Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 190 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 38a079c8-181c-4bd8-a45d-e132711029ff | < 4.0.2 |
HIGH | 8.8 | The Enable Media Replace plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, … | — | wordfence |
| 3889d01d-a961-46b9-a86e-8ab19641cf2d | HIGH | 8.8 | The Doctor Appointment Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includi… | — | wordfence | |
| 3871bae4-f954-4692-8af8-1f96f8fcb778 | < 4.0.9 |
HIGH | 8.8 | The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missi… | — | wordfence |
| 3856289b-6e82-4d05-afa2-ea561a4e5c30 | HIGH | 8.8 | The GERRYWORKS Post by Mail plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ… | — | wordfence | |
| 37f7f9ef-d57a-41e9-bd2c-2aa04a82b6c4 | < 2.0.6 |
HIGH | 8.8 | Cross-site scripting (XSS) vulnerability in the CSRF protection scheme in WordPress before 2.0.6 allows remote attackers… | — | wordfence |
| 37f704bf-82bc-44f7-8b3c-cbf117732aaf | HIGH | 8.8 | The Dailydeal by Templatic theme for WordPress is vulnerable to arbitrary file uploads via CSRF due to missing or incorr… | — | wordfence | |
| 37d4d038-3f5c-4c4a-b5f1-3dd23a5b345e | < 4.0.26 |
HIGH | 8.8 | The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.25 via the … | — | wordfence |
| 37a25fdf-da5d-42bd-a803-afb3787aabf4 | < 1.5.2 |
HIGH | 8.8 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Ma… | — | wordfence |
| 376f2fbf-98a4-49d9-bd22-40da5d37b62d | < 2.6.0 |
HIGH | 8.8 | The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upl… | — | wordfence |
| 3762cd92-604a-4dac-a09e-6b4a08c4d804 | < 0.5.16 |
HIGH | 8.8 | The Duplicator plugin for WordPress is vulnerable to SQL Injection in versions up to and including 0.5.14 due to insuffi… | — | wordfence |
| 373e9a7c-cdc3-43cb-9c8f-2be25f514b61 | < 2.8.3 |
HIGH | 8.8 | The Visual Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence |
| 372a4550-c38e-46d6-b7f2-15e05708d128 | < 0.9.5 |
HIGH | 8.8 | The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 0.9.5. This is … | — | wordfence |
| 370a6130-425c-4264-baaf-8989d3b00d14 | < 4.8.5 |
HIGH | 8.8 | The MC4WP: Mailchimp for WordPress for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… | — | wordfence |
| 37052cb9-8479-4004-9161-65f37028ae10 | < 4.1.5 |
HIGH | 8.8 | The Bit File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| 3702218f-a5ad-4244-874f-53b49cc9491c | < 2.2.7 |
HIGH | 8.8 | The Social Share Buttons by Supsystic plugin for WordPress is vulnerable to SQL Injection via several unknown parameters… | — | wordfence |
| 36e83a33-63e7-4282-9b3c-282bd21830b7 | < 3.6.1.1 |
HIGH | 8.8 | The JetFormBuilder β Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all ver… | — | wordfence |
| 36e15052-0e04-4b72-b573-b736109517b8 | < 3.7.35 |
HIGH | 8.8 | wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to… | — | wordfence |
| 36d02d5f-d534-4567-9587-1f6e4b21ca90 | HIGH | 8.8 | Multiple cross-site request forgery (CSRF) vulnerabilities in the DVS Custom Notification plugin 1.0.1 and earlier for W… | — | wordfence | |
| 36ad7fe2-0dc9-427d-811b-8fb1fdb78579 | < 1.3.1 |
HIGH | 8.8 | The ARI Stream Quiz β WordPress Quizzes Builder plugin for WordPress is vulnerable to PHP Object Injection in all vers… | — | wordfence |
| 36abba4d-9a73-4ef2-a910-6030acddd182 | HIGH | 8.8 | The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the u… | — | wordfence | |
| 368cff00-6a86-443e-aec4-4115a229a3c1 | < 2.0.9 |
HIGH | 8.8 | The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up … | — | wordfence |
| 3624708c-b0da-4177-a8e8-cf5f5c432f97 | < 2.11.8 |
HIGH | 8.8 | The WP Debugging plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.11… | — | wordfence |
| 361e2d5c-4355-4e71-91aa-2c1bc6b6fb78 | < 21.3 |
HIGH | 8.8 | The "Frontend File Manager Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… | — | wordfence |
| 3608fce3-0869-4516-ae08-68108f733c37 | < 5.0.30 |
HIGH | 8.8 | The WordPress Menu Plugin β Superfly Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery … | — | wordfence |
| 3604aece-5e76-4e8e-9caf-f518d6001277 | < 1.93.1 (02-07-2025) |
HIGH | 8.8 | The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →