Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 180 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 5205cc95-06d1-4bc6-a9ea-082df9566935 | < 1.1.4 |
HIGH | 8.8 | The WP Blog Post Layouts plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including… | — | wordfence |
| 51fe2379-e5c6-4cd0-b7d1-b03105403b97 | HIGH | 8.8 | The SK WP Settings Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence | |
| 51d4b7f6-183b-4a8d-a94d-83c66950a872 | < 2.1.0 |
HIGH | 8.8 | The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Esca… | — | wordfence |
| 51d0ba58-614e-4284-ae0b-b0b76fc5c46d | < 43.3 |
HIGH | 8.8 | The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43… | — | wordfence |
| 51cf2f40-7be8-4302-a766-88ec2f0501f5 | < 3.4.1 |
HIGH | 8.8 | includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF. | — | wordfence |
| 51cd2cb8-ac77-4962-9156-da0195ce1003 | HIGH | 8.8 | The BuddyForms plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.8.17. This… | — | wordfence | |
| 5184740a-c747-4217-bb13-6568465672df | < 1.4.3 |
HIGH | 8.8 | The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions… | — | wordfence |
| 517531ec-4160-4287-8499-6266e08223dc | < 4.2.1 |
HIGH | 8.8 | The Classified Listing plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2.… | — | wordfence |
| 51634a0c-f979-403b-80b0-8e3a65e7ad35 | HIGH | 8.8 | The FAQs Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.… | — | wordfence | |
| 516261b5-4356-40e1-9418-3243086bc1b4 | < 3.4 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers … | — | wordfence |
| 515a5dfd-c064-47d2-b347-e4f417bb260a | < 1.0.16 |
HIGH | 8.8 | The QuickCal plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.15. … | — | wordfence |
| 515502b5-c344-4855-aff1-57833233c5d2 | < 8.1 |
HIGH | 8.8 | The Wp photo text slider 50 plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions u… | — | wordfence |
| 5143a2d2-504a-46b8-b82b-19beba4da64d | < 2.0.22 |
HIGH | 8.8 | The Arbitrary File Upload plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including,… | — | wordfence |
| 5137244c-584f-4b48-869a-b6669c84eaac | < 1.1.6 |
HIGH | 8.8 | The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with result… | — | wordfence |
| 5118ed50-d7be-4606-af9d-18b63359956c | < 8.2.7 |
HIGH | 8.8 | The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape… | — | wordfence |
| 50bc789a-be96-4e65-9a1d-0314c0247613 | HIGH | 8.8 | The Smallerik File Browser plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… | — | wordfence | |
| 50adbe1d-9d79-4015-9e09-2166f97efc47 | HIGH | 8.8 | The Option Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missin… | — | wordfence | |
| 50946bc7-8d31-4376-bdcc-de7aad700503 | < 1.0.8 |
HIGH | 8.8 | The WPBifröst – Instant Passwordless Temporary Login Links plugin for WordPress is vulnerable to Privilege Escalation… | — | wordfence |
| 50932c88-994d-4904-b075-e48d2cb5bc24 | < 1.3 |
HIGH | 8.8 | The Add Multiple Marker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence |
| 50812a8b-7d49-41fa-ba50-47d07a4b6caa | < 4.1.2 |
HIGH | 8.8 | The Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently plugin for WordPress is vulnerable to PHP Obj… | — | wordfence |
| 507d308e-7df7-4bcb-b63c-f438b482c36b | HIGH | 8.8 | The Post Index WordPress plugin is vulnerable to Cross-Site Request Forgery via the OptionsPage function found in the ~/… | — | wordfence | |
| 507c2abd-47d3-4a28-a9b7-a1ad9b026e7d | < 1.6.4 |
HIGH | 8.8 | The Nokri - Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in … | — | wordfence |
| 506d1518-658f-4deb-9c30-d0bce5ef9df4 | < 3.7.28 |
HIGH | 8.8 | WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca… | — | wordfence |
| 502724d9-ccc4-42db-bc1e-c521f7c80e70 | < 3.3.3 |
HIGH | 8.8 | The Profile Builder/Profile Builder Pro plugins for WordPress is vulnerable to blind SQL Injection via multiple paramete… | — | wordfence |
| 501fb05a-c8ec-43c6-b462-2a83c4f8b6b7 | HIGH | 8.8 | The LiveSync for WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →