Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 189 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 3b1b60f4-39f7-4981-bd8d-b1c6e63cf082 | < 4.24 |
HIGH | 8.8 | The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to u… | — | wordfence |
| 3aecc02a-fd49-4743-9d7b-894cf657cbc1 | < 2.2.0 |
HIGH | 8.8 | The Asgaros Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1… | — | wordfence |
| 3acbdb2a-e7c6-4062-b48a-7035e464edaf | < 5.6.5 |
HIGH | 8.8 | The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
| 3ac48cd9-1de5-4840-b3f3-dc24ca52442e | < 2.6.85 |
HIGH | 8.8 | The Smart Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… | — | wordfence |
| 3abac0a1-a696-48b1-88d9-d0b102c82ac3 | < 1.1.1 |
HIGH | 8.8 | The WHIZZ plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.1.1. This is due to missi… | — | wordfence |
| 3ab6ed55-7067-4318-865b-33dcfc584386 | < 4.0.2 |
HIGH | 8.8 | The GSheetConnector For WPForms – WPForms Google Sheets Integration (Real-Time Sync) plugin for WordPress is vulnerabl… | — | wordfence |
| 3aa537bc-90fa-4d87-9dd5-e32aef4273c7 | < 1.1.0 |
HIGH | 8.8 | The Cart Link for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… | — | wordfence |
| 3a9f7a61-535f-45c8-a7e7-e8b095cacaa1 | < 1.5.63 |
HIGH | 8.8 | The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php. | — | wordfence |
| 3a6316d8-1d64-4d28-b28a-00ca0b5facee | HIGH | 8.8 | The Read more By Adam plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence | |
| 3a58644a-c678-41e7-8020-d2f2c247682f | HIGH | 8.8 | The G-Lock Double Opt-in Manager plugin for WordPress is vulnerable to generic SQL Injection via the 'json' parameter in… | — | wordfence | |
| 3a2c62a8-bc00-43b7-a3e8-a45d0cb75854 | < 5.0.0 |
HIGH | 8.8 | WordPress plugin wp-cleanfix has Remote Code Execution | — | wordfence |
| 3a17b6ad-c778-4677-b5bd-6ffc9b425ba1 | < 4.4.4 |
HIGH | 8.8 | The Quiz And Survey Master plugin for WordPress is vulnerable to Multiple SQL Injections via several parameters in versi… | — | wordfence |
| 3a17560b-4fe0-4e1b-b4a2-c411f1123914 | < 3.3.6 |
HIGH | 8.8 | Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sit… | — | wordfence |
| 3a12945d-a67c-4a19-a4e7-f65f5f2a21bb | < 13.2 |
HIGH | 8.8 | The Superb slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions … | — | wordfence |
| 39f12569-ff89-4c6b-afcf-a8c4421749cc | < 3.1.37.12.L |
HIGH | 8.8 | Vulnerability in wordpress plugin Event Expresso Free v3.1.37.11.L, The function edit_event_category does not sanitize u… | — | wordfence |
| 398ebe7e-b0a7-47d8-b2f2-61973182f520 | HIGH | 8.8 | The FoxyPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.4.9. … | — | wordfence | |
| 396f785f-0354-462e-bcaa-69e364c8c4b5 | HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the TweetScribe plugin 1.1 and earlier for WordPress allows remote at… | — | wordfence | |
| 396ecd5b-d351-4289-aea4-332af5101f10 | < 2.0.3 |
HIGH | 8.8 | The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in… | — | wordfence |
| 391ed7a2-64db-4a79-a697-86c70c60d02e | < 0.8.7 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to hi… | — | wordfence |
| 391e12f7-9521-4ac6-bd78-ac28df72030b | HIGH | 8.8 | The BNG Gateway For WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … | — | wordfence | |
| 390ee957-f06f-4952-b740-4578c130925f | < 1.4.5 |
HIGH | 8.8 | The WP Email Users plugin for WordPress is vulnerable to SQL Injection via the ‘filetitle’ parameter in versions up… | — | wordfence |
| 390a541e-68dd-43dd-8fe4-5334c534552c | HIGH | 8.8 | The Betheme theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 28.4.2. Thi… | — | wordfence | |
| 38ea001c-6edb-4f36-a7ec-19be1d857b9e | < 3.2.5 |
HIGH | 8.8 | The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all v… | — | wordfence |
| 38c6b149-39d7-491a-9f3a-261087a52a03 | HIGH | 8.8 | The Reales WP STPT plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to… | — | wordfence | |
| 38bf21c4-bf2e-4096-b4e3-9e3a5a60f1ad | < 3.2.1 |
HIGH | 8.8 | The Companion Auto Update plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →