Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 291 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b2ad5698-4299-48a4-bcc1-5f4436dfab27 | HIGH | 7.5 | The Dynamically Display Posts plugin for WordPress is vulnerable to SQL Injection via the 'tax_query' parameter in all v… | — | wordfence | |
| b2a8c307-2430-4ea9-afe0-e5e758eabdd1 | < 9.1.10 |
HIGH | 7.5 | The NEX-Forms β Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Refer… | — | wordfence |
| b2971aa0-8287-4142-bd04-7aec1ed92e7b | < 2.0.10 |
HIGH | 7.5 | The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in all versions up to, … | — | wordfence |
| b288386c-709c-49a6-9b46-28bf46c3c303 | < 7.0.0 |
HIGH | 7.5 | The Premium Packages β Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'cod… | — | wordfence |
| b251cc43-155a-4f73-9819-4805de3686bc | HIGH | 7.5 | The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to SQL Injection in versions … | — | wordfence | |
| b24625d7-2a38-451b-ab79-a1d9c5b8822a | < 19.1.5.1 |
HIGH | 7.5 | The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to … | — | wordfence |
| b20fa367-a12f-402a-a74a-2bb5fe090036 | < 7.3.1 |
HIGH | 7.5 | The plugin Directorist for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 7.3.0. T… | — | wordfence |
| b1e9c2c9-b306-44a5-9919-9b5f13fa3fcc | < 1.5.6 |
HIGH | 7.5 | The ModelTheme Addons for WPBakery and Elementor plugin for WordPress is vulnerable to PHP Object Injection in versions … | — | wordfence |
| b19794de-b623-4017-bd91-73986383c58b | < 1.3.7 |
HIGH | 7.5 | The Ultimate WP Mail plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the… | — | wordfence |
| b1695816-0f54-4095-8884-bc9856b4dac1 | < 1.1.8 |
HIGH | 7.5 | The ThemeMakers Almera Responsive Portfolio theme through 2015-05-15 for WordPress allows remote attackers to obtain sen… | — | wordfence |
| b157356c-a4be-48d6-8c58-ad1a9c96cda3 | < 1.1.0 |
HIGH | 7.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin f… | — | wordfence |
| b0f3cdce-e239-4c2f-83e3-e8d0b528d39e | < 3.3.5 |
HIGH | 7.5 | The LTL Freight Quotes β R+L Carriers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' an… | — | wordfence |
| b0bce89d-6b1d-4e7f-bd7f-6143a3b622de | < 2.0.29 |
HIGH | 7.5 | The wp-courses plugin through 2.0.27 for WordPress allows remote attackers to bypass the intended payment step (for cour… | — | wordfence |
| b0ae27c4-0381-4622-90e8-f4fee29767a3 | < 5.0.2 |
HIGH | 7.5 | inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /w… | — | wordfence |
| b073edd0-3f40-423e-976e-996b29caf66e | < 6.0.7 |
HIGH | 7.5 | The Kirki β Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file d… | — | wordfence |
| b06d4731-111d-43b5-a0ca-afc877c37001 | HIGH | 7.5 | The Goodlayers Hostel plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.2 due to… | — | wordfence | |
| b0696cbe-70e0-402d-bcfd-40907a973785 | < 1.4.8 |
HIGH | 7.5 | The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'hide_fields' and the 'attr_search' par… | — | wordfence |
| afcccbd2-8f84-4d46-a8c4-8d83266d51f9 | < 1.5.2 |
HIGH | 7.5 | The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.1 due to … | — | wordfence |
| afbd5080-8a25-4230-8836-20ffeca3f39d | < 2.3.3 |
HIGH | 7.5 | The WP Job Portal plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.3.2 due to ins… | — | wordfence |
| afa90746-2932-44fe-baf0-c251b5a063f3 | < 3.7.2 |
HIGH | 7.5 | The Support for CitiLights - Real Estate WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in ve… | — | wordfence |
| af871d3d-2dc0-49c3-a697-2635e4aa8f70 | < 2.6.7 |
HIGH | 7.5 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Sensitive Information Exp… | — | wordfence |
| af343f4d-8e0f-463f-bc5f-e48c6d6d11f7 | HIGH | 7.5 | The Tonda theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.5. This makes it… | — | wordfence | |
| af06ed29-00a0-4741-be69-44554156615b | HIGH | 7.5 | The Post Ideas plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2 due to insufficie… | — | wordfence | |
| aef584bd-60a5-4bf2-b8d3-58e3b45e785e | < 1.8.3 |
HIGH | 7.5 | The File Manager Pro β Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… | — | wordfence |
| aee59a8f-7f21-4572-b146-ab1b6350ddb1 | < 1.4 |
HIGH | 7.5 | The WP Hide & Security Enhancer plugin for WordPress is vulnerable to Arbitrary File Download in versions before 1.4. Th… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →