Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 204 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 17240c75-4e2a-45d2-8114-414c7e81af87 | HIGH | 8.8 | The Dropshipping & Affiliation with Amazon plugin for WordPress is vulnerable to arbitrary file uploads due to missing f… | — | wordfence | |
| 1718f2eb-6235-498f-8c1e-402c1caf7d02 | < 2.2.20.2 |
HIGH | 8.8 | The Permalink Manager Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| 16e6dc49-5edf-4ce4-95c9-19ef04a77379 | < 1.8.2 |
HIGH | 8.8 | An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF. | — | wordfence |
| 16d0c7ad-e9d3-42c9-ac73-cc8184c9d60d | HIGH | 8.8 | The Restaurant Cafeteria theme for WordPress is vulnerable to unauthorized access due to a missing capability check on t… | — | wordfence | |
| 16bce371-b524-48eb-8537-3f9df802abd3 | < 4.4 |
HIGH | 8.8 | The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all vers… | — | wordfence |
| 16630c5a-802e-404a-b90b-be7b906345b0 | < 4.1.5.3 |
HIGH | 8.8 | The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered dur… | — | wordfence |
| 16569267-ab52-4b96-86f0-d37c470a3938 | < 2.4.7 |
HIGH | 8.8 | The Clone plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.6 via des… | — | wordfence |
| 1647ac13-d9d1-46ae-93e7-855f55160e03 | < 1.4.2 |
HIGH | 8.8 | The Organization chart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence |
| 1644c2c3-11fa-48d6-ad99-416f27df4483 | < 115 |
HIGH | 8.8 | The Simple URLs plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in versions up to, and incl… | — | wordfence |
| 1625a77d-bbca-4d18-ae6f-03030ac51d5b | < 1.9.6 |
HIGH | 8.8 | The Rich Reviews by Starfish WordPress plugin before 1.9.6 does not properly validate the orderby GET parameter of the p… | — | wordfence |
| 15cf34d8-256b-495e-9385-a5d526bfb335 | HIGH | 8.8 | The Addon Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on… | — | wordfence | |
| 15c11a0e-6185-4072-88c6-303090adf898 | < 2.0.77.3 |
HIGH | 8.8 | In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain ful… | — | wordfence |
| 15b86ae0-93f0-4035-80c3-b3a713077b32 | HIGH | 8.8 | The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settin… | — | wordfence | |
| 15a9718f-f877-4e33-8f7a-950791c4ca85 | < 2.34.0 |
HIGH | 8.8 | The ThemeREX Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.3… | — | wordfence |
| 156b955d-e978-4ff5-ab56-35af257b3199 | < 1.5.8 |
HIGH | 8.8 | The MailerLite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7.… | — | wordfence |
| 15681d8b-df7b-48c5-bba8-658baf9b9bf1 | HIGH | 8.8 | The Core Tweaks WP Setup WordPress plugin through 4.1 allows to bulk-set many settings in WordPress, including the admin… | — | wordfence | |
| 15654ff3-2e61-44d2-ae3f-4a353db320cb | < 3.0.1 |
HIGH | 8.8 | The Smush β Lazy Load Images, Optimize & Compress Images plugin for WordPress is vulnerable to deserialization of untr… | — | wordfence |
| 1523db36-fdc6-4a9d-bb2c-d9b28668a3fc | HIGH | 8.8 | The Realestate theme for WordPress is vulnerable to arbitrary file uploads via CSRF due to missing or incorrect nonce va… | — | wordfence | |
| 15178478-5208-4869-a9f0-07e8e11ef0d5 | < 2.4 |
HIGH | 8.8 | The Void Elementor Post Grid Addon for Elementor Page builder plugin for WordPress is vulnerable to Local File Inclusion… | — | wordfence |
| 150021d3-71bb-41c0-bb1c-5843e94ec0b6 | HIGH | 8.8 | The Quasar form plugin for WordPress is vulnerable to SQL Injection via the 'id' shortcode attribute in versions up to, … | — | wordfence | |
| 14f0df3e-4333-49d8-a318-6f9fa614c23e | < 1.3 |
HIGH | 8.8 | The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set… | — | wordfence |
| 14d81210-9360-4153-9b5a-35d12cc0cbf0 | < 1.2 |
HIGH | 8.8 | The user-access-manager plugin before 1.2 for WordPress has CSRF. | — | wordfence |
| 14d44753-fbfb-4538-b8ae-0e2a13b14c8e | HIGH | 8.8 | Multiple cross-site request forgery (CSRF) vulnerabilities in the CrossSlide jQuery (crossslide-jquery-plugin-for-wordpr… | — | wordfence | |
| 14ad420b-df09-48de-8e36-d8edf0647837 | < 2.11.6 |
HIGH | 8.8 | The Easy Digital Downloads WordPress plugin before version 2.11.6 does not have Cross-Site Request Forgery checks in pla… | — | wordfence |
| 149fbc16-c35d-4f4b-9bae-13c05451de54 | HIGH | 8.8 | The Crafts & Arts theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5 via de… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →