Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 178 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 57d863b9-d544-4af5-afbe-268635a8dd98 | HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in askapache-firefox-adsense.php in the AskApache Firefox Adsense plugin… | — | wordfence | |
| 57cc15a6-2cf5-481f-bb81-ada48aa74009 | < 7.2.5 |
HIGH | 8.8 | The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence |
| 57be67fd-8485-495f-b5e9-6eb52af945b7 | < 3.116.0 |
HIGH | 8.8 | The WordPress Automatic Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file typ… | — | wordfence |
| 57a39691-8fff-4e62-a03a-70b428025d77 | HIGH | 8.8 | The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page… | — | wordfence | |
| 578cf704-e84d-469f-bf26-e60268506a78 | < 0.1.0.10 |
HIGH | 8.8 | The InstaWP Connect plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.1.0.9 due to… | — | wordfence |
| 578a908a-d447-4b3e-b5d1-be86363c982a | < 3.7.19 |
HIGH | 8.8 | In WordPress before 4.7.3, there is cross-site request forgery (CSRF) in Press This (wp-admin/includes/class-wp-press-th… | — | wordfence |
| 576ca901-45e2-4e6d-9bc4-370bf1f68077 | < 5.6.4 |
HIGH | 8.8 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to SQL Injection via the 'productid' attribute of… | — | wordfence |
| 5716c4e1-a6d3-42e8-b90c-d16f204c8503 | < 1.1.4 |
HIGH | 8.8 | The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, … | — | wordfence |
| 570474f2-c118-45e1-a237-c70b849b2d3c | < 3.11.7 |
HIGH | 8.8 | The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check… | — | wordfence |
| 56fce928-108d-4e59-8746-3699a9db427e | < 3.4.0 |
HIGH | 8.8 | The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to… | — | wordfence |
| 56f59303-cf82-4239-9e04-80a32f20d87c | < 2.2.4 |
HIGH | 8.8 | SQL injection vulnerability in the Multi Feed Reader prior to version 2.2.4 allows authenticated attackers to execute ar… | — | wordfence |
| 56808590-0226-4968-ba64-0965793a3511 | < 2.9.5 |
HIGH | 8.8 | The ListingPro - WordPress Directory & Listing Theme theme for WordPress is vulnerable to Local File Inclusion in all ve… | — | wordfence |
| 5658f62b-2f4a-46f7-b229-8e239c7ef148 | < 3.1 |
HIGH | 8.8 | The Tree Sitemap (Pages, Posts & Categories list) plugin for WordPress is vulnerable to Cross-Site Request Forgery in ve… | — | wordfence |
| 56405a91-259c-4700-bbc1-ffe0d77f3974 | < 1.3 |
HIGH | 8.8 | The Vernissage theme for WordPress is vulnerable to arbitrary option updates due to a missing capability check on the of… | — | wordfence |
| 5607fffa-341f-4237-b064-00fe2e6c9c9f | HIGH | 8.8 | The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an i… | — | wordfence | |
| 55bd9bb4-6a81-4e9d-b0a9-76725aba6635 | < 2.3.2 |
HIGH | 8.8 | The SEO Redirection - 301 Redirect Manager Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … | — | wordfence |
| 55852490-7087-41b8-9848-758e443ae04b | < 1.13.5 |
HIGH | 8.8 | The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action paramet… | — | wordfence |
| 5572fea7-a8d5-457d-88fc-57051b35aa11 | < 1.1.1 |
HIGH | 8.8 | The JiangQie Official Website Mini Program WordPress plugin before 1.1.1 does not escape or validate the id GET paramete… | — | wordfence |
| 55278cc8-338e-4583-9334-f91f94f22e13 | < 4.2.3 |
HIGH | 8.8 | The Custom API for WP plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4… | — | wordfence |
| 54fac673-2d83-4d06-a4c0-8bffc269a90c | HIGH | 8.8 | The Media.net Ads Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… | — | wordfence | |
| 54c14f04-32ec-4d05-b47b-3ff5e70c4daf | < 1.3.5 |
HIGH | 8.8 | The Houzez CRM plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.4 due to insuff… | — | wordfence |
| 54b3eaf4-5f45-4b94-8a7b-03da76d6ea83 | < 2.3.1 |
HIGH | 8.8 | The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_med… | — | wordfence |
| 54b2ae17-204f-44cf-bbd3-d012158a4e38 | HIGH | 8.8 | The Writer Helper plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in al… | — | wordfence | |
| 549ddee9-9f38-40e2-ac50-bff5366c0b94 | < 2.0.14 |
HIGH | 8.8 | The Testimonial Slider plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.… | — | wordfence |
| 54852b3d-9830-491d-aa41-bc2bf763a55d | < 4.4.6 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in Software License Manager versions prior to 4.4.6 allows remote attack… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →