerable to SQL Injection via the 'key'’ parameter in all versions up to, an… | — | wordfence |
| 64bae119-12c3-4b3e-88a7-2eb5a7b1b537 | < 1.7.7 |
HIGH | 8.8 | Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unpr… | — | wordfence |
| 6478cdbc-a20e-4fe2-bbd6-8a550e5da895 | < 5.3.2.0 |
HIGH | 8.8 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … | — | wordfence |
| 646a9885-8e0e-42a9-a113-0688c9f6dc93 | HIGH | 8.8 | The WP Image Uploader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… | — | wordfence | |
| 645f60ad-c8e5-47ec-94f1-960de4ef7838 | HIGH | 8.8 | The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This … | — | wordfence | |
| 642b589d-cb4b-46a0-b9f3-fad8b26bba0e | < 1.6.0 |
HIGH | 8.8 | The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks. | — | wordfence |
| 642a8e71-c267-41f5-bcf5-f5627be9038e | < 1.9.0.3 |
HIGH | 8.8 | The Csomagpontok és szállítási címkék WooCommerce hez plugin for WordPress is vulnerable to Cross-Site Request For… | — | wordfence |
| 642a6d42-100f-4461-b568-35e089287902 | < 3.73 |
HIGH | 8.8 | The plugin CRM WordPress Plugin for WordPress is vulnerable to SQL injection via several parameters in versions up to, a… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →