Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 22 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d7d6d15c-067f-44cb-bd61-ff39bed7e356 | < 4.9.28 |
CRITICAL | 9.8 | The UserPro plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 4.9.27. This ma… | — | wordfence |
| d7c94c68-bf3c-49b0-b7eb-39374c6002aa | CRITICAL | 9.8 | The Edit Comments WordPress plugin through 0.3 does not sanitise, validate or escape the jal_edit_comments GET parameter… | — | wordfence | |
| d792be47-bbca-4d94-95b3-194acf3f57b3 | CRITICAL | 9.8 | The Background animation blocks plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… | — | wordfence | |
| d748e0f8-fe00-4751-9c24-561fd27e62c3 | < 1.8.4 |
CRITICAL | 9.8 | The WooCommerce β Store Exporter plugin for WordPress is vulnerable to authorization bypass due to a missing capabilit… | — | wordfence |
| d73ca391-97a3-4701-8429-e73f5914e65e | < 1.26 |
CRITICAL | 9.8 | The RokStories plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '… | — | wordfence |
| d7261e93-2341-4e14-a9b3-8fec295f6cde | < 3.5.1.36 |
CRITICAL | 9.8 | The Smart Slider 3 Pro plugin for WordPress contains a malicious backdoor in version 3.5.1.35. This is due to a supply c… | — | wordfence |
| d722ec8d-bfca-4da1-8eb0-8d33735c5e44 | CRITICAL | 9.8 | The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,… | — | wordfence | |
| d7140a6e-a528-428e-850e-5e4a481c5d7d | < 4.8 |
CRITICAL | 9.8 | The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7. … | — | wordfence |
| d6f68904-e575-457d-9040-c791b645e6c8 | < 1.35.1 |
CRITICAL | 9.8 | The WP Property plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … | — | wordfence |
| d6d6391a-542a-41c1-8eec-07ad5e77abdd | < 0.7.9 |
CRITICAL | 9.8 | The Restaurant Zone theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in a… | — | wordfence |
| d6b6d824-51d3-4da9-a39a-b957368df4dc | < 3.2.6 |
CRITICAL | 9.8 | The MasterStudy LMS WordPress Plugin β for Online Courses and Education plugin for WordPress is vulnerable to union ba… | — | wordfence |
| d6ac2996-098f-474c-b44e-78d5af7b503a | < 3.5.4 |
CRITICAL | 9.8 | The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 … | — | wordfence |
| d6a4872e-0f62-44b1-b77e-0817b065980f | < 2.98 |
CRITICAL | 9.8 | The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay… | — | wordfence |
| d68d2144-96b9-482e-9791-c3506661596e | < 2.0.6 |
CRITICAL | 9.8 | The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'city' parameter when conducting job searc… | — | wordfence |
| d68a2b60-ee89-4231-b256-214eba418244 | < 3.3.1 |
CRITICAL | 9.8 | The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3… | — | wordfence |
| d6686b67-8648-4f1b-8e05-fa67db60c8aa | < 12.5 |
CRITICAL | 9.8 | The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to arbitrary … | — | wordfence |
| d6226ae5-3b75-4521-b060-004f291203c7 | < 5.5.3.7 |
CRITICAL | 9.8 | SQL injection vulnerability in the WatuPRO plugin before 5.5.3.7 for WordPress allows remote attackers to execute arbitr… | — | wordfence |
| d5c0c64c-7105-4bc3-b42d-89cfa44d02b9 | < 2.2 |
CRITICAL | 9.8 | The ChurcHope theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1 via the 'f… | — | wordfence |
| d5bf199d-5607-48d5-adcd-211ded2087d4 | CRITICAL | 9.8 | The JP Students Result Management System Premium plugin for WordPress is vulnerable to arbitrary file uploads due to mis… | — | wordfence | |
| d5b695d7-c690-4748-b218-5699d1aa63bf | < 2.0.0 |
CRITICAL | 9.8 | The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension … | — | wordfence |
| d5ab090c-14fd-4d58-a915-fd68e5eaefe1 | < 1.1.9 |
CRITICAL | 9.8 | Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.9 for WordPress allows remote… | — | wordfence |
| d590e730-ad5f-4046-b897-c3b8aed250b3 | < 6.0.7.2 |
CRITICAL | 9.8 | The RegistrationMagic β Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … | — | wordfence |
| d571e741-6d72-47fe-8eb0-8a75c173f626 | CRITICAL | 9.8 | The Simple Dashboard plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.… | — | wordfence | |
| d56cfeb1-1257-4f6b-b889-d9f5839ce60d | < 1.1.15 |
CRITICAL | 9.8 | The Sapa theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.14. This makes … | — | wordfence |
| d5400ec0-383b-4ac5-9b38-44533519e44d | < 5.1.8 |
CRITICAL | 9.8 | The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated an… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →