Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 212 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 038d1144-81b8-4e4b-b0d5-60516f02dbdf | < 3.3 |
HIGH | 8.8 | The WP Airbnb Review Slider plugin for WordPress is vulnerable to SQL Injection via the $tid value in versions up to, an… | — | wordfence |
| 034e77ef-fb3f-4e62-be1b-c56c454c5ba8 | < 1.3.5.4 |
HIGH | 8.8 | The JivoChat Live Chat WordPress plugin before 1.3.5.4 does not properly check CSRF tokens on POST requests to the plugi… | — | wordfence |
| 0311b546-01a4-4be8-97f3-6df6cd79c3fe | HIGH | 8.8 | The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and '… | — | wordfence | |
| 02f941bd-c42d-49de-9af0-374db3ce22f3 | HIGH | 8.8 | The WP e-Commerce Style Email plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… | — | wordfence | |
| 02a6428f-beef-4491-ab5f-130a9e7924c2 | < 5.2.3 |
HIGH | 8.8 | The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is kn… | — | wordfence |
| 02a283b2-a369-4927-a54a-61f26bee6ace | < 9.1.0.6 |
HIGH | 8.8 | The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all v… | — | wordfence |
| 0295711d-5da6-4e28-9151-b0ce762c7eb7 | < 1.1.16 |
HIGH | 8.8 | The Free Booking Plugin for Hotels, Restaurant and Car Rental is vulnerable to arbitrary file uploads due to missing fil… | — | wordfence |
| 0279eb4e-36e1-4cdd-8afb-b3a71e2c726e | HIGH | 8.8 | The Buddypress Humanity plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence | |
| 02699ada-f4bf-45c4-89e8-018dfff40ac1 | < 2.0.4 |
HIGH | 8.8 | The Video Gallery and Youtube Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… | — | wordfence |
| 02551726-672d-481a-8b77-ec7bf33a22c1 | HIGH | 8.8 | The WP Booklet plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.1.8 due t… | — | wordfence | |
| 02540fe4-b690-46ab-b79b-a90c8d796ec4 | < 5.12.1 |
HIGH | 8.8 | The Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… | — | wordfence |
| 0238801b-310a-43f9-bcc3-5b572868fc4d | HIGH | 8.8 | The FunnelFormsPro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.8… | — | wordfence | |
| 02282e33-7e3e-42e1-a7b0-9b5ad326600d | < 17-07-2019 |
HIGH | 8.8 | Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter. | — | wordfence |
| 01f0b785-418e-468c-b9f8-53cd46aca881 | < 1.0.34 |
HIGH | 8.8 | The Mingle Forum plugin for WordPress is vulnerable to generic SQL Injection in versions up to 1.0.34 due to insufficien… | — | wordfence |
| 01f038d7-2efd-41b2-8f4c-77bab80d8e91 | < 1.6.1 |
HIGH | 8.8 | The peepso-core plugin before 1.6.1 for WordPress has PeepSoProfilePreferencesAjax->save() privilege escalation. | — | wordfence |
| 01d31d8a-4459-488a-9cbe-92761faa58b4 | < 9.1 |
HIGH | 8.8 | The Image vertical reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode … | — | wordfence |
| 01cc613a-d0b5-4c8f-8961-8f8aaf63b8ac | HIGH | 8.8 | The Intrepidity theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.1.… | — | wordfence | |
| 01c1dd65-4cf9-487f-ae3f-9cfaea177385 | < 3.7.0 |
HIGH | 8.8 | The Companion Sitemap Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … | — | wordfence |
| 01bb2c40-989f-46c4-84d3-c7b25a49a631 | HIGH | 8.8 | The FAT Services Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.… | — | wordfence | |
| 01ab2ed8-ff2f-41ac-bbbd-d8878fd067d6 | < 8.1.1 |
HIGH | 8.8 | The Recipe Maker For Your Food Blog from Zip Recipes plugin for WordPress is vulnerable to SQL Injection via the ‘orde… | — | wordfence |
| 01aa00db-43e5-4c8a-a005-77a39ec89c94 | < 1.2.6 |
HIGH | 8.8 | The MemberPress Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… | — | wordfence |
| 0195bddf-eafe-45f2-9424-ffa235d9b4dc | < 1.1.1 |
HIGH | 8.8 | The Elegant Themes Monarch plugin before 1.2.7 for WordPress has privilege escalation. | — | wordfence |
| 01943559-e05b-4dca-b322-d880b2729ee7 | < 7.5.5 |
HIGH | 8.8 | The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including,… | — | wordfence |
| 018912c2-befc-403c-8e60-161580e84f55 | < 1.2.0 |
HIGH | 8.8 | The Event Monster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1… | — | wordfence |
| 01762804-df33-4c4d-b8f6-d94a1e5b5fc9 | < 1.5.3.2 |
HIGH | 8.8 | The Slideshow Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →