Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 191 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 35f91088-3c52-4b32-abe8-94731d631f25 | < 1.3 |
HIGH | 8.8 | The Custom Fields Account Registration For Woocommerce plugin for WordPress is vulnerable to Privilege Escalation in all… | — | wordfence |
| 35e220c0-1e4d-4365-a1be-de66930fa559 | < 5.11 |
HIGH | 8.8 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cr… | — | wordfence |
| 35dadb9c-f0c6-4b74-bb31-5e9d504b3db5 | < 2.8.22 |
HIGH | 8.8 | The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via multiple parameters in the 'get_logs' fun… | — | wordfence |
| 35d80441-6cbe-4bd4-a891-a4a1d24c77ec | < 1.3.0 |
HIGH | 8.8 | The Easy Media Gallery Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| 35afef52-350c-4b61-b9c0-3ae2572f81fb | < 2.9.3 |
HIGH | 8.8 | The Folders plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the hand… | — | wordfence |
| 3590277a-3319-4707-b728-d75ea59e8ad9 | < 3.0.2 |
HIGH | 8.8 | The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1… | — | wordfence |
| 358c0068-efd5-4bc8-9853-22fefdd9d76b | HIGH | 8.8 | The Portfolleo plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all v… | — | wordfence | |
| 357257df-123d-4885-ad48-ff38ce29eeb3 | < 2.8.7 |
HIGH | 8.8 | The Smooth Slider plugin through 2.8.6 for WordPress has SQL Injection via smooth-slider.php (trid parameter). | — | wordfence |
| 3566d9fa-faeb-4302-96e2-464a68eff66d | < 2.7 |
HIGH | 8.8 | The Smooth Slider plugin before 2.7 for WordPress has SQL Injection via the wp-admin/admin.php?page=smooth-slider-admin … | — | wordfence |
| 3566b602-c991-488f-9de2-57236c4735b5 | < 1.8.1 |
HIGH | 8.8 | The iPanorama 360 – WordPress Virtual Tour Builder plugin for WordPress is vulnerable to SQL Injection via the plugin'… | — | wordfence |
| 3566292a-91c8-4cb9-a1d3-45669d69bfc3 | HIGH | 8.8 | The Q and A plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.6.2. T… | — | wordfence | |
| 353c3cd9-5ada-466b-b8e5-d40e0ec4e867 | < 3.24.2 |
HIGH | 8.8 | The Thrive Theme Builder theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions prior to 3.24.2… | — | wordfence |
| 3538f5df-fd70-454d-87b0-08028dcbe449 | HIGH | 8.8 | The Banner System plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.0… | — | wordfence | |
| 3513ec24-0b1b-4528-9f89-eee5654e4e98 | < 3.3.44 |
HIGH | 8.8 | The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in a… | — | wordfence |
| 3503c7bf-5e96-4033-89c1-b7c13c5489d2 | HIGH | 8.8 | The WPlite WordPress plugin through 1.3.1 does not have CSRF check in place when updating its settings, which could allo… | — | wordfence | |
| 34e31a0f-27de-4536-9a7e-b8f68e557b3f | HIGH | 8.8 | The Quick Post Duplicator for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to… | — | wordfence | |
| 34da0e53-70d0-49ea-be7c-c2f610467172 | HIGH | 8.8 | The MDJM Event Management plugin for WordPress is vulnerable to privilege escalation via account takeover in all version… | — | wordfence | |
| 34d8ecee-ad52-47cd-ac78-4a82aa2ff58a | < 1.5.4 |
HIGH | 8.8 | SQL injection vulnerability in models/Cart66Ajax.php in the Cart66 Lite plugin before 1.5.4 for WordPress allows remote … | — | wordfence |
| 349d960b-cc62-47c6-b0d5-a199e1e679db | < 1.8.2.1 |
HIGH | 8.8 | The Frisbii Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.8.2. … | — | wordfence |
| 349cada2-8154-4429-a47a-1837581da1dc | < 3.2.8 |
HIGH | 8.8 | The Admin Custom Login WordPress plugin is vulnerable to Cross-Site Request Forgery due to the loginbgSave action found … | — | wordfence |
| 3469ba0d-8ef3-41d0-becb-cf2eb43758f1 | < 1.0.7 |
HIGH | 8.8 | The Stetic WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the stats_pa… | — | wordfence |
| 344b2f80-ea86-4bf0-8ee4-4b5c7b94c34b | < 1.3.5 |
HIGH | 8.8 | The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code exe… | — | wordfence |
| 342b2e81-fb26-416a-8f3d-4bc221260228 | < 1.14.6.1 |
HIGH | 8.8 | The Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization. | — | wordfence |
| 342a4482-f5d3-4cc9-a998-e3abac7142cf | < 4.0.1 |
HIGH | 8.8 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… | — | wordfence |
| 342049e5-834e-4867-8174-01ca7bb0caa2 | < 5.9.14 |
HIGH | 8.8 | The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →