Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 293 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| aac3ef07-f9b1-4f92-8d0a-8597c4eb8d94 | < 4.1.4 |
HIGH | 7.5 | The StoreContrl Woocommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includi… | — | wordfence |
| aab42989-b928-492f-a610-d2a5546751e0 | < 2.5 |
HIGH | 7.5 | The Persuasion Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.4. This … | — | wordfence |
| aaad8b81-d08b-4346-9167-defb6bc01ead | < 3.8 |
HIGH | 7.5 | The Hotel Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.7. This… | — | wordfence |
| aa4244d3-a611-416d-8159-2f6a8cf61b30 | < 3.05.5 |
HIGH | 7.5 | The Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin fo… | — | wordfence |
| aa1ed81c-04cb-4ccd-8c30-b1d943730909 | < 3.7.9 |
HIGH | 7.5 | The My Calendar β Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via th… | — | wordfence |
| aa157c80-447f-4406-9e49-9cc6208b7b19 | < 1.12.1 |
HIGH | 7.5 | The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includ… | — | wordfence |
| aa13c293-0530-478c-acfc-f7d69edae318 | < 1.0.5 |
HIGH | 7.5 | ansi-regex is vulnerable to Inefficient Regular Expression Complexity. Some WordPress plugins and themes use this depend… | — | wordfence |
| a9f17d4a-62b2-433e-bbba-551081a72fcb | < 1.0.9.4 |
HIGH | 7.5 | The Goya Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to 1.0.9.4. This makes it possib… | — | wordfence |
| a9d7aa30-421f-4d25-8e01-460069ef857d | < 2.14.19 |
HIGH | 7.5 | The Modula Image Gallery β Photo Grid & Video Gallery plugin for WordPress is vulnerable to PHP Object Injection in ve… | — | wordfence |
| a9b6f7a3-83eb-4352-9db6-ab4b03241702 | < 3.4.2 |
HIGH | 7.5 | The LTL Freight Quotes β For Customers of FedEx Freight plugin for WordPress is vulnerable to SQL Injection via the 'e… | — | wordfence |
| a9743351-9f28-49bf-8b08-85ffbdcfa5f0 | < 3.5.2 |
HIGH | 7.5 | The Co-Authors Plus plugin for WordPress is vulnerable to sensitive information disclosure via the /wp/v2/coauthors REST… | — | wordfence |
| a96f99ba-982b-4dac-a9ce-e75af85cd5d5 | < 6.0.7 |
HIGH | 7.5 | The Course Booking System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.0.6 du… | — | wordfence |
| a96d0979-a40b-4ced-872f-c5a8116471a1 | HIGH | 7.5 | The Visual Art | Gallery WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in versions up to, an… | — | wordfence | |
| a963cd9b-9f8f-4bd2-92cd-74c5e85e1d96 | < 3.4.8 |
HIGH | 7.5 | The Read More & Accordion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… | — | wordfence |
| a95f5aa7-6ff1-4ebf-9b5a-17ad784eefe7 | < 1.0.7 |
HIGH | 7.5 | The Fable Extra plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.6 due to insuf… | — | wordfence |
| a94708ec-ab09-4604-80ec-5bd85799c6e4 | < 2.2.3 |
HIGH | 7.5 | An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin in versions up to, and inc… | — | wordfence |
| a9057fc2-f346-47e5-964a-f3c5b1653c03 | < 4.21.2 |
HIGH | 7.5 | The LMS by LifterLMS β Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.… | — | wordfence |
| a9000c52-fdd7-43e2-ae6a-9f127c4a9fcd | < 4.7.52 |
HIGH | 7.5 | The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sev… | — | wordfence |
| a8dc0712-f78e-46c5-a0d1-2db752498d54 | < 3.9.9 |
HIGH | 7.5 | The Eventer plugin for WordPress is vulnerable to SQL Injection via the 'event' parameter in the 'eventer_get_attendees'… | — | wordfence |
| a84da684-17b3-43d7-b8dd-2570ee44851e | < 3.15.5 |
HIGH | 7.5 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, … | — | wordfence |
| a83e7d8b-a93a-4347-bb59-de1e2fd954a5 | < 2.8.154 |
HIGH | 7.5 | The GeoDirectory β WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable t… | — | wordfence |
| a78998da-1cb1-4991-95a8-a551bde04064 | HIGH | 7.5 | The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in … | — | wordfence | |
| a770204d-d89f-4c3e-a667-06ec1d96dbf7 | HIGH | 7.5 | The Medinik Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.6 due to insu… | — | wordfence | |
| a7689a95-7f63-46e1-b5fd-4279be66e0f0 | < 5.0.9 |
HIGH | 7.5 | The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up … | — | wordfence |
| a73f7812-771d-4d9f-9a7c-e4e01ec05023 | < 7.11.2 |
HIGH | 7.5 | The Avada theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_i… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →