Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 211 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 0638c8f3-070a-4b42-ba58-396f3f259b9d | < 1.2.1 |
HIGH | 8.8 | The Responsive Owl Carousel for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up … | — | wordfence |
| 05ce62ce-a02f-431e-95b1-ade38988e3ad | < 3.31.0 |
HIGH | 8.8 | The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … | — | wordfence |
| 0593c20d-3422-4817-9639-614254b609db | < 3.5.0 |
HIGH | 8.8 | The AI Engine β The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalati… | — | wordfence |
| 057abffb-1c52-49ca-8791-ca44f0c5a011 | < 4.0.3 |
HIGH | 8.8 | The Streamit theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i… | — | wordfence |
| 05481984-7c18-4ec7-8d7c-831809c3e86b | < 8.2.0 |
HIGH | 8.8 | Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability … | — | wordfence |
| 05448e64-6179-4409-a197-7cdc3c4f1563 | < 0.81 |
HIGH | 8.8 | The DrawBlog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 0.81. This is due to mi… | — | wordfence |
| 0542f8bf-8fb1-4c47-89b7-106a6feacca1 | < 1.1.3 |
HIGH | 8.8 | The WP Mail Log plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … | — | wordfence |
| 053d374e-68b2-4d48-af6d-45087d5ce211 | HIGH | 8.8 | The Webriti SMTP Mail WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which c… | — | wordfence | |
| 0534bc03-5d7d-47fe-9c07-c9a61af38df2 | < 0.72 |
HIGH | 8.8 | SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary … | — | wordfence |
| 0531ca34-5d7b-4071-a1aa-934f14b87728 | < 8.2 |
HIGH | 8.8 | The Jquery accordion slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in version… | — | wordfence |
| 052dce55-c02d-4e66-b500-bf6160a5b188 | < 4.8 |
HIGH | 8.8 | The demon image annotation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… | — | wordfence |
| 051a3967-ef86-49bc-b72c-23e43568fef6 | < 7.0.19 |
HIGH | 8.8 | The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in version… | — | wordfence |
| 0509aaf1-8aae-42e5-84d3-ea9b431703f3 | < 1.2.0 |
HIGH | 8.8 | The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin… | — | wordfence |
| 04e64fe3-6502-4303-b1f1-1bd62ca00a9c | < 8.7.4 |
HIGH | 8.8 | The MapSVG β Vector maps, Image maps, Google Maps plugin for WordPress is vulnerable to arbitrary file uploads due to … | — | wordfence |
| 04bdc2ef-a7aa-45a7-b600-be832eefa32e | < 5.10.4 |
HIGH | 8.8 | The Better Click To Tweet plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence |
| 04af8675-1b1e-4f17-9eaf-87b49d8702e4 | < 3.5.6.2 |
HIGH | 8.8 | The JetFormBuilder β Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Remote Code Execution in all ve… | — | wordfence |
| 048e266f-5de5-4bcf-96ae-5c6ff969c5f7 | < 1.1.4 |
HIGH | 8.8 | The aThemes Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inclu… | — | wordfence |
| 046fde5c-9f11-4f09-a4eb-83c289680a18 | < 1.5 |
HIGH | 8.8 | The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unite… | — | wordfence |
| 046f11b6-7d1a-4bd3-8250-4c5a50fab3ff | HIGH | 8.8 | The Default Thumbnail Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… | — | wordfence | |
| 045fbe5b-0e63-4820-97a7-017dd72eb73a | < 3.2.20 |
HIGH | 8.8 | The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery … | — | wordfence |
| 0459d852-4d6b-4457-ad8d-47a3cddded8b | < 1.4.4 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the wpcr_do_options_page function in WP Comment Remix plugin before 1… | — | wordfence |
| 043f5052-6606-4f0e-a6f2-d7276eb50106 | < 1.13 |
HIGH | 8.8 | The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page. | — | wordfence |
| 043e8bd1-37e8-422d-98df-606dc17a6db7 | HIGH | 8.8 | The Auto Login using a secure tokenized url. Role wise login restriction. plugin for WordPress is vulnerable to privileg… | — | wordfence | |
| 041c4d44-28ee-49a4-8407-367ad2960cf6 | < 1.3.4 |
HIGH | 8.8 | The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do… | — | wordfence |
| 039b7dcc-fad6-4bc1-b0f9-7e888eb54412 | < 1.7.2 |
HIGH | 8.8 | The Visual Email Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and inc… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →