Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 215 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 2db8e79f-e70b-421f-8120-7aa65e704deb | < 1.0.5 |
HIGH | 8.6 | The MiwoFTP plugin for WordPress is vulnerable to Arbitrary File Download in versions before 1.0.5. This is due to the i… | — | wordfence |
| 27616d9e-c1eb-489f-ace7-76c0e5be2597 | < 2.05.03 |
HIGH | 8.6 | The Formidable Form Builder plugin for WordPress is vulnerable to SQL Injection via the ‘display-frm-data’ shortcode… | — | wordfence |
| 26e07115-efee-4db5-ba24-25a063286e90 | < 4.0.26 |
HIGH | 8.6 | The MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution plugin for WordPress is vulnerable to unau… | — | wordfence |
| 091dadcb-71ac-4321-b3aa-72b5fbbd9163 | HIGH | 8.6 | The TeploBot - Telegram Bot for WP plugin for WordPress is vulnerable to sensitive information disclosure due to missing… | — | wordfence | |
| 04e2f1f3-95c9-4a90-8c76-7b405a3815f7 | < 3.6.16 |
HIGH | 8.6 | The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 3.6.15… | — | wordfence |
| 04383919-dae0-4865-b0ff-88049f8cd4db | < 6.2.4 |
HIGH | 8.6 | The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP… | — | wordfence |
| fe7e6a53-36c3-41fc-bae8-a9e1de2494ad | < 1.5.3 |
HIGH | 8.5 | The Category Order and Taxonomy Terms Order plugin for WordPress is vulnerable to PHP Object Injection in versions up to… | — | wordfence |
| f96eb21c-7682-47e3-bd3a-37482d1bd37f | HIGH | 8.5 | The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creatin… | — | wordfence | |
| f1105dc3-222f-46a5-a9b1-74c11923f886 | < 2.2.10 |
HIGH | 8.5 | The Replyable plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.9 via des… | — | wordfence |
| e9c2a942-c14c-4b59-92a7-6946b2e4731b | < 1.8.4 |
HIGH | 8.5 | The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_con… | — | wordfence |
| bf70f652-5244-421c-8ee6-75719315ed64 | < 1.6.1 |
HIGH | 8.5 | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to SQL Injection via the 'acf7db' shortcode in version… | — | wordfence |
| b01ad77f-2349-48bb-b4e9-f7cbce435de9 | < 3.2.12 |
HIGH | 8.5 | The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Server-Side Reque… | — | wordfence |
| a859505e-87ba-49f0-910b-de6141976f86 | < 2.22 |
HIGH | 8.5 | The CMS Commander – Manage Multiple Sites plugin for WordPress is vulnerable to PHP Object Injection in versions up to… | — | wordfence |
| a54038e1-e9e4-48aa-b368-e8d9ec687e85 | HIGH | 8.5 | The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks… | — | wordfence | |
| 950a7cc8-c057-41ba-ae2c-e6393cd5a01b | < 1.6.2 |
HIGH | 8.5 | The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to SQL Injection in versions up to… | — | wordfence |
| 8de52b68-c273-4561-98b0-e51afd6cd47b | < 2.2.5 |
HIGH | 8.5 | The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in ve… | — | wordfence |
| 80064e3b-6996-49eb-a475-0ffe0e894f9e | < 1.11.30 |
HIGH | 8.5 | The Memberpress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and inclu… | — | wordfence |
| 70724bc7-c1f4-4965-8bba-99b2ed21d34b | < 4.4.4 |
HIGH | 8.5 | The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive Information Exposure in all… | — | wordfence |
| 66898509-a93c-4dc3-bf01-1743daaa0ff1 | < 1.9.2.2 |
HIGH | 8.5 | The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… | — | wordfence |
| 6417269d-3d49-4f33-b92a-5aacb052bab0 | < 3.6.3 |
HIGH | 8.5 | The ElementsKit PRO plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, … | — | wordfence |
| 5886128e-e72f-4d84-8c17-1ed4a0fcc17e | < 2.6.7 |
HIGH | 8.5 | The Spectra plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 2.6.6 vi… | — | wordfence |
| 55491c64-e4b5-4919-bdcb-7285f2a3c3cd | < 9.1.1 |
HIGH | 8.5 | The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode… | — | wordfence |
| 43b11ab0-c7f2-4a7a-aab7-7f9dd58ec1ab | < 7.11.2 |
HIGH | 8.5 | The Avada theme for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 7.11.1 via … | — | wordfence |
| 2e78c759-4a54-4ee4-8eff-df91fe9dad46 | < 1.2.13 |
HIGH | 8.5 | The WP Remote Users Sync plugin for WordPress is vulnerable to Server Side Request Forgery via the 'notify_ping_remote' … | — | wordfence |
| 196e629f-7c77-4bcb-8224-305a0108b630 | < 2.8.2 |
HIGH | 8.5 | The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check o… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →