Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 187 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 3fda31fa-efc9-44b9-99ba-9e3e23aa2ee0 | < 1.9.3 |
HIGH | 8.8 | The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_op… | — | wordfence |
| 3f9bf252-dcfb-4142-8301-1a5b565e975a | < 0.3.3 |
HIGH | 8.8 | The FunCaptcha β Anti-Spam CAPTCHA plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before… | — | wordfence |
| 3f92c416-8e95-4097-9f16-e1f9389b2334 | HIGH | 8.8 | The Builderall for WordPress plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and incl… | — | wordfence | |
| 3f6b435b-d8b4-434b-8cac-cc3adbc437eb | < 4.7.35 |
HIGH | 8.8 | WordPress Core is vulnerable to Remote Code Execution in multiple release branches, including versions 4.7.0 through 7.0… | — | wordfence |
| 3f630773-f65a-44a5-9b84-ea542c78a69a | < 1.10.4 |
HIGH | 8.8 | The Clean Login for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.3. This… | — | wordfence |
| 3f5fa5c1-311a-4e35-83c8-387f8039e671 | HIGH | 8.8 | The Essential Breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence | |
| 3f074584-ec8a-4259-b959-fe37c0244acc | HIGH | 8.8 | The Wishlist Member plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence | |
| 3f061e7f-6a87-4d4a-9b4e-8234883f2ebc | < 3.17.0 |
HIGH | 8.8 | The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalatio… | — | wordfence |
| 3edfc4af-2a28-4bdf-becf-018d9f656947 | < 1.7.1050 |
HIGH | 8.8 | The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and in… | — | wordfence |
| 3ebe25a7-fa4d-4e3f-b969-2ff3a8388b06 | < 0.8.5.8 |
HIGH | 8.8 | The WP Fastest Cache plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.8.5.… | — | wordfence |
| 3ebc324a-4858-4502-b962-a4e26ca7445e | HIGH | 8.8 | The Make A Statement theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence | |
| 3e91fabe-469f-4743-bb8d-76ef20313b37 | < 5.99 |
HIGH | 8.8 | Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authen… | — | wordfence |
| 3e900c98-5ab1-4674-b820-553c44df7c02 | HIGH | 8.8 | The FavIcon Switcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence | |
| 3e8a25d1-4bd8-4ecf-ac10-a333abaac328 | < 3.2.6 |
HIGH | 8.8 | The Image Intense plugin for WordPress is vulnerable to unspecified SQL Injection in versions up to, and including, 3.2.… | — | wordfence |
| 3e03bc79-b42e-4015-8476-2b0488c71028 | < 4.5.3 |
HIGH | 8.8 | An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authent… | — | wordfence |
| 3e037931-870f-45eb-973c-0276911682ad | < 1.4.0 |
HIGH | 8.8 | The Debugger & Troubleshooter plugin for WordPress was vulnerable to Unauthenticated Privilege Escalation in versions up… | — | wordfence |
| 3de5ebda-a935-46fb-b35f-2f3784a63203 | < 6.5.1 |
HIGH | 8.8 | The PDF Invoices for WooCommerce + Drag and Drop Template Builder plugin for WordPress is vulnerable to PHP Object Injec… | — | wordfence |
| 3dc7bc0a-b209-431f-a9f1-f850b1a1d1b4 | < 3.5.0 |
HIGH | 8.8 | The GiveWP plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.2 via de… | — | wordfence |
| 3dbe01a5-a6ab-42d6-a485-ec54a4a62a0f | < 5.0 |
HIGH | 8.8 | The Add Custom Codes β Insert Header, Footer, Custom PHP Snippets, CSS, Javascript plugin for WordPress is vulnerable … | — | wordfence |
| 3d96d38a-7f0e-4e47-ba49-727705eaaac6 | HIGH | 8.8 | The Empowerment theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.2 vi… | — | wordfence | |
| 3d933256-765b-4e1b-b5a1-39bf767bf860 | HIGH | 8.8 | The Mojoomla School Management System plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in unkn… | — | wordfence | |
| 3d6629e9-ab43-4eca-9340-5691421ab19d | < 1.7.11 |
HIGH | 8.8 | The Contact Form by Supsystic plugin for WordPress is vulnerable to generic SQL Injection via the 'sidx' and 'sord' para… | — | wordfence |
| 3d5c5511-570e-4048-8c1b-68cfc831f0c6 | < 3.0 |
HIGH | 8.8 | The Advanced Menu Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence |
| 3d56fdde-ab7a-4e7c-9f48-48e71e09a681 | < 5.6.12 |
HIGH | 8.8 | The OWM Weather plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.6.1… | — | wordfence |
| 3d36d52e-7247-4f06-ae10-7827ae242983 | < 1.9 |
HIGH | 8.8 | The AdsforWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8. Thi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →