Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 197 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 27b9ff55-f2b4-4713-a39d-6f57ee4c229b | HIGH | 8.8 | The Simpolio - Fullscreen Portfolio & Blog HTML Theme theme for WordPress is vulnerable to arbitrary option updates due … | — | wordfence | |
| 27ac48a7-52ee-46cb-a6d0-efbd2b516445 | < 1.3.3 |
HIGH | 8.8 | The users-customers-import-export-for-wp-woocommerce plugin (and other Webtoffee plugins) before 1.3.9 for WordPress all… | — | wordfence |
| 279e6990-3423-437b-b484-34e80240218e | < 1.1.8.1 |
HIGH | 8.8 | The AI Image Generator for Your Content & Featured Images β AI Postpix plugin for WordPress is vulnerable to arbitrary… | — | wordfence |
| 2730a090-e1ae-4fd5-9873-9a15dfc1efd9 | < 4.7.6 |
HIGH | 8.8 | The PublishPress Authors plugin for WordPress is vulnerable to Local File Inclusion via the filterAuthorBoxHtml() functi… | — | wordfence |
| 272515e3-18ae-4e7f-8503-722d7964b3c2 | HIGH | 8.8 | The Web Invoice plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.3 due to insuf… | — | wordfence | |
| 26abf509-f0a9-4849-9028-d6c42832158f | < 2.3.5 |
HIGH | 8.8 | The BeeTeam368 Extensions Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu… | — | wordfence |
| 267d2b02-6365-4553-9809-bc3a8b070c7e | < 1.8.4.1 |
HIGH | 8.8 | The Content Mask WordPress plugin before 1.8.4.1 does not have authorisation and CSRF checks in various AJAX actions, as… | — | wordfence |
| 265be0af-66a4-4636-ab81-f8e2c5a1282e | < 2.1.7 |
HIGH | 8.8 | The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6… | — | wordfence |
| 2659d22f-3b54-4268-8618-b0c685278f6e | < 0.2.7 |
HIGH | 8.8 | The Extra Block Design, Style, CSS for ANY Gutenberg Blocks plugin for WordPress is vulnerable to Cross-Site Request For… | — | wordfence |
| 2657aa8a-b2de-4cb4-b9f8-e7fb0c887a7a | < 4.11.3.4 |
HIGH | 8.8 | The WooCommerce Affiliate Plugin β Coupon Affiliates plugin for WordPress is vulnerable to Cross-Site Request Forgery … | — | wordfence |
| 264cb002-bf40-4cc2-9c21-cda9bb24f494 | < 6.1 |
HIGH | 8.8 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi… | — | wordfence |
| 26399541-a6a7-4c01-b72c-1ebf73f18c84 | < 1.5.7 |
HIGH | 8.8 | The Store Toolkit for WooCommerce plugin for WordPress is vulnerable to missing authorization checks on the woo_st_admin… | — | wordfence |
| 2636efe7-20c4-4d12-ab2f-45035e8a1ca0 | HIGH | 8.8 | The Perfect Survey WordPress plugin before 1.5.2 does not have proper authorisation nor CSRF checks in the save_global_s… | — | wordfence | |
| 262db9aa-0db5-48cd-a85b-3e6302e88a42 | HIGH | 8.8 | The Google Maps made Simple plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions u… | — | wordfence | |
| 260f805a-8022-40f7-a2f4-1bbbf81c1e8b | < 2.0.1 |
HIGH | 8.8 | The Corpkit - Business Consulting WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to mis… | — | wordfence |
| 26050f70-7a10-4df5-acd5-1c9e7613bf2c | < 2.5.4 |
HIGH | 8.8 | The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to,… | — | wordfence |
| 25fab7b3-59ce-44ca-83fa-bd25b7f31af0 | HIGH | 8.8 | The "Follow Me Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence | |
| 25f71a19-85b1-4bc9-b193-d9de2eba81ee | < 1.5.91 |
HIGH | 8.8 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code… | — | wordfence |
| 25e9dbfd-a24e-400c-b926-051c1eb3643a | HIGH | 8.8 | The Theme File Duplicator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… | — | wordfence | |
| 25e4abf4-9869-436c-8fd3-9f59b2363ba7 | HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the twimp-wp plugin for WordPress allows remote attackers to hijack t… | — | wordfence | |
| 25b94c05-87c5-44fb-90d5-6c65d035dba6 | < 3.4.34 |
HIGH | 8.8 | The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it ha… | — | wordfence |
| 25affa52-13a7-4726-b02a-5af78afa8acf | < 4.0.1 |
HIGH | 8.8 | The WP-BusinessDirectory β Business directory plugin for WordPress plugin for WordPress is vulnerable to arbitrary fil… | — | wordfence |
| 25a25dae-578b-40d6-95c3-8428ca545ac3 | < 0.9.1 |
HIGH | 8.8 | The yet-another-stars-rating plugin before 0.9.1 for WordPress has yasr_get_multi_set_values_and_field SQL injection via… | — | wordfence |
| 25a05249-d899-429b-a7d3-c283c03a48a2 | < 13-07-2019 |
HIGH | 8.8 | Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter. | — | wordfence |
| 2577102f-6355-4483-bd3d-1948497cb843 | < 4.9.9.3 |
HIGH | 8.8 | The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →