Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 223 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f321b8f6-0712-4932-b861-b208debb368f | < 1.8.7 |
HIGH | 8.1 | The VaultPress plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.8.6 via t… | — | wordfence |
| f2a98c03-6660-4997-b60f-6b95e6ffe57b | < 1.1.5 |
HIGH | 8.1 | The WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable to … | — | wordfence |
| f27d2dc9-c26e-4cb9-999f-da6359881867 | < 2025.1.1 |
HIGH | 8.1 | The WP REST Cache plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2025.1.0.… | — | wordfence |
| f23d0089-b216-4d02-af23-e06262b44004 | HIGH | 8.1 | The Barista theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.5.1. This make… | — | wordfence | |
| f1eacb72-df11-4a3b-9064-f8f776f3522b | HIGH | 8.1 | The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.… | — | wordfence | |
| f1e31357-7fbc-414b-a4f4-53fa5f2fc715 | HIGH | 8.1 | The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate… | — | wordfence | |
| f1b9725b-dee5-44ca-bb33-c6812fb76adc | < 28.1.6 |
HIGH | 8.1 | The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in … | — | wordfence |
| f1b7768a-9204-429d-a4d2-db9f240e92a4 | < 2.9.17 |
HIGH | 8.1 | The WP User Manager β User Profile Builder & Membership plugin for WordPress is vulnerable to arbitrary file deletion … | — | wordfence |
| f16eea85-fa55-46b4-85a8-e441a119a569 | HIGH | 8.1 | The Gunslinger theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7. This mak… | — | wordfence | |
| f15f29e6-ecb7-403c-881f-f4dfdd7b8a84 | < 2.4.22 |
HIGH | 8.1 | The EmallShop theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.4.21 via des… | — | wordfence |
| f12936a0-26c3-459b-8c81-fba40186cbd7 | HIGH | 8.1 | The Progress theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2. This makes… | — | wordfence | |
| f0c69764-d64b-4231-8251-2f289dce69e1 | < 1.1.9 |
HIGH | 8.1 | The VintWood theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.8. This mak… | — | wordfence |
| f0a0ed90-a20e-40c6-b128-d46e6e9a0131 | < 1.8.6 |
HIGH | 8.1 | The Ireca theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.8.5. This makes … | — | wordfence |
| f0638310-7ea0-4f3a-8fda-c83360747926 | < 2.1 |
HIGH | 8.1 | The PatioTime theme for WordPress is vulnerable to PHP Object Injection in versions up to 2.1 via deserialization of unt… | — | wordfence |
| f048b2ca-bd20-4af7-8f44-a5c9cbca95ed | HIGH | 8.1 | The VideoPro theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.8.1. This m… | — | wordfence | |
| f03732fa-ce5d-4e5f-b39a-c556ed1f16a8 | HIGH | 8.1 | The Hyori theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.6. This makes … | — | wordfence | |
| f035edda-69ca-46ae-98f8-2a84ce682d1f | HIGH | 8.1 | The Photocart Link plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6. Thi… | — | wordfence | |
| f026d837-7c1c-4468-be3f-7728a644af59 | HIGH | 8.1 | The Dentario theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5 via deseria… | — | wordfence | |
| efd279c2-9e95-45bd-9494-fb53a6333c65 | < 4.7.8 |
HIGH | 8.1 | The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7… | — | wordfence |
| efd27466-f68e-4d8a-a1ec-90dbb6ff126b | < 2.7.4 |
HIGH | 8.1 | The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence |
| efa65940-1a46-4a91-be8f-689d2addeabd | HIGH | 8.1 | The Dixon theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.2.1. This make… | — | wordfence | |
| efa4c442-0281-4f7e-a43e-0191cb31c3a4 | HIGH | 8.1 | The Simple Retail Menus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2… | — | wordfence | |
| ef9ad6b4-40f0-40ce-9f17-37077cb1a5ca | HIGH | 8.1 | The CoSchool LMS β A complete Learning Management System to Create and Sell Your Courses Online plugin for WordPress i… | — | wordfence | |
| ef9a6ef5-368e-40df-9a17-2779e453dfcc | < 2.7.8 |
HIGH | 8.1 | The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive up… | — | wordfence |
| ef5a0b2d-8ee7-4d4e-b126-00ea11e81ddb | < 2.4.6 |
HIGH | 8.1 | The Atomlab theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.5. This make… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →