Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 292 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| aedb424a-9346-4bf9-8ce2-50f12bfc1fb7 | HIGH | 7.5 | The Emerce Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.8 due to insuffi… | — | wordfence | |
| aeceaf36-824e-45bf-a7c8-6ed13e2435dd | < 2.2.9 |
HIGH | 7.5 | The Easy Elementor Addons plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2… | — | wordfence |
| ae74048a-ea29-46cc-913b-86094640e88d | < 1.1.2 |
HIGH | 7.5 | The ThemeMakers Axioma Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensi… | — | wordfence |
| ae5b4d81-c2f1-4d0d-b7b0-5556bf0451f5 | < 16.26.12 |
HIGH | 7.5 | The WP-Recall β Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'da… | — | wordfence |
| adf40b81-c013-4abc-9b99-4eb96a536385 | < 6.3.6 |
HIGH | 7.5 | The Awesome Support β WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to PHP Object Injection i… | — | wordfence |
| adcbb70e-c99f-4f05-8869-50cf16f6de79 | < 2.2.1 |
HIGH | 7.5 | The Wholesale Market plugin for WordPress is vulnerable to arbitrary file download due to missing file name validation v… | — | wordfence |
| ad74d5d0-270e-41d3-9596-2f71b05af276 | < 3.9.1 |
HIGH | 7.5 | The Yoco Payments plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.9.0 via t… | — | wordfence |
| ad4784ce-38f2-49b7-8323-ce08a16a311b | HIGH | 7.5 | Directory traversal vulnerability in the Download Zip Attachments plugin 1.0 for WordPress allows remote attackers to re… | — | wordfence | |
| ad32fdd9-d1b5-4591-851f-889a7e3db047 | HIGH | 7.5 | The Product Rearrange for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… | — | wordfence | |
| ad20d235-26e1-4071-89ea-21e721ec9505 | < 4.4.6 |
HIGH | 7.5 | The Sailing theme for WordPress is vulnerable to Local File Inclusion in versions up to 4.4.6. This makes it possible fo… | — | wordfence |
| ad19205d-d355-45d8-be5b-f8005459a8c7 | HIGH | 7.5 | The Likes and Dislikes Plugin plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versio… | — | wordfence | |
| ad021954-83ec-4f56-8c4d-79751eda94b0 | HIGH | 7.5 | The URL Shortener plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.7 due to ins… | — | wordfence | |
| acde5693-53fe-47b8-ad0b-6799ab63d0c1 | < 0.5.6 |
HIGH | 7.5 | The Ghost plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp-admin/t… | — | wordfence |
| ac856b65-2ac5-4627-b12d-86aec62e58d6 | < 4.2 |
HIGH | 7.5 | The ARPrice plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.1.3 due to insuffici… | — | wordfence |
| ac53ade6-b654-4169-a50a-96b3de3d108d | < 1.0.6 |
HIGH | 7.5 | The TableOn β WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filt… | — | wordfence |
| ac3fbecc-43c5-42da-85c9-8a732be71503 | < 4.3.4.2 |
HIGH | 7.5 | The EventPrime β Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to PHP Object Injection in v… | — | wordfence |
| ac27f20a-2048-46f3-b84f-43e2d4a345d2 | HIGH | 7.5 | The WordPress RokBox plugin is vulnerable to Denial of Service via the 'src' parameter in the 'thumb.php' file in versio… | — | wordfence | |
| ac106300-c351-483d-8877-502a4b02941c | HIGH | 7.5 | The ARMember Premium β Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for Wo… | — | wordfence | |
| abf422ce-fa03-4bed-a4ec-b31d36de7633 | < 22.0 |
HIGH | 7.5 | The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabi… | — | wordfence |
| abc5ed0a-504f-4d8c-9662-a4c9f7c7acb8 | < 1.13.19 |
HIGH | 7.5 | The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'object_ids' and 'exclude_object_i… | — | wordfence |
| abab29c7-88a9-4c6f-9691-ed9087cde2ff | < 3.0.13 |
HIGH | 7.5 | The The Ultimate WordPress Toolkit β WP Extended plugin for WordPress is vulnerable to time-based SQL Injection via th… | — | wordfence |
| ab62ea47-6ecb-40e3-82f8-3f35d738ece8 | HIGH | 7.5 | The KuteShop theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2.9. This mak… | — | wordfence | |
| ab3baeb6-8728-46af-89ad-33811ead84b0 | < 10.11.1 |
HIGH | 7.5 | The AcyMailing β An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is… | — | wordfence |
| aaf38354-f95a-4bc5-a63e-3774eadf4fcb | HIGH | 7.5 | The ThemeMakers Invento Responsive Gallery/Architecture Template component through 2015-05-15 for WordPress allows remot… | — | wordfence | |
| aad65aa5-b928-463b-a287-ea0dc8da7c80 | < 1.7.0 |
HIGH | 7.5 | The Advanced 301 and 302 Redirect plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →