Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 20 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| dd75b8ec-1961-4a7a-92e6-1517e638974b | CRITICAL | 9.8 | The Simple User Capabilities plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability chec… | — | wordfence | |
| dd5b0c3a-0dd0-440f-b3a5-6d80f70e0f7c | < 2.4.0 |
CRITICAL | 9.8 | The Zingiri Web Shop plugin for WordPress has multiple vulnerabilities in versions up to, and including, 2.3.7. This is … | — | wordfence |
| dd58a528-4c01-407d-b3f9-99c0817e9820 | CRITICAL | 9.8 | The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_to… | — | wordfence | |
| dd2d82f4-1493-4829-a4e9-adbb98301324 | CRITICAL | 9.8 | The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL sta… | — | wordfence | |
| dcfd8c4d-d48b-468d-a7d5-1ec05b068f79 | CRITICAL | 9.8 | The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, … | — | wordfence | |
| dcea4ecf-e690-4d1f-beab-fbb30c5bb52e | < 2.0.1 |
CRITICAL | 9.8 | An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers… | — | wordfence |
| dc83b0ff-7228-466a-b831-53cca252a3f3 | < 1.9.3 |
CRITICAL | 9.8 | PHP remote file inclusion vulnerability in template/album.php in DM Albums 1.9.2, as used standalone or as a WordPress p… | — | wordfence |
| dc7f5751-5c95-4105-b2a6-592d11d46ac6 | < 2.2.1 |
CRITICAL | 9.8 | The CE21 Suite plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.0. T… | — | wordfence |
| dc57d762-1e26-4980-ac82-ba35bf252ef8 | < 1.1.0 |
CRITICAL | 9.8 | The Demo My WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1… | — | wordfence |
| dc3555b6-9b5d-4fed-9d99-9f69f0566b99 | CRITICAL | 9.8 | The Sudan Payment Gateway for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… | — | wordfence | |
| dc3457a5-3d5b-40dc-b9b1-e819187c4d99 | < 1.40.1 |
CRITICAL | 9.8 | The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 d… | — | wordfence |
| dc1e5fb7-92d0-4e7f-9b1b-15673e3b852a | < 2.7.4 |
CRITICAL | 9.8 | The Gravity Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.7.3 via… | — | wordfence |
| dc02768c-3ea1-4254-a652-342d0abdf839 | < 2.4.1 |
CRITICAL | 9.8 | The Dør theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4. This makes it … | — | wordfence |
| dbfc52a4-6c9d-480b-9247-1513318ff84b | CRITICAL | 9.8 | The Contact form 7 Custom validation plugin for WordPress is vulnerable toSQL Injection via the 'post' parameter in vers… | — | wordfence | |
| dbadc2e6-38fa-47f8-9d8b-79fb867f1003 | < 5.6.0 |
CRITICAL | 9.8 | The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Privilege… | — | wordfence |
| db9819c4-e000-4113-a613-7510fce923c9 | < 8.1.7 |
CRITICAL | 9.8 | The search-everything plugin before 8.1.7 for WordPress has SQL injection related to WordPress 4.7.x, a different vulner… | — | wordfence |
| db7234a1-e888-454d-8a1c-4de19c4cbec4 | < 2.0.1 |
CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in the getip function in wp-limit-login-attempts.php in the WP Limit Login Attemp… | — | wordfence |
| db30acd7-ce51-45d9-8ff0-6ceea8237a8c | < 2.1.33 |
CRITICAL | 9.8 | The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32… | — | wordfence |
| db1c581b-5cc9-46c0-ba5d-605642697729 | CRITICAL | 9.8 | The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up … | — | wordfence | |
| dac658b5-4253-4095-9fda-4d3cdc7f7e2e | < 0.4.2 |
CRITICAL | 9.8 | The CDN Vote plugin for WordPress is vulnerable to SQL Injection via the 'cdnvote_post_id' and 'cdnvote_point' parameter… | — | wordfence |
| dabd12b9-c07d-4a5d-bec3-905b90ff0dbf | CRITICAL | 9.8 | The Fontsy plugin for WordPress is vulnerable to SQL Injection via many parameters, such as 'id' called via get_fonts() … | — | wordfence | |
| dab7e451-f2ea-4f41-8e38-a2a983ccb18b | < 6.9 |
CRITICAL | 9.8 | The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra… | — | wordfence |
| da95e282-54b9-4296-99f3-9187c04dcaac | < 1.5.8 |
CRITICAL | 9.8 | The Leaflet Maps Marker Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… | — | wordfence |
| da95086a-6ae2-4b4d-8312-78e3800ded7f | < 2015.0514 |
CRITICAL | 9.8 | SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for W… | — | wordfence |
| da86d422-f0ef-439b-ae67-6cb9699073e0 | < 3.0.18 |
CRITICAL | 9.8 | The Wawp OTP Verification, Order Notifications, and Country Code Selector for WooCommerce plugin for WordPress is vulner… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →