Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 2 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 9b41efbd-bd47-415f-8de7-f30b3a7cf326 | CRITICAL | 10.0 | The Imperial Fairytale Theme for WordPress is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal i… | — | wordfence | |
| 99746867-597b-49df-aa9e-548456a58542 | CRITICAL | 10.0 | The Photocrati Theme for WordPress is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in all ve… | — | wordfence | |
| 98cf2a10-cc53-4479-87d1-71489f6a8c51 | < 3.5.3 |
CRITICAL | 10.0 | The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 v… | — | wordfence |
| 971d40d2-428f-49d9-8918-89843980f177 | < 1.0.4 |
CRITICAL | 10.0 | The TrueBooker β Appointment Booking and Scheduler Plugin. plugin for WordPress is vulnerable to SQL Injection in all … | — | wordfence |
| 93e2d007-8157-42c5-92ad-704dc80749a3 | < 3.14.2 |
CRITICAL | 10.0 | The GiveWP β Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in al… | — | wordfence |
| 929fd4e6-9040-41cb-98f0-0cfdd80caf42 | < 9.5.1 |
CRITICAL | 10.0 | The Salon booking system plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… | — | wordfence |
| 8df5c412-e995-411f-94a9-afd7f9941125 | < 6.9.8 |
CRITICAL | 10.0 | The Super Store Finder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.9.7 due t… | — | wordfence |
| 82802e80-efb5-4aa3-9fea-9c21bfb71efa | < 2.9 |
CRITICAL | 10.0 | The Real3D Flipbook plugin for WordPress is vulnerable to Unauthenticated File or Directory Delete in versions up to, an… | — | wordfence |
| 813821c8-a9f9-408e-b85e-1c24d90f5e4a | < 16.26.6 |
CRITICAL | 10.0 | The WP-Recall β Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection in all vers… | — | wordfence |
| 7dbf982f-c83f-4980-b758-9e241e0de67b | CRITICAL | 10.0 | The Customify Site Library plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includ… | — | wordfence | |
| 7b57e750-71ec-4c52-999b-6c14a78c3bff | < 1.4.5 |
CRITICAL | 10.0 | The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion … | — | wordfence |
| 7887e0a6-53bf-49c7-a7a6-7c65cec28cae | CRITICAL | 10.0 | The RocketTheme's Refraction Theme is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in versio… | — | wordfence | |
| 76dc5fc0-adb9-401c-ab50-e0cb23a88fa3 | < 2.9.5 |
CRITICAL | 10.0 | The ListingPro theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.4 due to insuffi… | — | wordfence |
| 71782003-3fbf-44d3-a5fd-7370acff2eea | < 6.6.9 |
CRITICAL | 10.0 | The PayPlus Payment Gateway plugin for WordPress is vulnerable SQL Injection in all versions up to, and including, 6.6.8… | — | wordfence |
| 712887d9-25fd-4d8f-a2e6-e6f2855f5ddb | CRITICAL | 10.0 | The Music theme for WordPress is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in all known v… | — | wordfence | |
| 683cc327-e17e-49f6-a903-f8a40bb832d1 | < 9.3.9 |
CRITICAL | 10.0 | The XStore theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.3.8 due to insufficien… | — | wordfence |
| 6827dc47-669c-41de-8716-7932ce8e5259 | CRITICAL | 10.0 | The Revy plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all version… | — | wordfence | |
| 659fcb95-9041-443e-9b75-0d2f8c6108aa | < 5.8.0 |
CRITICAL | 10.0 | The WP Travel Engine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.9 due to … | — | wordfence |
| 6598d171-e68c-4d2f-9cd1-f1574fa90433 | < 1.4.5 |
CRITICAL | 10.0 | The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1… | — | wordfence |
| 5fc5fb44-8264-46b7-9486-f145d6cbfde2 | < 3.2.16 |
CRITICAL | 10.0 | The Cost Calculator Builder plugin for WordPress is vulnerable to SQL Injection via discount codes in versions up to, an… | — | wordfence |
| 5f800156-1ccc-431f-9b2b-3b2ba3428bbc | < 4.14.8 |
CRITICAL | 10.0 | The Realtyna Organic IDX plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.… | — | wordfence |
| 5baec449-59f9-47f3-af80-eb31adeacb7a | < 0.2.42 |
CRITICAL | 10.0 | The ActiveDEMAND plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… | — | wordfence |
| 5a3e2d1c-8879-4def-8861-3d6d8b683b7e | < 2.7.4 |
CRITICAL | 10.0 | The BuddyPress plugin for WordPress is vulnerable to Arbitrary File Deletion in versions 2.0 - 2.7.3. This allows unauth… | — | wordfence |
| 5931ad4e-7de3-41ac-b783-f7e58aaef569 | < 2.1.1 |
CRITICAL | 10.0 | The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/r… | — | wordfence |
| 56d24bc8-4a1a-4e60-aec5-960703a6058a | < 1.6.4 |
CRITICAL | 10.0 | Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A m… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →