Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 233 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| c172ab2b-ce1f-4a0d-b31f-b75ff2f03506 | < 2.6.0 |
HIGH | 8.1 | The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in all versions up to,… | — | wordfence |
| c1204614-395a-4226-9d45-c334eaba090d | < 10.8.10.2 |
HIGH | 8.1 | The Thrive Apprentice plugin for WordPress is vulnerable to PHP Object Injection in versions up to 10.8.10.2 via deseria… | — | wordfence |
| c1010470-63d4-49c5-9811-0e86fbeb57d5 | HIGH | 8.1 | The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and … | — | wordfence | |
| c0c3d504-8e45-42e8-a6e1-27848c347dae | HIGH | 8.1 | The Bazinga theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9. This make… | — | wordfence | |
| c0680c2e-5983-4866-ad53-b35bed384d00 | HIGH | 8.1 | The UNIVERSAM plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 8.72.34 via d… | — | wordfence | |
| bfc7c214-8d76-453c-a05d-682aa425b06e | < 2.1.0 |
HIGH | 8.1 | The Quick Restaurant Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence |
| bfc01e65-fbfa-4639-93e6-7b045b0e2ec4 | < 2.0.3 |
HIGH | 8.1 | The UPC/EAN/GTIN Code Generator plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p… | — | wordfence |
| bf37762d-d7b0-4241-9ed1-f969042d7452 | < 3.10.0 |
HIGH | 8.1 | The TinySalt theme for WordPress is vulnerable to Local File Inclusion in versions up to 3.10.0. This makes it possible … | — | wordfence |
| bef61f05-a2dc-4f61-a5da-7161a9912196 | < 6.2.4 |
HIGH | 8.1 | The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via… | — | wordfence |
| bed8347e-9d89-4484-ae2a-a949feee552e | HIGH | 8.1 | The Conquerors | American Football & NFL PSD Template theme for WordPress is vulnerable to Local File Inclusion in versi… | — | wordfence | |
| be976b54-2418-440c-9f27-667a4156ef08 | < 1.6 |
HIGH | 8.1 | The Hiroshi theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.1 via deseri… | — | wordfence |
| be6592b8-d60f-48c3-bda3-8fd69dcf1d0b | HIGH | 8.1 | The Gable theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5. This makes it… | — | wordfence | |
| be41bf79-8cc3-41fa-856a-1b6c06e647c7 | HIGH | 8.1 | The Pizza House theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.0 via de… | — | wordfence | |
| be224599-ab12-4fb3-9ab4-eecbbc33445b | HIGH | 8.1 | The Strux theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9. This makes it… | — | wordfence | |
| be0a5922-e7ca-448e-aceb-d27002484bea | < 2.7.5 |
HIGH | 8.1 | The Abstracts plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7.4. This m… | — | wordfence |
| bde00f73-853a-420e-9c6c-0205bf371ff3 | HIGH | 8.1 | The Grecko theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.17. This makes … | — | wordfence | |
| bd8a9b92-8ef5-44bc-a977-58875fc4079b | HIGH | 8.1 | The tf-woo-product-grid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,… | — | wordfence | |
| bd331eb2-9ec2-4105-ae79-01c9c772de35 | HIGH | 8.1 | The Cars4Rent | Auto Rental & Taxi WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Injection in al… | — | wordfence | |
| bd073b97-b9b3-417c-ad82-e07a75cee3c4 | < 1.12.4 |
HIGH | 8.1 | The Embed Privacy plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation… | — | wordfence |
| bc308993-7fc5-41db-a396-f05e95fe47b8 | < 5.1.2 |
HIGH | 8.1 | The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up to and including 5.1.1.… | — | wordfence |
| bc2db74d-61b9-498a-a0d8-e43466b06f37 | < 2.9.4.2 |
HIGH | 8.1 | The Beaver Builder β WordPress Page Builder plugin for WordPress is vulnerable to unauthorized access and modification… | — | wordfence |
| bc1ab4f8-dccf-4d1b-90b8-828a7c6100c7 | HIGH | 8.1 | The PhotoMe theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.6.11 via deser… | — | wordfence | |
| bc1600b9-b590-47ca-b2d9-d521381da541 | < 11.4.0 |
HIGH | 8.1 | The Content Egg β Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File D… | — | wordfence |
| bc11d6bc-d0e6-4ec8-9e7f-ca8a88b2a726 | HIGH | 8.1 | The Agricola - Agriculture & Organic Farm Theme theme for WordPress is vulnerable to PHP Object Injection in versions up… | — | wordfence | |
| bbe5d631-8f2a-49a9-aeb8-b9965a5875ca | < 5.9.0 |
HIGH | 8.1 | The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to PHP Object Injection in versions up t… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →