Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,590 vulnerabilities found (page 254 of 1584)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 50970977-79c7-4014-8f90-a1e6ff47b6f3 | HIGH | 8.1 | The Skyward theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.10. This makes… | — | wordfence | |
| 5090f734-71f4-44e3-8733-430ab61aca08 | HIGH | 8.1 | The Nuts theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.10. This makes it… | — | wordfence | |
| 506006ce-7b1c-4f9d-93f3-abc87abea2bb | HIGH | 8.1 | The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions… | — | wordfence | |
| 502e71ab-9974-45dc-b777-b43bf1c56297 | HIGH | 8.1 | The Pubzinne theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.12. This ma… | — | wordfence | |
| 4ff2088e-c7f8-47e8-8858-f6bf6a801812 | HIGH | 8.1 | The Tourimo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.3. This make… | — | wordfence | |
| 4feccf0a-983d-4435-9cd6-5f7cb23f41a9 | HIGH | 8.1 | The Rashy theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.3. This makes … | — | wordfence | |
| 4fe1aa29-9f50-4503-9539-c9859e50e753 | < 1.13.19 |
HIGH | 8.1 | The Geo Mashup plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.13.18. Thi… | — | wordfence |
| 4fd88ad7-e983-4419-8951-30c50969946a | HIGH | 8.1 | The Weedles theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.12. This mak… | — | wordfence | |
| 4fd78299-f71f-473d-9c62-77be9495393f | HIGH | 8.1 | The The Qlean theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.12. This mak… | — | wordfence | |
| 4fb5b208-0443-4d75-902b-8687217e26fd | HIGH | 8.1 | The WP Pipes plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.3. This ma… | — | wordfence | |
| 4f74991b-8b24-40c0-a550-0f7971e148fb | < 1.2.18 |
HIGH | 8.1 | The Hara theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.17. This makes … | — | wordfence |
| 4f3ee9f6-6465-4caf-9aef-72dd37c61a2c | < 6.2.4 |
HIGH | 8.1 | The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions… | — | wordfence |
| 4f02ee56-40bd-4132-92e1-e2897ff2a4c4 | < 1.7.17 |
HIGH | 8.1 | The WPCOM Member plugin for WordPress is vulnerable to authentication bypass via brute force in all versions up to, and … | — | wordfence |
| 4eedc291-7fa3-4c47-8edb-3a3edade96d6 | < 1.4.4 |
HIGH | 8.1 | The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is v… | — | wordfence |
| 4ea2ed8b-b24a-4da2-9ee7-5a3a4a7a4280 | < 1.1.2 |
HIGH | 8.1 | The Hashthemes Demo Importer Plugin for WordPress contained several AJAX functions which relied on a nonce which was vis… | — | wordfence |
| 4e95b32b-c050-41eb-8fce-461257420eb6 | < 3.9.6 |
HIGH | 8.1 | The Tutor LMS β eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refe… | — | wordfence |
| 4e8e52a7-1f5a-4cc0-81db-9b97b5ea7491 | HIGH | 8.1 | The Victo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.16. This makes… | — | wordfence | |
| 4e725c3c-3c12-4aa8-a0f8-80b4fbbf0b24 | < 1.8.3 |
HIGH | 8.1 | The Hitek theme for WordPress is vulnerable to Local File Inclusion in versions up to 1.8.3. This makes it possible for … | — | wordfence |
| 4e4ee98d-695a-4c47-864b-0d60e1691b8a | HIGH | 8.1 | The Agricola theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.0. This mak… | — | wordfence | |
| 4e0f666b-0549-4728-b056-4d59cf262c4b | HIGH | 8.1 | The Seil - A Responsive WordPress Blog Theme theme for WordPress is vulnerable to PHP Object Injection in all versions u… | — | wordfence | |
| 4dd62de7-76c6-40aa-ba0b-e227109a9fcb | < 1.10 |
HIGH | 8.1 | The Pelicula theme for WordPress is vulnerable to PHP Object Injection in versions up to 1.10 via deserialization of unt… | — | wordfence |
| 4d218a19-6f8c-468d-aad2-90b0f73687b4 | HIGH | 8.1 | The Abelle theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.22. This makes … | — | wordfence | |
| 4d2034a0-f0d8-418f-8fd9-04e50e5e804e | < 2.1.0 |
HIGH | 8.1 | The Subscribe to Download plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2… | — | wordfence |
| 4cd2a38a-3cd6-40e6-9134-8b9f02d761be | < 1.5.9 |
HIGH | 8.1 | The PeakShops theme for WordPress is vulnerable to Local File Inclusion in versions up to 1.5.9. This makes it possible … | — | wordfence |
| 4cc62b7b-9603-4f12-9cb0-9183365822a7 | HIGH | 8.1 | The Store Locator for WordPress with Google Maps β LotsOfLocales plugin for WordPress is vulnerable to Local File Incl… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →