Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 185 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 44e71dea-d736-49c2-a630-f42905ac6b4d | HIGH | 8.8 | The Pixabay Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t… | — | wordfence | |
| 44c5a1cd-aac2-4c44-8aaa-9b5fdafad133 | < 1.3.3 |
HIGH | 8.8 | The MAZ Loader – Preloader Builder for WordPress plugin before 1.3.3 does not validate or escape the loader_id paramet… | — | wordfence |
| 44b259c7-ea91-4ab5-a46b-67aec50654c3 | HIGH | 8.8 | The SEO Scout plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.9.83 … | — | wordfence | |
| 449dfb1b-cd06-406f-82d5-c615383a0409 | < 2.0.1 |
HIGH | 8.8 | The Wiguard – CCTV & Security WordPress Theme for Surveillance Companies theme for WordPress is vulnerable to arbitrar… | — | wordfence |
| 4488d982-4e57-4614-b336-f1bba8dfa91d | HIGH | 8.8 | The surveys plugin for WordPress is vulnerable to generic SQL Injection via the ‘action’ parameter in versions up to… | — | wordfence | |
| 444a848d-61bc-4801-815f-d68bea59f5bc | HIGH | 8.8 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Wp Unique Article Header Image plugin 1.0 and earlier … | — | wordfence | |
| 442252f8-2896-44ba-a19c-d153b03b268b | < 2.4.8 |
HIGH | 8.8 | The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_… | — | wordfence |
| 4403fbe3-965b-4eb9-976f-efbfbf99b2e8 | < 2.4 |
HIGH | 8.8 | The Slider a SlidersPack plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.… | — | wordfence |
| 43b04825-d1c6-4e2a-9035-1f4fbfe14818 | < 1.7.15 |
HIGH | 8.8 | The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.14… | — | wordfence |
| 43a60896-3b88-4b36-b6d9-46812b8ba35b | HIGH | 8.8 | Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV comma… | — | wordfence | |
| 439e4c99-8f34-4e66-9d86-c0cbb8cf6da0 | < 4.4.42 |
HIGH | 8.8 | The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, … | — | wordfence |
| 437e8d95-2ab3-4cb0-94ca-110f742d6eff | < 2.1 |
HIGH | 8.8 | The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language … | — | wordfence |
| 437712f5-a493-4625-a314-856f0d0d9758 | < 1.4.2 |
HIGH | 8.8 | The Better Elementor Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ… | — | wordfence |
| 4372e6a4-3671-4110-bebb-85c1a97c5abb | HIGH | 8.8 | The ipBlockList plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. … | — | wordfence | |
| 4336d597-7e87-46eb-8abd-9fafd6cd25d9 | < 1.2.90 |
HIGH | 8.8 | The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to SQL Injection via the pageId parameter in vers… | — | wordfence |
| 431331aa-4d9f-41f2-a522-567bbd9b8831 | < 5.12.1 |
HIGH | 8.8 | The Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence |
| 430b7e72-72b8-4cf8-99f4-ee1d1d4b4f24 | < 1.1.24 |
HIGH | 8.8 | The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all ve… | — | wordfence |
| 430a0b93-2cb7-45bf-86ac-4a8b3a0be77a | < 1.2 |
HIGH | 8.8 | The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks wi… | — | wordfence |
| 4306b3b2-2834-4445-8c85-afc5c39f4632 | < 2.6.4 |
HIGH | 8.8 | The Namaste! LMS plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.6.3 via … | — | wordfence |
| 43039f2a-b3f9-4836-8b55-e8a091b1a102 | HIGH | 8.8 | The WP-GeoMeta plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wp_aj… | — | wordfence | |
| 4301666c-98a5-4028-978f-f50e5b8f4a6a | HIGH | 8.8 | The FoxyPress plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up to, and includin… | — | wordfence | |
| 42f54887-ce98-4360-8d07-37b1a48fc3fd | < 13.2.6 |
HIGH | 8.8 | The WP Statistics plugin for WordPress is vulnerable to time-based blind SQL Injection via the ‘agent’ parameter in … | — | wordfence |
| 42b373da-d5a6-4e3b-90f4-059da3641841 | < 4.5.5 |
HIGH | 8.8 | The IndieAuth plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5… | — | wordfence |
| 42a4ef37-c842-4925-b06a-3e6423337567 | < 2.0.23 |
HIGH | 8.8 | The Cookie Information | Free GDPR Consent Solution plugin for WordPress is vulnerable to arbitrary option updates due t… | — | wordfence |
| 429ce9e6-e51b-4f1e-8e26-f679b08d68d3 | < 1.5 |
HIGH | 8.8 | The Debug Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →