Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 206 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 121a3b46-0b31-4f28-b98e-fc06760548ae | < 1.10.0 |
HIGH | 8.8 | The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to time-based blind SQL Injection via the ‘d… | — | wordfence |
| 1200d2b3-2c1b-44a4-bf87-2d9b0121d6cb | HIGH | 8.8 | SQL Injection (SQLi) vulnerability in Don Crowther's 3xSocializer plugin <= 0.98.22 at WordPress possible for users with… | — | wordfence | |
| 11fd8768-0168-4e3b-9c2d-659fc4101a73 | < 4.0.5 |
HIGH | 8.8 | The MainWP Google Analytics Extension for WordPress are vulnerable to SQL Injection via an unknown parameter due to insu… | — | wordfence |
| 11d53df8-f7b3-467c-8b3a-515974f1ea69 | < 1.5.1.3 |
HIGH | 8.8 | SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitra… | — | wordfence |
| 11c369eb-7e5b-4fcf-a526-23466ebad420 | < 4.1 |
HIGH | 8.8 | SQL injection vulnerability in includes/mode-edit.php in the Simple Retail Menus (simple-retail-menus) plugin before 4.1… | — | wordfence |
| 11bb7190-023b-45e1-99a5-7313c489ef45 | < 1.1.9 |
HIGH | 8.8 | The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all ver… | — | wordfence |
| 11ba187b-1fe4-4077-ad9d-a07660133e91 | < 2.3.29 |
HIGH | 8.8 | The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and in… | — | wordfence |
| 11b5f0a1-bf22-46be-a165-c62f1077da0f | < 2.4.7 |
HIGH | 8.8 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions … | — | wordfence |
| 11aaec16-930d-44f6-abe5-4f7fdc32f252 | < 6.2.1 |
HIGH | 8.8 | The LayerSlider plugin for WordPress is vulnerable to Cross-Site Request forgery in versions up to, and including 6.2.0,… | — | wordfence |
| 115f966d-b0f4-46c0-af05-48dd5bf72098 | < 3.4.3.19 |
HIGH | 8.8 | The WP Shop plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting via the ‘w… | — | wordfence |
| 113dcd4d-e62f-44dc-8087-28d265ef66be | < 1.9.7 |
HIGH | 8.8 | The WPGlobus plugin 1.9.6 for WordPress has CSRF via wp-admin/options.php. | — | wordfence |
| 112e4abe-aac7-4fac-b03f-b998374846c4 | < 3.0.1 |
HIGH | 8.8 | The WP Custom Cursors plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence |
| 10e98088-423d-45bb-ae90-51e895d2929b | < 2.8.1.2 |
HIGH | 8.8 | The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to arbitrary file uploads due to mis… | — | wordfence |
| 10e49bdd-3a72-4bb7-ba31-21ba4a5b377f | < 4.8.76 |
HIGH | 8.8 | The SAML Single Sign On plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence |
| 10c65f72-a115-4340-8ed3-ac1e2ce014d2 | < 2.09 |
HIGH | 8.8 | The Green Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence |
| 10c1402d-613d-4d72-b488-c0af2bee4d59 | < 1.2 |
HIGH | 8.8 | The MathJax LaTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.2. This is due t… | — | wordfence |
| 10a36e37-4188-403f-9b17-d7e79b8b8a6d | < 2.6.0 |
HIGH | 8.8 | The String Locator plugin for WordPress is vulnerable to deserialization of untrusted input via the 'string-locator-path… | — | wordfence |
| 1091862b-784b-496f-a951-6784544cb51b | < 5.30.5 |
HIGH | 8.8 | The YARPP plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.30.4 via the ya… | — | wordfence |
| 107afaa6-6c0b-43fb-9713-ebc4f1189ea6 | < 3.2 |
HIGH | 8.8 | The Timeline Event History plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi… | — | wordfence |
| 107a0612-5e58-428b-a097-1c4012e89449 | HIGH | 8.8 | The ACF Images Search And Insert plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type v… | — | wordfence | |
| 10590944-e08e-4980-846d-7a88880b2dcd | < 4.13 |
HIGH | 8.8 | The Accessibility Suite by Online ADA plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… | — | wordfence |
| 1055bba0-7dbd-4382-afaf-ecea442c527c | < 12.7.0 |
HIGH | 8.8 | The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameter… | — | wordfence |
| 101edd24-3f9e-4055-8547-9cd7e2b626b5 | < 1.3.16 |
HIGH | 8.8 | The Invite Anyone plugin before 1.3.16 for WordPress has admin-panel CSRF. The plugin’s setting pages had a vulnerabil… | — | wordfence |
| 0ff3a292-3924-4823-867a-fedb2c1cdd00 | < 1.4.1.4 |
HIGH | 8.8 | Multiple plugins for WordPress with the Jewel Theme Recommended Plugins Library are vulnerable to Unrestricted Upload of… | — | wordfence |
| 0fee990a-8ac0-40a2-9f25-96defd62263d | < 6.3.10 |
HIGH | 8.8 | The Theme My Login plugin for WordPress is vulnerable to Local File Inclusion in versions before 6.3.10 via the login_te… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →