Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 24 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d1cd5209-7959-49ae-a363-5fb4f06e2aec | < 2.4.11 |
CRITICAL | 9.8 | The Five Star Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to PHP Object Injection in all versio… | — | wordfence |
| d1cc604a-b3dc-4dc1-b20b-4021b5b7d426 | < 2.72 |
CRITICAL | 9.8 | The wp-polls plugin before 2.72 for WordPress has SQL injection. | — | wordfence |
| d10672ba-ae98-43e8-9ad8-2b12e2b7bc49 | CRITICAL | 9.8 | The Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin for WordPress is vulnerable to Remote Code Execut… | — | wordfence | |
| d1043dce-628f-485b-bc1c-b78938c2a6f5 | < 2.4.4 |
CRITICAL | 9.8 | The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via acco… | — | wordfence |
| d0fb6bf0-48b8-48cc-8080-8fe19c36ce7c | < 2.6.6 |
CRITICAL | 9.8 | The Dendelion theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the up… | — | wordfence |
| d0fa6998-b85a-413e-be00-81926b4ea6ab | CRITICAL | 9.8 | The Telecash Ricaricaweb plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.… | — | wordfence | |
| d0dd4fc0-1c6a-4556-b219-893563a27a69 | < 3.0.2 |
CRITICAL | 9.8 | The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret managemen… | — | wordfence |
| d0b27bc8-617a-4f98-954f-e49f87dca311 | < 3.6.11 |
CRITICAL | 9.8 | The education theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.6.10 via… | — | wordfence |
| d0ad02d9-546f-4bcb-b567-785e3acfb489 | < 1.1.0 |
CRITICAL | 9.8 | The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t… | — | wordfence |
| d0ace3b6-7941-43c6-b636-8f7b9d51da3e | < 8.1.15 |
CRITICAL | 9.8 | The Level Four Store Front plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… | — | wordfence |
| d0966138-b28b-4c03-a2cf-b51c5f478276 | CRITICAL | 9.8 | The VEDA - MultiPurpose WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to,… | — | wordfence | |
| d07b5377-ce5f-4faa-ac72-78f5175913c3 | CRITICAL | 9.8 | The Magazine Basic plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter due to insuffi… | — | wordfence | |
| d0538778-5ba4-4bec-a89d-ef90a9ba8375 | < 3.1.8.7 |
CRITICAL | 9.8 | The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6… | — | wordfence |
| d03b4dcd-297d-4361-9cc4-6ccf3d4f0e85 | CRITICAL | 9.8 | The Pyrmont V2 theme for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions up to, and includin… | — | wordfence | |
| CVE-2026-7637 | CRITICAL | 9.8 | The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deseria… | — | nvd | |
| CVE-2026-3535 | CRITICAL | 9.8 | The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type val… | — | nvd | |
| CVE-2026-1994 | < 260215 |
CRITICAL | 9.8 | The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and … | — | nvd |
| CVE-2026-1555 | CRITICAL | 9.8 | The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_i… | — | nvd | |
| CVE-2026-1405 | CRITICAL | 9.8 | The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… | — | nvd | |
| CVE-2026-0926 | CRITICAL | 9.8 | The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.… | — | nvd | |
| CVE-2025-13851 | CRITICAL | 9.8 | The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user re… | — | nvd | |
| CVE-2025-13563 | CRITICAL | 9.8 | The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3… | — | nvd | |
| CVE-2025-12981 | CRITICAL | 9.8 | The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This i… | — | nvd | |
| CVE-2025-12882 | CRITICAL | 9.8 | The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. … | — | nvd | |
| cfffe880-e3f9-4163-a726-e248433e1034 | < 2.3.30 |
CRITICAL | 9.8 | The My Calendar plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.3.29 via the '… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →