Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 276 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f5c1f0f4-4557-4ae9-bf0d-14c61721a2c5 | < 7.8.8 |
HIGH | 7.5 | Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports. | — | wordfence |
| f5af4aa1-e384-4bc2-a9d2-67e4685eea4e | HIGH | 7.5 | The Miion theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.7. This makes … | — | wordfence | |
| f5319467-92f6-4d4f-a76a-12aeb25d3c6b | < 0.1.3.7 |
HIGH | 7.5 | The InstaWP Connect β 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in al… | — | wordfence |
| f4ccfeac-e20e-45f3-9c38-a139130b4ab8 | < 3.8.2 |
HIGH | 7.5 | The SMS Alert Order Notifications β WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to,… | — | wordfence |
| f4832fbb-94ed-41c4-8434-1972f4d92476 | < 2.4.2 |
HIGH | 7.5 | The Ultimate Member plugin for WordPress is vulnerable to Username Enumeration in versions up to, and including, 2.4.1 v… | — | wordfence |
| f43db496-80ea-442c-9417-7aa03ec95f02 | < 5.4.02 |
HIGH | 7.5 | The WP Ghost (Hide My WP Ghost) β Security & Firewall plugin for WordPress is vulnerable to Path Traversal in all vers… | — | wordfence |
| f393c5c0-03e7-4f9b-8714-2b25c1010176 | HIGH | 7.5 | The Uroan Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.4 due to insuff… | — | wordfence | |
| f37cc880-d8a4-431a-9639-abf01163030a | < 1.15.43 |
HIGH | 7.5 | The Form Maker by 10Web β Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL I… | — | wordfence |
| f2febf69-b146-4ca5-bfa9-f5477da5cd6c | < 3.1.6 |
HIGH | 7.5 | The Memphis Documents Library plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and incl… | — | wordfence |
| f2db06b1-c823-45db-b6f5-b656978cc779 | < 0.6.67 |
HIGH | 7.5 | A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attac… | — | wordfence |
| f2c20cde-012c-4dca-a8ae-2229131c08e1 | < 7.34.0 |
HIGH | 7.5 | The Modern Events Calendar (Lite & Pro) plugin for WordPress is vulnerable to SQL Injection in versions up to, and inclu… | — | wordfence |
| f2891f3d-9081-4a9f-8408-2373ce1d0306 | < 4.6.3 |
HIGH | 7.5 | The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to time-based SQL Injection v… | — | wordfence |
| f26f1613-5fb4-4c4b-a993-15089b53af2e | HIGH | 7.5 | The WP HRM LITE plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1 due to insuffi… | — | wordfence | |
| f24e753e-2eb0-49a2-9fb1-68daaca12816 | < 1.0.8 |
HIGH | 7.5 | The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase I… | — | wordfence |
| f24db166-93d6-4a61-a8fe-455eebde0777 | HIGH | 7.5 | Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_contact.php doesn't check that the user is autho… | — | wordfence | |
| f218f967-a218-4a5f-991e-cfed226a313f | HIGH | 7.5 | The WPCHURCH plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.7.0 due to insuffic… | — | wordfence | |
| f214b915-f33a-450f-880b-f08be8284e9c | HIGH | 7.5 | The Sala theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1.3 via deseriali… | — | wordfence | |
| f200062a-5f53-4abc-ae96-904f85d8b4e8 | HIGH | 7.5 | The Sales Countdown Timer for WooCommerce and WordPress plugin for WordPress is vulnerable to Local File Inclusion in ve… | — | wordfence | |
| f185709e-0d13-48d3-9c15-03466b72dac2 | < 19.1.5 |
HIGH | 7.5 | The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due t… | — | wordfence |
| f14a658c-1517-4af4-8bd7-c379ac07ab35 | < 5.2.11 |
HIGH | 7.5 | The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… | — | wordfence |
| f1117b57-bd86-4e90-b1bb-e13939e0e766 | < 1.5.1 |
HIGH | 7.5 | The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.0 due to … | — | wordfence |
| f10cf49b-1b78-43c1-b0d1-c1dbb74d5696 | < 3.8.6.2 |
HIGH | 7.5 | The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all version… | — | wordfence |
| f1060875-21dc-41fb-866a-940e6aeb3c22 | < 2.5 |
HIGH | 7.5 | The Echelon Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.4. This is … | — | wordfence |
| f0ff2cb3-a385-4f5c-b555-b6a3dadfc458 | < 2.2 |
HIGH | 7.5 | The Fusion Theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.1. This is d… | — | wordfence |
| f0e97124-641c-4d35-a274-6a127d2d7d18 | < 3.8.4.1 |
HIGH | 7.5 | The JetEngine plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.8.4.1 (exclusive) via d… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →