Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 196 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2a0f9f80-e338-4afd-9a4b-e421865c8b0b | < 1.5.29 |
HIGH | 8.8 | The Page Builder: Live Composer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and in… | — | wordfence |
| 29e76d57-217f-4f21-8bc6-a86290783a19 | < 3.1.9.7 |
HIGH | 8.8 | The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and … | — | wordfence |
| 29e49f76-9769-41c9-aeed-9e2857ebbd25 | < 1.7.11 |
HIGH | 8.8 | The Coming Soon by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… | — | wordfence |
| 29da4c49-3608-4bff-8184-01dc08752403 | < 1.1.0 |
HIGH | 8.8 | The Fatcat Apps Analytics Cat plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… | — | wordfence |
| 29d72347-ba49-45c6-a964-2c75064ac866 | < 2.4 |
HIGH | 8.8 | The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path … | — | wordfence |
| 29c0fb4d-c38c-4c78-9e15-797f3c3a4b30 | < 2.7.2 |
HIGH | 8.8 | The FastDup β Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creat… | — | wordfence |
| 2984b9ca-e821-4c23-b792-4d0e54e44a7c | < 5.11.1 |
HIGH | 8.8 | The Business Directory Plugin β Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cr… | — | wordfence |
| 297c7411-5065-458c-8cad-4f6243610b8a | < 6.2.10 |
HIGH | 8.8 | The Advanced Custom Fields Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc… | — | wordfence |
| 29778d95-4859-4383-91c7-15e7907b825c | < 3.7.28 |
HIGH | 8.8 | In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted meta… | — | wordfence |
| 296f8a23-8223-4d9c-a238-d93fcd5abd87 | < 2.3.4 |
HIGH | 8.8 | The EazyDocs β Most Powerful Knowledge base, wiki, Documentation Builder Plugin (easy docs, knowledgebase) plugin for … | — | wordfence |
| 2954583e-4ebe-4658-b132-0085f2b1cf08 | < 1.0.15 |
HIGH | 8.8 | The Classified Pro theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability che… | — | wordfence |
| 293ac389-cc82-400c-ab50-8e53f00c925a | < 6.3 |
HIGH | 8.8 | The Display Eventbrite Events plugin for WordPress is vulnerable to Local File Inclusion via the 'layout' attribute in a… | — | wordfence |
| 29169235-03d3-43a7-9afd-ddfc1a486faf | < 1.6.7 |
HIGH | 8.8 | The Subaccounts for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all v… | — | wordfence |
| 29143d81-9134-4b0e-8540-5f37e5b08707 | < 5.3 |
HIGH | 8.8 | The Crossword Compiler Puzzles plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… | — | wordfence |
| 28e74811-aae8-4276-abb1-cbe4fbcfd08b | HIGH | 8.8 | A vulnerability was found in Global Content Blocks Plugin 2.1.5. It has been declared as problematic. This vulnerability… | — | wordfence | |
| 28e1a11b-5320-41be-bc78-580322e5f407 | < 2.10.16 |
HIGH | 8.8 | An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did … | — | wordfence |
| 28d3388e-0731-46b6-bf66-e7a1d98c321a | < 5.9 |
HIGH | 8.8 | Multiple SQL injection vulnerabilities in cs_admin_users.php in the wp-championship plugin 5.8 for WordPress allow remot… | — | wordfence |
| 28c3b377-4cab-4c17-adc3-6ce8b600b20a | HIGH | 8.8 | The Woo MerchantX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0… | — | wordfence | |
| 289c9759-f4d3-4b42-9f90-12ea43bbafad | < 4.1.14 |
HIGH | 8.8 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… | — | wordfence |
| 284b9b04-aa8f-41ff-b944-3488c5da8e20 | < 2.0.9 |
HIGH | 8.8 | The Listing, Classified Ads & Business Directory β uListing plugin for WordPress is vulnerable to Cross-Site Request F… | — | wordfence |
| 283c2b7b-b231-4a23-96be-776115676443 | < 2.6.5 |
HIGH | 8.8 | The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option. | — | wordfence |
| 28333161-9c76-4108-9256-9ffa91eaf818 | < 4.6.4 |
HIGH | 8.8 | The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms. | — | wordfence |
| 281c336e-7a1e-4106-ae79-b3b512b430ca | < 1.9.9.5.2 |
HIGH | 8.8 | The WPLMS plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versio… | — | wordfence |
| 2812b31d-11c0-4efe-95e2-ea713293dad1 | < 6.3.1 |
HIGH | 8.8 | Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Post… | — | wordfence |
| 27e40af7-5697-4482-a96d-9216886c363b | < 2.7.27 |
HIGH | 8.8 | The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →