Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 216 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 02b61eb1-a93f-4437-87de-d698af8ef9f6 | < 6.9.4 |
HIGH | 8.5 | The Blog2Social plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including 6.9.3 due to… | — | wordfence |
| 00bf8f2f-6ab4-4430-800b-5b97abe7589e | < 7.13.0 |
HIGH | 8.5 | The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and … | — | wordfence |
| 39b6a1c7-2f8a-49e9-8807-a53a25524018 | < 2.9.28 |
HIGH | 8.4 | The Ninja Forms Contact Form plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.9.2… | — | wordfence |
| ffa90aae-c512-4e7f-a041-e3e41cb8a1d8 | < 3.5.5 |
HIGH | 8.3 | The Count per Day plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.… | — | wordfence |
| fd4ac2b0-120a-4e68-bf8d-e039336fe9dc | < 3.7.17 |
HIGH | 8.3 | wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed… | — | wordfence |
| fc9cb292-94cb-4d1e-a0b7-98856db7c28e | < 1.10.8 |
HIGH | 8.3 | The Merge + Minify + Refresh plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… | — | wordfence |
| fb534d86-c477-4a9c-b048-2fbc002168b2 | < 2.7 |
HIGH | 8.3 | The module cerdic/csstidy, which is used in several plugins, is vulnerable to Server-Side Request Forgery due to the inc… | — | wordfence |
| f83f878d-b708-4677-929a-e1ced535d99f | < 3.4.5 |
HIGH | 8.3 | The MainWP Child plugin for WordPress is vulnerable to authentication bypass due to insufficient validation on the check… | — | wordfence |
| f6f26854-7e25-4e64-9f03-916ece6fde03 | HIGH | 8.3 | The ZD YouTube FLV Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and i… | — | wordfence | |
| f53cd4a3-a6db-42c2-b4d8-218071c4bcd4 | < 1.0.13 |
HIGH | 8.3 | The Premmerce User Roles plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to… | — | wordfence |
| f1ef067b-e4b4-4174-b6ff-ec94a7afd55d | < 3.8.2 |
HIGH | 8.3 | The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail… | — | wordfence |
| ef1468eb-9b98-4d45-b357-70998ba17de7 | < 0.8.24 |
HIGH | 8.3 | The UpdraftCentral Dashboard plugin 0.8.23 for WordPress is vulnerable to Server-Side Request Forgery via the font param… | — | wordfence |
| ed08d248-7467-4a3b-91a2-4286d91b9c50 | HIGH | 8.3 | The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions … | — | wordfence | |
| ebcbeb7c-eadb-4541-94f0-6e85f7f3e6a1 | HIGH | 8.3 | The Homepage SlideShow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence | |
| e92f35dc-7e19-464a-bb8a-40a662e2270a | < 3.8.14.4 |
HIGH | 8.3 | The WP eCommerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various … | — | wordfence |
| e51e1cd2-6de9-4820-8bba-1c6b5053e2c1 | < 1.0.1 |
HIGH | 8.3 | The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This… | — | wordfence |
| ddb97db0-cbf3-42be-a5c7-12fc2a2bc9e8 | HIGH | 8.3 | The WP Lead Plus X plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.… | — | wordfence | |
| dbc98f55-a8f9-4234-84aa-df38302bf0b8 | < 3.0.3 |
HIGH | 8.3 | The WooCommerce Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… | — | wordfence |
| d5d23fdc-081a-4228-897f-2470a9327887 | < 1.3.7 |
HIGH | 8.3 | The WooCommerce AJAX Product Filters plugin for WordPress is vulnerable to Arbitrary Settings Update in versions up to, … | — | wordfence |
| d2a99b86-5eb8-438d-a040-68aba2ffa183 | < 2.3.9 |
HIGH | 8.3 | The Request a Quote WordPress plugin through 2.3.8 does not validate uploaded CSV files, allowing unauthenticated users … | — | wordfence |
| ccd85a72-1872-4c4f-8ba7-7f91b0b37d4a | < 3.3.1 |
HIGH | 8.3 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to CSV injection in versions up to, and in… | — | wordfence |
| c824823c-68d0-4f41-ac22-c517763357eb | < 2.7.8.6 |
HIGH | 8.3 | The Traveler β Travel Booking WordPress Theme for WordPress is vulnerable to both Reflected and Stored Cross-Site Scri… | — | wordfence |
| c03cf3a2-3be9-44da-a050-a5978eb3eadc | < 2.0.1 |
HIGH | 8.3 | The Canto plugin 1.9.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker to make a … | — | wordfence |
| bb85341a-0253-41b2-992e-9202cb3e0f2d | < 1.6 |
HIGH | 8.3 | SQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administ… | — | wordfence |
| ad3de7e6-a080-4ce8-aa27-21e7f8fdb2c7 | < 3.6.2 |
HIGH | 8.3 | The Fusion Builder plugin for WordPress, an Avada theme core plugin, is vulnerable to Server-Side Request Forgery in ver… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →