Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 174 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 6158ec37-a6fb-42f9-bab6-bf547ea28ea0 | < 3.1.1 |
HIGH | 8.8 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i… | — | wordfence |
| 6145e2d7-c917-4814-a13e-6d34088cb784 | < 2.1.1 |
HIGH | 8.8 | The WPC Admin Columns plugin for WordPress is vulnerable to privilege escalation in versions 2.0.6 to 2.1.0. This is due… | — | wordfence |
| 60d59753-5b6b-4f3e-8faf-8053750ae05d | HIGH | 8.8 | The AN_GradeBook for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions up to, and including, 5… | — | wordfence | |
| 60b1abeb-b11a-4de7-b747-53b166276a28 | HIGH | 8.8 | Mufeng's Hermit ι³δΉζζΎε¨ plugin <= 3.1.6 is vulnerable to SQL injection. This allows authenticated attackers with… | — | wordfence | |
| 609e1177-15aa-476b-b56b-299495055850 | HIGH | 8.8 | The Zegen - Church WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to missing file type … | — | wordfence | |
| 609424cf-8bba-4dbd-992f-c48b7283e9f4 | HIGH | 8.8 | The Seo Meta Tags plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4… | — | wordfence | |
| 6083c255-48df-498c-ad28-fa8a2e20c67a | HIGH | 8.8 | The Custom Post Type Lockdown plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… | — | wordfence | |
| 6082791e-feac-41f7-b565-9d98624ddf50 | < 1.7.33 |
HIGH | 8.8 | The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pw… | — | wordfence |
| 60679026-13a3-4702-91a3-876636f3c5bc | < 1.1.7 |
HIGH | 8.8 | The Booster Elite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, bu… | — | wordfence |
| 605dae3b-534d-45f3-98bd-150713c34bb7 | < 1.5.10 |
HIGH | 8.8 | The JetCompareWishlist plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.… | — | wordfence |
| 6045475f-f95a-4618-82ed-e42637d1c1d8 | < 1.1.10 |
HIGH | 8.8 | The Easy PayPal Shopping Cart for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence |
| 603b1f0e-185c-4a0a-a6a2-c63105b2c9f3 | < 2.9.1 |
HIGH | 8.8 | The Finale WooCommerce Sale Countdown plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t… | — | wordfence |
| 603210ca-7231-4c91-8258-fe3cd6e37425 | < 1.9.1 |
HIGH | 8.8 | The WP Delicious β Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to … | — | wordfence |
| 6003ad4e-f4ad-49bf-8d83-3da4945456a4 | < 2.0 |
HIGH | 8.8 | The Ultimate Classified Listings plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inclu… | — | wordfence |
| 6001660c-4b18-473d-a07d-30e0f7af29d1 | HIGH | 8.8 | The DD Roles plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.1. This … | — | wordfence | |
| 60013752-d7cf-46e8-84e1-1b614f737b46 | < 2.19.26 |
HIGH | 8.8 | The Spectra Gutenberg Blocks β Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code … | — | wordfence |
| 5fff40e4-6bab-46b4-a6b6-34f89d1aa12c | < 4.2.16 |
HIGH | 8.8 | The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to Privilege Escalat… | — | wordfence |
| 5fd0971e-7749-4970-ad39-d0d64a9f1d90 | < 2.4.2 |
HIGH | 8.8 | The Custom CSS, JS & PHP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… | — | wordfence |
| 5fca3dae-43a9-4130-ad04-8624aeb0c26b | < 1.2550 |
HIGH | 8.8 | The church-admin plugin before 1.2550 for WordPress has CSRF affecting the upload of a bible reading plan. | — | wordfence |
| 5f8f8d46-d7e7-4b07-9b10-15e579973474 | HIGH | 8.8 | The Auto Refresh Single Page plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu… | — | wordfence | |
| 5f42c8a0-2dbc-4902-83e4-d9d9ea441e1a | < 3.8.12 |
HIGH | 8.8 | The Multivendor Marketplace Solution for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery i… | — | wordfence |
| 5f2fa602-79db-4bb3-a55c-75da59116f06 | < 5.0.6 |
HIGH | 8.8 | A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance… | — | wordfence |
| 5f2f34e1-3b08-4e23-a29b-21e61e6a6063 | < 2.4.8 |
HIGH | 8.8 | The Admin Custom Login plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting v… | — | wordfence |
| 5f24baee-7003-449b-9072-d95fa1e26c8f | < 4.0.25 |
HIGH | 8.8 | The Event Manager, Events Calendar, Tickets, Registrations β Eventin plugin for WordPress is vulnerable to Local File … | — | wordfence |
| 5ee1bc43-1d9f-4bf7-b5cb-848c6d53938e | < 8.6.5 |
HIGH | 8.8 | The MapSVG β Vector maps, Image maps, Google Maps plugin for WordPress is vulnerable to arbitrary file uploads due to … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →