Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 202 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 1bd45442-0614-4dd0-bffa-11de68233dd4 | HIGH | 8.8 | The Ultra Demo Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence | |
| 1bb409f0-ccbd-4dfa-b097-b29ee539daa3 | < 1.7.0 |
HIGH | 8.8 | The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and in… | — | wordfence |
| 1b948297-7ca1-4c5a-9ade-6b26e7bbcd62 | < 2.0.8 |
HIGH | 8.8 | The Miraculous Elementor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including… | — | wordfence |
| 1b631b92-b8fb-4f9b-ae2a-bbfd16440ebb | HIGH | 8.8 | The twitterDash plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. … | — | wordfence | |
| 1b36fc50-7573-466e-883e-8d26f243c4d0 | < 92.0.0 |
HIGH | 8.8 | The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing f… | — | wordfence |
| 1b2cf896-7cb8-4a1e-bd8c-4da339965138 | < 1.3.20 |
HIGH | 8.8 | The All Bootstrap Blocks plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.… | — | wordfence |
| 1b2ac807-c6e1-43de-8385-240ccae87e81 | HIGH | 8.8 | The Amazon Einzeltitellinks WordPress plugin through 1.3.3 does not have CSRF check in place when updating its settings,… | — | wordfence | |
| 1b29048e-cf06-463c-82e0-f1d973e50232 | < 1.35.15 |
HIGH | 8.8 | The Ultimate Addons for Beaver Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,… | — | wordfence |
| 1af5f7be-cfe2-4e0b-ae84-e44095644d84 | HIGH | 8.8 | The EFBP_verify_upload_file AJAX action of the Easy Form Builder WordPress plugin through 1.0, available to authenticate… | — | wordfence | |
| 1ab0d9f3-0185-41f1-bab5-f47f828fa79c | < 1.0.6 |
HIGH | 8.8 | The MiwoFTP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.6. Th… | — | wordfence |
| 1aa7d0c2-27ec-47ad-8baa-c281c273078e | < 2.7.31.2 |
HIGH | 8.8 | The Pods β Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all ve… | — | wordfence |
| 1aa7a7f9-f331-4d06-94ea-182535080a90 | < 4.6.19 |
HIGH | 8.8 | wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPres… | — | wordfence |
| 1a8b22b4-151c-4f42-a0a0-966dc5eb7a9d | HIGH | 8.8 | The PayGreen β Ancienne version plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… | — | wordfence | |
| 1a5f970a-e6a0-4dc7-8e99-342a32f5fd49 | < 0.3.6 |
HIGH | 8.8 | The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 … | — | wordfence |
| 1a20dc1d-eb7c-47ac-ad9a-ec4c0d5db62e | < 4.8.8 |
HIGH | 8.8 | The Jupiter X Core plugin for WordPress is vulnerable to Local File Inclusion to Remote Code Execution in all versions u… | — | wordfence |
| 1a14b86f-a5c8-4ec2-9940-68a37a6c4a86 | HIGH | 8.8 | The Unseen Blog theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 vi… | — | wordfence | |
| 19fe28c0-c0ef-49aa-91c1-2e273201babd | < 9.3.9 |
HIGH | 8.8 | The XStore theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a… | — | wordfence |
| 19eec720-a223-422c-8e39-298a5c27b866 | HIGH | 8.8 | The WP shop plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.6.0. Th… | — | wordfence | |
| 19c3d7dd-ccde-463c-abd9-f2c67961251a | HIGH | 8.8 | The iSpring Embedder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence | |
| 195f86a5-e3dc-4414-bbe3-dea312bf30a9 | < 2.0.1 |
HIGH | 8.8 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and incl… | — | wordfence |
| 193c9fe9-17bc-47e7-b93d-dfcebcf8004d | < 31.4 |
HIGH | 8.8 | The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability… | — | wordfence |
| 190edd82-840d-4468-8f5a-127cce049336 | < 1.6.4 |
HIGH | 8.8 | The YITH Request a Quote for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… | — | wordfence |
| 1900941d-cbb6-4384-977e-6c40f65b2789 | < 3.0.8 |
HIGH | 8.8 | The plugin My Private Site for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3… | — | wordfence |
| 18e8f72b-daa0-4a9f-a67b-d9be9a0862d2 | < 3.6.6 |
HIGH | 8.8 | The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.5. This… | — | wordfence |
| 18b9e6c0-f1c3-4ef5-b0da-671828508781 | HIGH | 8.8 | The B-Banner Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →