Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 179 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 547830df-eb90-471b-87be-5c5f2fc52b36 | HIGH | 8.8 | The Rate Own Post plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to insuf… | — | wordfence | |
| 5439651e-5557-4b13-813a-4fc0ad876104 | < 3.0.5 |
HIGH | 8.8 | The Classified Listing β Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Cross-Site R… | — | wordfence |
| 542a18f6-9d17-4e54-85e1-e01630ca371e | < 2.14.43 |
HIGH | 8.8 | The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and… | — | wordfence |
| 540d1c86-c648-42e1-a360-cc188d1a5635 | < 1.2.9 |
HIGH | 8.8 | The Gallery PhotoBlocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence |
| 53e2f7d5-ceb3-4c15-a761-a9f7c7585358 | < 2.3.2 |
HIGH | 8.8 | The Conditional Shipping for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… | — | wordfence |
| 53ab1f5f-7331-4587-8c37-e9bd86a83ae6 | < 1.25.4 |
HIGH | 8.8 | The Name Directory plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… | — | wordfence |
| 537bdd21-7ebd-4c17-a681-18703ac973a5 | HIGH | 8.8 | The Image Zoom plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.8.… | — | wordfence | |
| 53757567-5024-46cc-b2ae-04b5fc55a35c | HIGH | 8.8 | The Button Widget Smartsoft plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence | |
| 5361df27-493c-4731-9502-071af4894bbb | HIGH | 8.8 | The Orders functionality in the WordPress Page Contact plugin through 1.0 has an order_id parameter which is not sanitis… | — | wordfence | |
| 535e754e-f851-4809-a148-d9ba808b9d8a | < 9.2 |
HIGH | 8.8 | The Wp anything slider plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,… | — | wordfence |
| 535aa061-479f-415e-bee6-3151c42b917e | HIGH | 8.8 | The Configurator Theme Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ… | — | wordfence | |
| 53591a3b-8a99-40e2-8145-1d7785bcbab4 | HIGH | 8.8 | The AI Quiz | Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privil… | — | wordfence | |
| 53409aeb-67a6-4a44-993a-fb23f8fb1344 | HIGH | 8.8 | The WooCommerce Extra Cost plugins for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence | |
| 532ce349-0f4c-4197-bbbd-1e3dcbd0c9d3 | < 3.0.8 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in WordPress Email Template Designer - WP HTML Mail versions prior to 3.… | — | wordfence |
| 5311b43c-14dd-4bdd-b6d0-d6468b831968 | < 3.4.12 |
HIGH | 8.8 | The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to privilege e… | — | wordfence |
| 52cce49b-49b3-49b0-9f18-4829f07a420f | < 4.1.3 |
HIGH | 8.8 | The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File… | — | wordfence |
| 52b04517-f0be-4bbf-818c-70a12d76bfec | < 3.7.20 |
HIGH | 8.8 | The Advanced Views β Display Posts, Custom Fields, and More plugin for WordPress is vulnerable to Server-Side Template… | — | wordfence |
| 528a28e7-cdf9-4dfa-b710-8b934863de91 | HIGH | 8.8 | The WPBookit Pro - Appointment Booking Plugin for WordPress plugin for WordPress is vulnerable to arbitrary file uploads… | — | wordfence | |
| 527f8f08-bab3-4319-99bf-845c8b378c19 | < 1.0.3 |
HIGH | 8.8 | The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, … | — | wordfence |
| 5278e8d4-d23e-47ce-b920-dfb7ec56387c | < 1.2.4 |
HIGH | 8.8 | The Health Check & Troubleshooting plugin for WordPress is vulnerable to unauthorized execution of AJAX actions by subsc… | — | wordfence |
| 525a2180-3643-4f78-aafd-99a546bac363 | < 2.8.0 |
HIGH | 8.8 | The Bit Form Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence |
| 522b477f-9df9-4d30-aa03-d4946acab21a | HIGH | 8.8 | The WP User Switch plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.… | — | wordfence | |
| 52203b9c-7629-4969-8d2d-eb1ef33d160c | < 2.4.2 |
HIGH | 8.8 | The Membership & Content Restriction β Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, valid… | — | wordfence |
| 5217c992-4d0d-4774-a404-367e6b6bc47e | HIGH | 8.8 | The Testimonial Slider And Showcase Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, an… | — | wordfence | |
| 520df463-1ac9-4dbe-b490-8d962757cde7 | HIGH | 8.8 | The Radius Blocks plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.1. Th… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →