Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 173 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 6428cf3c-a784-4e64-a6ef-041b3793ff67 | < 6.5 |
HIGH | 8.8 | The Hercules Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4 v… | — | wordfence |
| 64196936-a0b8-48a7-ba5c-01ce061df82c | < 1.5.8 |
HIGH | 8.8 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not have CSRF check in place when adding a … | — | wordfence |
| 63f53e3c-b038-4722-b5ba-7212e50b5978 | < 2.5.2 |
HIGH | 8.8 | The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file wit… | — | wordfence |
| 63d806ed-2cfc-4ac6-9ebb-75c13d2cfad4 | < 1.8.6 |
HIGH | 8.8 | The Teardrop theme for WordPress is vulnerable to arbitrary option updates in versions up to, and including, 1.8.5. This… | — | wordfence |
| 63af783b-5593-4f84-8a4b-e4a19d9c994c | HIGH | 8.8 | The Admin Log plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.50. T… | — | wordfence | |
| 63a4a077-c99e-4742-9fa1-f323fd24b950 | < 2.3.11 |
HIGH | 8.8 | The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'u… | — | wordfence |
| 6363b693-91b8-41cb-b13a-df6fdf9402c5 | < 5.1.3 |
HIGH | 8.8 | The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1.… | — | wordfence |
| 633d26e9-8a05-4f4b-93a8-5644f2f699db | < 12.7.0 |
HIGH | 8.8 | The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpf… | — | wordfence |
| 6324795d-3fab-4806-b7d8-f122d31429ff | < 10.8 |
HIGH | 8.8 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to SQL Injection via the $tid value in versions up t… | — | wordfence |
| 6320cd5f-c5a9-4731-9374-9b8b0838a1ec | < 2.15 |
HIGH | 8.8 | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable main… | — | wordfence |
| 6319ef8c-15ea-4e43-8d46-a6a110cba212 | HIGH | 8.8 | The de:branding plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.2. … | — | wordfence | |
| 6305b7be-8651-4028-a8cf-ea58b4977225 | < 1.6.5 |
HIGH | 8.8 | The Cardealer theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. T… | — | wordfence |
| 62fd2c51-eac1-47c0-adbc-90bdd8dbbc8e | HIGH | 8.8 | The Schreikasten WordPress plugin through 0.14.18 does not sanitise or escape the id GET parameter before using it in SQ… | — | wordfence | |
| 62ce7300-4d97-4add-a09d-1f14c99d1c9e | < 5.8.0 |
HIGH | 8.8 | The wproject theme for WordPress is vulnerable to Privilege Escalation in all versions up to 5.8.0 (exclusive). This mak… | — | wordfence |
| 629d4809-1dd2-4b67-8d8d-9c55f5240f94 | < 1.3.7 |
HIGH | 8.8 | Multiple plugins by the vendor E-plugins are vulnerable to privilege escalation due to insufficient restriction on sever… | — | wordfence |
| 6297753c-72c0-4926-9365-d0c760ddfd2a | HIGH | 8.8 | The Yotpo Reviews for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… | — | wordfence | |
| 628eef73-1725-4290-bb30-07792d1d5b6c | < 21.3 |
HIGH | 8.8 | The Frontend File Manager plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including,… | — | wordfence |
| 62831b8a-2c6c-44cd-9ed1-f188893bed35 | < 1.4.6 |
HIGH | 8.8 | The Store Locator WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
| 6263e0cd-5843-444d-8d12-61a898a77724 | < 1.5.5 |
HIGH | 8.8 | The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, al… | — | wordfence |
| 624bdb9e-6c50-4a00-9a04-1a32c938d48b | < 1.2.6 |
HIGH | 8.8 | The Image Hotspot by DevVN plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi… | — | wordfence |
| 62402e53-ff46-410e-9cc1-a87b677e6526 | < 1.6.2 |
HIGH | 8.8 | The Role Based Pricing for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file … | — | wordfence |
| 61bc71cf-aeaf-4f33-8367-68d5e8ea442c | < 2.8.1 |
HIGH | 8.8 | The EazyDocs plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.8.0. This ma… | — | wordfence |
| 61bbd7fe-cacf-4390-b976-3b931fc84af3 | < 1.1.5 |
HIGH | 8.8 | The bbp-move-topics plugin before 1.1.5 for WordPress has CSRF. | — | wordfence |
| 61992821-a053-4bc6-853a-1a826d096746 | < 3.6.4 |
HIGH | 8.8 | The Uncanny Toolkit for LearnDash plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… | — | wordfence |
| 616c65e7-8d0c-4be8-bd6f-f98187ff1539 | < 3.4.7 |
HIGH | 8.8 | The User Meta Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on th… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →