Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 273 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 68420c5a-4add-4597-bd2a-20dc831e81bd | < 2.4.27 |
HIGH | 7.7 | The Best WordPress Gallery Plugin β FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versio… | — | wordfence |
| 442551ba-409d-4b46-bdba-111a8df00a47 | < 1.3.7 |
HIGH | 7.7 | The WP CSV Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.6. This al… | — | wordfence |
| 31f6032a-19f8-463b-9642-cba205069a22 | < 2.9.4 |
HIGH | 7.7 | Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2… | — | wordfence |
| 2e27cfff-6763-4e54-af5d-0f4cf23e72f7 | < 3.7.5 |
HIGH | 7.7 | wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remo… | — | wordfence |
| 103a7e7b-74bb-4691-8670-c66ed2144596 | < 2.9.12 |
HIGH | 7.7 | The Paid Memberships Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'membership' shortcode in v… | — | wordfence |
| 0f02b258-d911-401e-8b32-57166d75bde7 | HIGH | 7.7 | The ARforms plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 6.4.1. This … | — | wordfence | |
| eabde2e7-5cd4-4c3e-959a-69e04f6350d3 | < 4.9.4 |
HIGH | 7.6 | The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu… | — | wordfence |
| dfd6c2b8-b00c-49d1-930f-50397e742ac5 | < 2.0.7 |
HIGH | 7.6 | The Gallery Images Ape plugin for WordPress is vulnerable to Arbitrary Plugin Deactivation in versions up to, and includ… | — | wordfence |
| d9d6e168-a768-4062-9ef1-0be9d6c65c51 | < 6.2.0 |
HIGH | 7.6 | The RumbleTalk Live Group Chat plugin for WordPress is vulnerable to unauthorized access of data, modification of data, … | — | wordfence |
| cf4f3f5e-28f7-492c-9d54-4826826bd904 | < 2.7.1 |
HIGH | 7.6 | On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capab… | — | wordfence |
| cd7553e8-e43d-4740-b2ee-e3d8dc351e53 | < 4.1.6 |
HIGH | 7.6 | The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up … | — | wordfence |
| ba4aabcc-9db8-4385-90c2-58ed93df8f9d | < 5.8 |
HIGH | 7.6 | WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database… | — | wordfence |
| b801e7d9-0ca0-471e-a524-af19ea0d85be | < 5.4.7 |
HIGH | 7.6 | WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database… | — | wordfence |
| af063570-43f7-4bf4-850c-21c3bff40ac1 | HIGH | 7.6 | The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to unauthorized modification of data due… | — | wordfence | |
| 7be75b0a-737d-4f0d-b024-e207af4573cd | < 2.3.42 |
HIGH | 7.6 | The Contact Form builder with drag & drop for WordPress β Kali Forms plugin for WordPress is vulnerable to unauthorize… | — | wordfence |
| 5a4d7d40-8e0e-4251-8e25-3fd4ebd3a93e | < 2.6.3 |
HIGH | 7.6 | The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versi… | — | wordfence |
| 52daa230-1600-4ace-9adf-3f4e9be51e9f | < 2.1.0 |
HIGH | 7.6 | The JupiterX Core plugin for WordPress suffers from several access control issues in versions up to, and including, 2.0.… | — | wordfence |
| 406b52dc-3d36-4b03-a932-34f456395979 | < 2.5.1 |
HIGH | 7.6 | The Product Import Export for WooCommerce β Import Export Product CSV Suite plugin for WordPress is vulnerable to Serv… | — | wordfence |
| 3283b3ff-1787-466b-9517-84bd715e4165 | < 2.6.1 |
HIGH | 7.6 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all… | — | wordfence |
| 0652b19c-52c8-4d77-973f-1e93a5ba811c | < 5.0.5 |
HIGH | 7.6 | Cross-site request forgery (CSRF) vulnerability in the Facebook Members plugin before 5.0.5 for WordPress allows remote … | — | wordfence |
| ffffedb4-633a-4490-98f1-9bc827c8ba1c | < 3.9.001 |
HIGH | 7.5 | The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to o… | — | wordfence |
| ffdd5446-5835-4976-b764-9b5c75251438 | HIGH | 7.5 | The Flexi Product Slider and Grid for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all vers… | — | wordfence | |
| ffd1cd48-96dc-4b35-8310-a5eb0a82dc19 | < 1.18 |
HIGH | 7.5 | The RokNewsPager plugin for WordPress is vulnerable to Full Path Disclosure in versions up to, and including, 1.17 via t… | — | wordfence |
| ffb72c2a-f0b5-4a82-a187-121636a1d324 | < 1.3.6.5 |
HIGH | 7.5 | The HUSKY β Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in… | — | wordfence |
| ff904d2a-5be1-4a17-ac95-b0099eb616f6 | < 3.1.5 |
HIGH | 7.5 | The Pendulum theme for WordPress is vulnerable to PHP Object Injection in versions up to 3.1.5 via deserialization of un… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →