Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 182 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4d1512c2-75c1-405b-8bb4-f42ec69159a7 | HIGH | 8.8 | The Auto Featured Image plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… | — | wordfence | |
| 4ce8e0f1-5a7b-41a3-81d0-7fd12c9da6d9 | < 3.6.1 |
HIGH | 8.8 | The Croma Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escal… | — | wordfence |
| 4ccc8f3b-9028-45db-8db2-574736fe3ccb | < 3.1.22 |
HIGH | 8.8 | The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 3.1.2… | — | wordfence |
| 4cbbedcb-52dd-44b9-a629-1da0a2552f13 | < 1.2.9 |
HIGH | 8.8 | The Ovic Responsive WPBakery plugin for WordPress is vulnerable to arbitrary option updates due to a missing capability … | — | wordfence |
| 4c9aabb6-d17c-4845-ae1b-6ee3d8b9bfb1 | HIGH | 8.8 | The SB Uploader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the… | — | wordfence | |
| 4c498789-79f4-4b79-8e55-57eab1c51d4e | < 4.5.13 |
HIGH | 8.8 | The Redux Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.5… | — | wordfence |
| 4c298a24-b68b-450e-b823-f91841046783 | < 9.4.3 |
HIGH | 8.8 | The 3CX Live Chat plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 9.4.2 via… | — | wordfence |
| 4be5c7d7-47dd-42ee-9cde-9e9ad6276e41 | < 5.2.0 |
HIGH | 8.8 | The LayerSlider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.6.1… | — | wordfence |
| 4bddaefc-9ddc-4798-acb6-7b87f7c924a1 | < 1.1.13 |
HIGH | 8.8 | The Creator LMS β The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized modif… | — | wordfence |
| 4bc3da9e-4b5f-4200-9df9-0ae953571377 | < 7.1.1 |
HIGH | 8.8 | The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via 'por… | — | wordfence |
| 4b8adf59-3bd3-497a-8afd-3df4f7660863 | < 4.27.5 |
HIGH | 8.8 | The sonaar theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.27.4. This … | — | wordfence |
| 4b475ada-3b31-40a3-9a81-5a7b1a1e190a | < 1.3.1 |
HIGH | 8.8 | The Contact Form Entries plugin for WordPress is vulnerable to generic SQL Injection via the plugin's shortcode attribut… | — | wordfence |
| 4b41d134-be9e-469f-b26b-ac30d95db0a3 | < 3.7.1 |
HIGH | 8.8 | The Tutor LMS Pro β eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injectio… | — | wordfence |
| 4b2fc891-f3c6-4f4f-ad52-0a1a949eed25 | < 1.3.0 |
HIGH | 8.8 | The Toret Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc… | — | wordfence |
| 4b2c3987-fe7e-426d-8398-acdd6fa3a3dd | < 1.0.47 |
HIGH | 8.8 | The Doubly β Cross Domain Copy Paste for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all v… | — | wordfence |
| 4b0f5c2c-f01a-4a09-99c2-2b7dfe3bcd05 | HIGH | 8.8 | The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in pl… | — | wordfence | |
| 4b0edbf1-bbd2-4e63-86f3-898ad6666d7b | HIGH | 8.8 | The Hospital Management System for Wordpress plugin for WordPress is vulnerable to Privilege Escalation in all versions … | — | wordfence | |
| 4b06792e-0b4e-4c1e-b7e9-8cbbae343298 | < 1.4.8 |
HIGH | 8.8 | The wpCentral for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.4.7 due to missing… | — | wordfence |
| 4aff8870-4222-454a-90cd-044784cb4224 | < 1.3.12 |
HIGH | 8.8 | The WPSmartContracts plugin for WordPress is vulnerable to generic SQL Injection via an unknown parameter in versions up… | — | wordfence |
| 4af83d4b-2eae-481f-b3fd-d5bcacc1d709 | HIGH | 8.8 | The uContext for Clickbank plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in v… | — | wordfence | |
| 4af801db-44a6-4cd3-bd1a-3125490c8c48 | < 5.38.10 |
HIGH | 8.8 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty… | — | wordfence |
| 4af41f69-1335-4199-bf29-c9699de50a16 | HIGH | 8.8 | The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valida… | — | wordfence | |
| 4adb7436-11e6-4512-b6c9-551402909bf0 | < 3.17.1 |
HIGH | 8.8 | The Zox News - Professional WordPress News & Magazine Theme plugin for WordPress is vulnerable to unauthorized data modi… | — | wordfence |
| 4ad5ca1c-b8c3-42c0-8170-821ada826cbb | < 3.7.2 |
HIGH | 8.8 | The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.… | — | wordfence |
| 4a76f851-3f4e-4457-a33c-eede51c4b4d1 | < 2.0.0 |
HIGH | 8.8 | The Block Logic β Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →