Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 274 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ff506c6a-6a8b-47ca-a2bd-e9502a60271d | < 2.15.2 |
HIGH | 7.5 | The Paid Member Subscriptions plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.15… | — | wordfence |
| ff346465-62c2-4a2b-8a4a-c88558d7cabd | < 1.7 |
HIGH | 7.5 | The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is… | — | wordfence |
| ff319625-bc2c-454a-8194-f9fe11baad2f | < 1.3.8 |
HIGH | 7.5 | The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in version… | — | wordfence |
| ff21241d-e488-4460-b8c2-d5a070c8c107 | < 3.2.8 |
HIGH | 7.5 | The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~… | — | wordfence |
| feee3268-b384-400c-a76d-e5d7972c05b7 | < 2.2.69 |
HIGH | 7.5 | The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all… | — | wordfence |
| fed758e0-7fea-4b6a-9157-47f5603be2c9 | HIGH | 7.5 | The Instant Appointment plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2 due to… | — | wordfence | |
| fec590e7-c15e-4063-892a-a945333d848e | HIGH | 7.5 | The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the … | — | wordfence | |
| febd1ff3-3a1a-49c2-b210-9e72051e3172 | < 3.1.7 |
HIGH | 7.5 | The Travel Booking WordPress Theme theme for WordPress is vulnerable to blind time-based SQL Injection via the ‘order_… | — | wordfence |
| feb056b0-5ea0-4257-8d58-0e29b3c304bd | < 3.2.39 |
HIGH | 7.5 | The Download Manager WordPress plugin before 3.2.39 uses the uniqid php function to generate the master key for a downlo… | — | wordfence |
| fea7c3f1-1fb4-4a0f-8bbe-c4a0e346993f | < 5.9.2 |
HIGH | 7.5 | The Basel - Responsive WooCommerce Theme theme for WordPress is vulnerable to unauthorized access due to a missing capab… | — | wordfence |
| fe93f443-7941-4463-a068-c292c172f071 | HIGH | 7.5 | The S3 Bubble Amazon S3 HTML5 Video with Adverts plugin for WordPress is vulnerable to Arbitrary File Download in versio… | — | wordfence | |
| fe926435-ef91-4717-8612-31c053771491 | HIGH | 7.5 | The AdminOnline plugin for WordPress is vulnerable to Directly Traversal/Arbitrary File Read via the 'file' parameter in… | — | wordfence | |
| fe573d64-036e-4f6f-bcc1-5183bb9ad2b9 | < 2.0.3 |
HIGH | 7.5 | The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including… | — | wordfence |
| fe43b168-5b40-4d64-8fbd-c394970e832e | HIGH | 7.5 | The North plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.2. This makes… | — | wordfence | |
| fdf33f1c-7e07-425a-aed7-43511f358362 | HIGH | 7.5 | The School Management plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 92.0.0 due t… | — | wordfence | |
| fd839b20-69d1-4cad-80fc-3e7b9940fd30 | < 3.8.10.2 |
HIGH | 7.5 | The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The list… | — | wordfence |
| fd739eb1-4d63-42a2-85ba-a4cfc034628f | HIGH | 7.5 | The Handmade Framework plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.9.… | — | wordfence | |
| fd64b351-fbce-4c75-bdd7-3b38a1b5d049 | < 3.2.2 |
HIGH | 7.5 | The WPC Product Options for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to,… | — | wordfence |
| fd5fb3fb-425a-458b-b3cb-92cd23f50726 | < 3.8.10 |
HIGH | 7.5 | The JetEngine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.9.1 due to insuf… | — | wordfence |
| fd1704ef-e259-40a3-974b-128145bc8a4a | < 2.4.13 |
HIGH | 7.5 | The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parame… | — | wordfence |
| fc0a1bfe-0ead-4333-bb77-0f2f4356626d | < 1.0.0 |
HIGH | 7.5 | The Peter's Math Anti-Spam Spinoff plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to 1.0.0. This is… | — | wordfence |
| fbea84f2-2077-4ea9-b5dc-e527423810fc | HIGH | 7.5 | The Sports Rankings and Lists plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu… | — | wordfence | |
| fbcb33c1-d8f4-4ff9-8148-7bce494b2f0f | HIGH | 7.5 | The WP Backup+ (aka WPbackupplus) plugin through 2018-11-22 for WordPress allows remote attackers to obtain sensitive in… | — | wordfence | |
| fb5c7875-e531-4ee8-bd19-360cbcfef8ed | < 4.0.8 |
HIGH | 7.5 | The Turbo Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to 4.0.8. This makes it poss… | — | wordfence |
| fb26ea7b-fc54-4cef-aaa8-3a41e8d0c371 | < 2.0 |
HIGH | 7.5 | The wp-private-content-plus plugin before 2.0 for WordPress has no protection against option changes via save_settings_p… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →