Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 213 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 0153fb37-788e-42f2-9dfa-76418decf1f3 | < 1.2.0 |
HIGH | 8.8 | The TextBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 1.0.0 to 1.1.1. This is due… | — | wordfence |
| 014dcf08-1968-4a3f-a772-2248e65dfb07 | < 140219 |
HIGH | 8.8 | Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress… | — | wordfence |
| 010df788-42cf-4455-9f5f-b23d03905afb | < 1.9.15 |
HIGH | 8.8 | The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF. | — | wordfence |
| 00f9fd4b-4730-4fa5-80b2-00d97dc72b8e | HIGH | 8.8 | Multiple cross-site request forgery (CSRF) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactF… | — | wordfence | |
| 00f5812d-661e-4206-8c3d-127bc3d48961 | HIGH | 8.8 | The Woocommerce Tabs Plugin, Add Custom Product Tabs plugin for WordPress is vulnerable to Cross-Site Request Forgery in… | — | wordfence | |
| 00c44ede-326d-48f5-8c78-fe5d566018f3 | < 1.3.2 |
HIGH | 8.8 | The AWSM Team – Team Showcase Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to,… | — | wordfence |
| 00b24f2f-af29-4297-b253-3242dc56542f | < 1.6.8 |
HIGH | 8.8 | The Better Find and Replace plugin for WordPress is vulnerable to unauthorized Privilege Escalation due to a missing cap… | — | wordfence |
| 009a6ae4-e9b5-4199-be25-b60e06dc136b | < 4.1.6 |
HIGH | 8.8 | The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… | — | wordfence |
| 009899d4-4139-43ea-a7a1-dc3a1a9ea1e6 | HIGH | 8.8 | The Cross-Linker WordPress plugin through 3.0.1.9 does not have CSRF check in place when creating Cross-Links, which cou… | — | wordfence | |
| 005b56c7-55ae-4db0-9ab2-3e22bd8a08ae | < 4.9.2 |
HIGH | 8.8 | The Spiffy Calendar plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter among others in … | — | wordfence |
| 005a27c6-b9eb-466c-b0c3-ce52c25bb321 | < 2.6.1 |
HIGH | 8.8 | Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to… | — | wordfence |
| 005234f9-8ae2-455a-8dcd-5d29a6051270 | < 1.1.121 |
HIGH | 8.8 | The plugin Image Slider is vulnerable to SQL Injection via the post parameter in the function ewic_duplicate_slider in v… | — | wordfence |
| 004e7773-31b9-47e5-a26b-64e75b6b2f9d | HIGH | 8.8 | The Simple Code Insert Shortcode plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1… | — | wordfence | |
| 00243844-a2ec-42fd-84d9-03e89619e361 | < 1.9 |
HIGH | 8.8 | The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via the ‘orderby’ … | — | wordfence |
| 001c6260-fa3d-49e7-873e-a96c1d6a2e97 | < 0.0.7 |
HIGH | 8.8 | The Webenvo theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versi… | — | wordfence |
| 00086b84-c1ec-447a-a536-1c73eac1cc85 | HIGH | 8.8 | The MOLIE WordPress plugin through 0.5 does not validate and escape a post parameter before using in a SQL statement, le… | — | wordfence | |
| e830fe1e-1171-46da-8ee7-0a6654153f18 | < 4.0.2 |
HIGH | 8.7 | The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the L… | — | wordfence |
| d4da8ead-326f-4c93-b56d-8bfa643d7906 | < 2.13.5 |
HIGH | 8.7 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil… | — | wordfence |
| 69fd1068-4bbd-4e8a-9d35-5e9a072c72e1 | < 3.6.1 |
HIGH | 8.7 | The Relevanssi plugin for WordPress is vulnerable to generic SQL Injection via the ‘relevanssi_weight_’ parameter in… | — | wordfence |
| 5d94f38f-4b52-4b0d-800c-a6fca40bda3c | < 0.9.90 |
HIGH | 8.7 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Directory Traversal in versions up to, … | — | wordfence |
| 52c24f18-832b-4416-a148-a23e38b257e0 | < 2.79.2 |
HIGH | 8.7 | The WP-DBManager plugin for WordPress is vulnerable to Directory Traversal allowing arbitrary file deletion in versions … | — | wordfence |
| 364804a5-8699-46be-b25e-890a10134a25 | < 9.4.1 |
HIGH | 8.7 | The WP Statistics plugin for WordPress is vulnerable to blind SQL Injection via the ‘page-id’ parameter in versions … | — | wordfence |
| fe0def72-affb-4f42-8857-0e2b8b602c7f | HIGH | 8.6 | Directory traversal in the Media File Organizer (aka media-file-organizer) plugin 1.0.1 for WordPress lets an attacker g… | — | wordfence | |
| fdfb5e74-e52c-4f44-acdc-9740624af9e7 | < 3.2.5 |
HIGH | 8.6 | The Simple File List plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 3.2… | — | wordfence |
| eb7e4e96-a4ff-4c6c-91de-c0e5ba78f0da | < 2.0.1 |
HIGH | 8.6 | The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized ac… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →