Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 21 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| da807a8d-56de-494d-9f8a-9f749ab6c90e | < 1.8 |
CRITICAL | 9.8 | The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload via qquploader ajax file uploader. | — | wordfence |
| da760bcf-b252-4b88-9f54-af0a097e3295 | < 0.71 |
CRITICAL | 9.8 | PHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute a… | — | wordfence |
| da6eb803-3e2a-4ff1-9b93-6f109e8d0714 | < 7.8.2 |
CRITICAL | 9.8 | The RSVPMaker plugin for WordPress is vulnerable to SQL Injection via the 'event_count' parameter called via the 'signed… | — | wordfence |
| da590a65-8728-4577-b6e4-ecebc2a2277d | < 2.8 |
CRITICAL | 9.8 | The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeo… | — | wordfence |
| da525d8d-9a69-4bb3-821a-948646c4ee2b | < 1.7.1 |
CRITICAL | 9.8 | The CozyStay theme for WordPress is vulnerable to Local File Inclusion in versions up to 1.7.1. This makes it possible f… | — | wordfence |
| da51b3ef-b12f-4af0-90b7-1ea61595b661 | < 1.5.4 |
CRITICAL | 9.8 | The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in… | — | wordfence |
| da44b8d8-3f3f-4791-9f45-dee5e60f9bcc | CRITICAL | 9.8 | The Ach Invoice App plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.1. … | — | wordfence | |
| da3e3d6c-7643-4f22-aa88-2c4ce80aed1f | < 3.1.9 |
CRITICAL | 9.8 | The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via t… | — | wordfence |
| da36ba83-490e-4c9d-8a34-c5c79392a09a | < 3.9.8 |
CRITICAL | 9.8 | The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'product_id' parameter … | — | wordfence |
| da1d37f5-45d5-4775-a217-24fdb3b53da7 | < 2.0.14 |
CRITICAL | 9.8 | The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.p… | — | wordfence |
| da0f0e1a-bbf8-42a5-b330-b53134488ebd | < 1.0.4 |
CRITICAL | 9.8 | The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type … | — | wordfence |
| d9f6ef14-dc04-46da-b2fc-e84b91153bfe | CRITICAL | 9.8 | SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress al… | — | wordfence | |
| d98d1782-a6cc-403a-b0fa-43282daa1136 | < 2.5.9.1 |
CRITICAL | 9.8 | The DukaPress plugin for WordPress is vulnerable to blind SQL Injection via the ‘id’ parameter in the 'dukapress/dow… | — | wordfence |
| d96877a4-c5c0-429e-a7b8-03935c4b36fa | CRITICAL | 9.8 | The Opstore theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.5. This make… | — | wordfence | |
| d9450e6b-df5e-4265-a3df-08cb10eb8dc0 | CRITICAL | 9.8 | The Kiddo Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload… | — | wordfence | |
| d91a7cd4-929d-4df1-9557-ebd47e93c6e3 | < 5.1.8 |
CRITICAL | 9.8 | The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to privilege escalation via account … | — | wordfence |
| d8e849fb-76e0-427a-8e05-d340add1c150 | < 2.2.13.7 |
CRITICAL | 9.8 | Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.6 and earlier for WordPress… | — | wordfence |
| d8da513f-19b1-4ec4-b3ad-dc3a7bb6ab49 | < 2.6.6.0 |
CRITICAL | 9.8 | The SP Projects & Document Manager plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and in… | — | wordfence |
| d893edd0-8a60-43fd-94bb-3b52cea1d00e | < 3.0 |
CRITICAL | 9.8 | importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not reliably delete… | — | wordfence |
| d84b94b3-b4ef-400c-8d4c-6b52d839c239 | CRITICAL | 9.8 | The PSW Front-end Login & Registration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to… | — | wordfence | |
| d84ad258-8a0c-44b2-9897-03ad214e8493 | CRITICAL | 9.8 | The Barclaycart plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … | — | wordfence | |
| d818b467-a893-4f4f-b623-abff99ef37b4 | CRITICAL | 9.8 | The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via th… | — | wordfence | |
| d80ab1a4-19f9-4fea-87b4-1d2ba465e860 | < 1.7.3 |
CRITICAL | 9.8 | The Web Directory Free plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, … | — | wordfence |
| d7f024c5-80d8-490f-b448-9bccb877024b | < 1.1 |
CRITICAL | 9.8 | The Premium Courses & eLearning plugin for WordPress is vulnerable to SQL Injection via the ‘level_ids’ parameter in… | — | wordfence |
| d7eb5fad-bb62-4f0b-ad52-b16c3e442b62 | < 6.44 |
CRITICAL | 9.8 | The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →