Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 23 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d534feae-d1b7-4544-b1c5-c23f37dd5bab | < 1.1.7 |
CRITICAL | 9.8 | The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This i… | — | wordfence |
| d52f601b-6a80-4b6f-895b-fcbbdf73103a | < 1.9.1.5 |
CRITICAL | 9.8 | The 3DPrint Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… | — | wordfence |
| d52983d1-7da4-44e6-bfed-75107b923267 | CRITICAL | 9.8 | The Kish Guest Posting plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence | |
| d5209e18-894e-46fa-9eb1-11016ef41104 | < 2.5.4 |
CRITICAL | 9.8 | The Custom Login Page Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all … | — | wordfence |
| d51d8b79-04ff-470f-92da-12eb72ac023a | CRITICAL | 9.8 | The WP Ticket Ultra Help Desk & Support Plugin plugin for WordPress is vulnerable to Local File Inclusion in all version… | — | wordfence | |
| d4f3d386-98cc-4b5a-b13f-841e812bb37f | < 3.0.1 |
CRITICAL | 9.8 | Unspecified vulnerability in the folder framework in the Enfold theme before 3.0.1 for WordPress has unknown impact and … | — | wordfence |
| d4e1ca02-4eb5-4a46-99d5-89630f37d9ed | CRITICAL | 9.8 | The Steveas WP Live Chat Shoutbox plugin for WordPress is vulnerable to SQL Injection via several parameters in versions… | — | wordfence | |
| d4bce9d1-38b9-4c25-b5dc-fd9dedfc3ede | < 1.3.3 |
CRITICAL | 9.8 | The WholesaleX β WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing) plugin for WordPress… | — | wordfence |
| d4ae4e05-cdbf-481f-abcc-9704e75ec8ad | < 1.6.0 |
CRITICAL | 9.8 | The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 pa… | — | wordfence |
| d4994d7d-82f7-4cb0-869f-e27abe04b621 | < 1.7.1 |
CRITICAL | 9.8 | The Knews Multilingual Newsletters plugin for WordPress is vulnerable to generic SQL Injection via an unknown parameter … | — | wordfence |
| d4837258-c749-4194-926c-22b67e20c1fc | < 2.9.6 |
CRITICAL | 9.8 | The Chartify β WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to… | — | wordfence |
| d4804081-67b1-4c62-af8e-bdbcea2ba6e7 | < 8.0.0 |
CRITICAL | 9.8 | The WP Support Plus Responsive Ticket System plugin for WordPress is vulnerable to Authentication Bypass in versions up … | — | wordfence |
| d44f8af2-3525-4b00-afa8-a908250cc838 | < 0.9.2.2 |
CRITICAL | 9.8 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, a… | — | wordfence |
| d42eeda5-7034-4544-be97-8064ff6d3185 | CRITICAL | 9.8 | Directory traversal vulnerability in the Ajax Pagination (twitter Style) plugin 1.1 for WordPress allows remote attacker… | — | wordfence | |
| d4095518-0daf-4cfe-a521-86fb1c927f51 | < 4.00 |
CRITICAL | 9.8 | A SQL injection issue was discovered in the Quick Chat plugin before 4.00 for WordPress. | — | wordfence |
| d3af64a2-3bd6-47af-919e-00c5249dcc74 | < 1.2.1 |
CRITICAL | 9.8 | The WP Email Debug plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the W… | — | wordfence |
| d3a5be68-8073-48b0-a536-bb3a05e83dda | CRITICAL | 9.8 | The EduKart Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. … | — | wordfence | |
| d3a4fa4d-a7d2-4890-b0f5-5fe69bc5e7ac | < 2.13.8 |
CRITICAL | 9.8 | The Paid Membership Subscriptions β Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPr… | — | wordfence |
| d34f4e77-f384-4d84-be32-0d349962b614 | < 5.5.2 |
CRITICAL | 9.8 | The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass… | — | wordfence |
| d323d28f-280c-49cd-b7f7-3e272ea62549 | CRITICAL | 9.8 | A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/list… | — | wordfence | |
| d257d0e0-7e42-49d5-83c6-f5c44f2e15fc | < 1.2.2 |
CRITICAL | 9.8 | The WP Marketplace β Complete Shopping Cart / eCommerce Solution plugin for WordPress is vulnerable to arbitrary file … | — | wordfence |
| d2448afc-70d1-4dd5-b73b-62d182ee9a8a | < 6.26.13 |
CRITICAL | 9.8 | The OAuth Single Sign On β SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptogra… | — | wordfence |
| d22fb2e8-bb61-49bc-9fab-8f7c58339a69 | < 3.7.3 |
CRITICAL | 9.8 | The Custom 404 Pro plugin for WordPress is vulnerable to blind SQL Injection via multiple parameters including the 'User… | — | wordfence |
| d21cf285-9d75-43a2-9e81-67116f0bf896 | < 5.2 |
CRITICAL | 9.8 | The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldu… | — | wordfence |
| d1e8412a-f2fb-4f90-9847-1e4043dda480 | < 1.0.7 |
CRITICAL | 9.8 | The Simplified Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →