Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 289 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| bdcd9e73-ed37-4a5b-8dfa-6ef5cd6f47e2 | < 5.0 |
HIGH | 7.5 | The Binary MLM Plan plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0 due to ins… | — | wordfence |
| bd563af4-b97f-4746-a5e9-8dc5dfda272e | HIGH | 7.5 | The Authentic theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.0.4. This… | — | wordfence | |
| bd3ee85a-324d-4991-bffc-db28ce374bbe | < 4.4.4 |
HIGH | 7.5 | The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to SQL Injection via … | — | wordfence |
| bd087d06-5395-4dfd-a288-2c3271a62842 | < 6.8.6 |
HIGH | 7.5 | WordPress Core is vulnerable to generic SQL Injection via the 'author__not_in' parameter in versions 6.8 - 7.0.1 due to … | — | wordfence |
| bcf37d4e-e94a-4046-9949-c208e4e70197 | < 2.7.7 |
HIGH | 7.5 | The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions … | — | wordfence |
| bcec59c3-dccc-4ddf-920c-76cc7b9685ac | HIGH | 7.5 | The Coven Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3 due to insuffic… | — | wordfence | |
| bc927a93-0cb2-4211-9f93-c0671039011e | < 6.15.10 |
HIGH | 7.5 | The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15… | — | wordfence |
| bc860f44-c8ee-4b32-9702-7214e213790b | HIGH | 7.5 | The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is… | — | wordfence | |
| bc84ca1f-747d-444e-b997-a79731b7ab51 | < 8.2 |
HIGH | 7.5 | The Greenly theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 8.1. This makes … | — | wordfence |
| bc74d1a3-5066-4b06-bfed-3b018e844126 | HIGH | 7.5 | The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable… | — | wordfence | |
| bc406e8a-c4eb-45c3-a53c-37644e0dabfa | < 2.4.9 |
HIGH | 7.5 | The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() f… | — | wordfence |
| bc07432e-0f3b-411d-9e38-61e4ed1a854b | < 1.3.15 |
HIGH | 7.5 | The Zota theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.14. This makes … | — | wordfence |
| bbc7704b-8a28-4daf-8b83-bccc3783c43c | < 3.4.9 |
HIGH | 7.5 | The Recipe Card Blocks for Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized access due to an inc… | — | wordfence |
| bba4286b-acce-4dff-b809-dbd04d59702b | < 1.2.4 |
HIGH | 7.5 | search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes. | — | wordfence |
| bb8bbfdb-c2a2-49b6-8a24-b788427d72b6 | HIGH | 7.5 | The CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - WordPress Plugin plugin for WordPress is vulnerab… | — | wordfence | |
| bb7e9ea4-c450-491f-b924-47ed4abec64a | < 1.6.6 |
HIGH | 7.5 | The User Activity Log plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includ… | — | wordfence |
| ba4da955-7651-42e5-aefa-72c70a7b1035 | < 2.51.3 |
HIGH | 7.5 | The Strong Testimonials plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on … | — | wordfence |
| ba311865-be4b-4c56-a761-409582e981b5 | < 4.3.2 |
HIGH | 7.5 | The Small Package Quotes – For Customers of FedEx plugin for WordPress is vulnerable to SQL Injection via the 'edit_id… | — | wordfence |
| b9ffb0ac-84cf-4a82-b89b-05e43608db52 | < 2.2.6 |
HIGH | 7.5 | The WP Human Resource Management plugin before 2.2.6 for WordPress mishandles leave applications. | — | wordfence |
| b9fa5c83-3701-4017-97c1-75f57e762c4e | < 2.2.261 |
HIGH | 7.5 | The Store Locator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.260 v… | — | wordfence |
| b96f40fe-3ffa-4fc5-b51a-ff3771224bd5 | < 1.31.3 |
HIGH | 7.5 | TheWP Job Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.31.2 vi… | — | wordfence |
| b967eb98-69f8-41c5-a19a-9d20979accb0 | < 5.4.2 |
HIGH | 7.5 | The Mayosis Core plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.4.1 v… | — | wordfence |
| b939377b-276c-4612-9687-4e1b77e104cd | < 4.0.35 |
HIGH | 7.5 | The Classiera theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.34 due to insuffi… | — | wordfence |
| b8f24fae-6a8b-4c67-a204-c085ae43552f | < 3.2.35 |
HIGH | 7.5 | The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpo… | — | wordfence |
| b8dc0b5e-87b9-4831-a92a-bbf6eb1346e2 | < 1.9.9 |
HIGH | 7.5 | The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure i… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →