Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 201 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 1e1d008d-28a4-4827-8d25-158307382394 | HIGH | 8.8 | The Sinking Dropdowns plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence | |
| 1e18c00b-fd26-4ac3-adf8-fd52d139e33f | < 2.2.1 |
HIGH | 8.8 | The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to Privilege Escalat… | — | wordfence |
| 1df74d3d-b7c9-4cf8-b1a7-d2b0b4f706d2 | < 3.5.3 |
HIGH | 8.8 | The get_fb_likeboxes() function in the Popup Like box – Page Plugin WordPress plugin before 3.5.3 did not use whitelis… | — | wordfence |
| 1de36458-d7e5-43cf-af40-0fd7a6eea5bb | < 8.0.8 |
HIGH | 8.8 | The WP Support Plus Responsive Ticket System plugin for WordPress is vulnerable to arbitrary file uploads in versions up… | — | wordfence |
| 1dd928cb-5466-424e-a87a-3a9618edb56b | < 3.7.2 |
HIGH | 8.8 | The Phone Orders for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… | — | wordfence |
| 1da18430-1bd0-4f63-9e22-5d26de2be410 | < 1.0.7 |
HIGH | 8.8 | The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida… | — | wordfence |
| 1d92ce83-03de-4981-8d90-0b8d2a2d16ef | < 1.2.2 |
HIGH | 8.8 | The Core Control plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence |
| 1d79432d-7977-4279-ac69-8e9db682800e | < 3.2.6.8 |
HIGH | 8.8 | LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection | — | wordfence |
| 1d7440ae-f939-478c-8861-57020537dd44 | < 0.5.7 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in Attendance Manager 0.5.6 and earlier allows remote attackers to hijac… | — | wordfence |
| 1d17d3ce-2478-498b-8364-75d2449a9b58 | < 2.4.22 |
HIGH | 8.8 | The ad-inserter plugin before 2.4.22 for WordPress has remote code execution. | — | wordfence |
| 1d063d01-5f67-4c7f-ab71-01708456e82b | HIGH | 8.8 | The WPMK Ajax Finder WordPress plugin is vulnerable to Cross-Site Request Forgery via the createplugin_atf_admin_settin… | — | wordfence | |
| 1cf65f79-d386-4dd4-a360-b2f764dfaf19 | < 3.8.2 |
HIGH | 8.8 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insu… | — | wordfence |
| 1c703856-9519-4181-9312-dcf862840bd9 | < 4.2.153 |
HIGH | 8.8 | An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated atta… | — | wordfence |
| 1c507681-61e9-4bf0-8fe5-e2f401a7a8be | < 1.8.4.1 |
HIGH | 8.8 | The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8… | — | wordfence |
| 1c49f37f-62eb-40ce-9c9e-e7e8785fc114 | < 1.2.7 |
HIGH | 8.8 | The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in versions up to, an… | — | wordfence |
| 1c442d6b-a272-4fb1-8f8e-8cdda326be6d | HIGH | 8.8 | The Push Notifications for WordPress by PushAssist plugin for WordPress is vulnerable to arbitrary file uploads due to m… | — | wordfence | |
| 1c3247d1-c230-44f5-8151-355c2078f01b | HIGH | 8.8 | The School Management plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 93.0.… | — | wordfence | |
| 1c307340-2911-46b9-9c90-0a7ebad8a0e9 | < 1.12 |
HIGH | 8.8 | The Smash Balloon Social Photo Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … | — | wordfence |
| 1c22de8c-e6e1-4b85-8d9f-619e9f63129e | < 1.10.0 |
HIGH | 8.8 | The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion i… | — | wordfence |
| 1c2153f5-1c8b-4095-a0a8-849a7ee967c1 | HIGH | 8.8 | Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter. | — | wordfence | |
| 1c1ce474-ecce-4d21-b174-cb54a2441b2b | < 9.0.3 |
HIGH | 8.8 | The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Improper Privilege Management in v… | — | wordfence |
| 1c1c7ec9-d01f-433d-abec-dc2b6ff684c7 | < 2.9.5 |
HIGH | 8.8 | The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the re… | — | wordfence |
| 1c0f613e-5ee6-447c-b508-702627223979 | < 1.1.3 |
HIGH | 8.8 | The Login Widget for Ultimate Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and i… | — | wordfence |
| 1bebb24c-c141-4fcf-8288-9b8faaaf69c9 | < 2.1.13 |
HIGH | 8.8 | The Team Manager – WordPress Showcase Team Members plugin for WordPress is vulnerable to Local File Inclusion in all v… | — | wordfence |
| 1bdba04e-df4d-4094-877e-611d69e2e25d | < 2.9.4 |
HIGH | 8.8 | The Page Builder: KingComposer plugin for WordPress is vulnerable to authorization bypass in versions up to, and includi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →