Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 271 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 00747cde-efb3-486f-ac19-903dee69263d | HIGH | 8.1 | The Ekoterra - NonProfit & Ecology Theme theme for WordPress is vulnerable to Local File Inclusion in versions up to, an… | — | wordfence | |
| 00200994-e9a3-4fa2-84b6-b5fd79d4995f | < 1.4.5 |
HIGH | 8.1 | The Ziston theme for WordPress is vulnerable to Local File Inclusion in versions up to 1.4.5. This makes it possible for… | — | wordfence |
| db1bad2e-55df-40c5-9a3f-651858a19b42 | < 7.9.9 |
HIGH | 8.0 | The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includin… | — | wordfence |
| da082107-1c71-4d18-a864-986807568de9 | < 2.6.0 |
HIGH | 8.0 | lib\modules\contributors\contributor_list_table.php in the Podlove Podcast Publisher plugin 2.5.3 and earlier for WordPr… | — | wordfence |
| d482f3a1-4a5a-4382-88b1-fd3b91605694 | HIGH | 8.0 | The User Meta β User Profile Builder and User management plugin plugin for WordPress is vulnerable to arbitrary file d… | — | wordfence | |
| c7c7247c-2fc3-46ff-858e-2242b7211476 | < 3.9.2 |
HIGH | 8.0 | The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. … | — | wordfence |
| c272f769-65da-4963-aff0-8f68a277ea63 | < 3.7.37 |
HIGH | 8.0 | WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-pri… | — | wordfence |
| bfd16372-9173-4168-8604-5c117d05c349 | < 1.2.4 |
HIGH | 8.0 | The Health Check & Troubleshooting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… | — | wordfence |
| baafd001-144d-4ee4-b7e6-28c0931e6e10 | < 2.11.3 |
HIGH | 8.0 | The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl… | — | wordfence |
| b4fe8b1f-da1c-4f94-9ab4-272766b488c3 | < 7.9.9 |
HIGH | 8.0 | The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includin… | — | wordfence |
| b0ef885f-fd62-4513-83cb-65381b99a172 | < 3.7.37 |
HIGH | 8.0 | WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to … | — | wordfence |
| a9b8f2d5-a2c5-4f90-ab1d-4e17f7a7996e | < 5.4.17 |
HIGH | 8.0 | The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This … | — | wordfence |
| a7e35f18-7659-4b97-b99f-b57ac941cb22 | HIGH | 8.0 | The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and … | — | wordfence | |
| a176f206-eb96-4902-8355-eec3c9ff6809 | < 1.8.0 |
HIGH | 8.0 | The Checkout Field Editor plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1… | — | wordfence |
| 9efa04ca-68c8-4221-a3d9-cf75010d2266 | < 5.3.7 |
HIGH | 8.0 | The AutomatorWP β Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for Wor… | — | wordfence |
| 93554eb7-2f81-4eb1-809e-6dfe1f5b6196 | < 2.1.2 |
HIGH | 8.0 | The WPForms User Registration plugin for WordPress is vulnerable to privilege escalation in all versions up to, and incl… | — | wordfence |
| 82f80916-37ab-4c5a-9787-2544c620acac | < 0.9.0.3 |
HIGH | 8.0 | The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and i… | — | wordfence |
| 7d8365a6-dfa2-4753-b655-3c2bcadeae75 | < 1.6.0 |
HIGH | 8.0 | The phpCAS library uses HTTP headers to determine the service URL used to validate tickets. This allows an attacker to c… | — | wordfence |
| 74e5bed8-3c6a-479a-9f2f-f15a467cd896 | < 1.3.9 |
HIGH | 8.0 | The Contact Form Widget β Contact Query, Contact Page, Form Maker, Query Table plugin for WordPress is vulnerable to S… | — | wordfence |
| 5c517278-9d2a-4ef6-bf0e-a62f6b00dd20 | < 1.4.3.2 |
HIGH | 8.0 | The 140+ Widgets | Best Addons For Elementor β FREE for WordPress is vulnerable to PHP Object Injection in versions up… | — | wordfence |
| 56b16f10-2f48-49db-85f6-f934bc267110 | < 1.0.4 |
HIGH | 8.0 | The My WP Translate plugin for WordPress is vulnerable to an authorization bypass weakness in versions up to, and includ… | — | wordfence |
| 50ac32ed-f83c-4afc-aac2-a79c69497091 | < 1.20.5 |
HIGH | 8.0 | The Import and export users and customers plugin for WordPress is vulnerable to CSV Injection in versions up to, and inc… | — | wordfence |
| 4c3ee9fa-5d66-4f84-818f-ceec2f0c0b96 | < 0.6.0 |
HIGH | 8.0 | The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and… | — | wordfence |
| 48f148ee-800d-4c8f-bf43-893ec7961f3a | < 1.0.0-beta3 |
HIGH | 8.0 | The WordCamp Talks plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.0.0 Beta2 via… | — | wordfence |
| 4658109d-295c-4a1b-b219-ca1f4664ff1d | < 0.9.92 |
HIGH | 8.0 | The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in version… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →