Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 294 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a6d636a6-108c-40c5-b7c9-e3dee6bcaa0b | < 7.9.8 |
HIGH | 7.5 | The GamiPress β Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress i… | — | wordfence |
| a65eb62d-847b-4f3a-848b-1290e3118c01 | < 2.9.4 |
HIGH | 7.5 | The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.… | — | wordfence |
| a6505b91-ffca-4ec4-9fd5-a9a5adbd2b0e | < 1.3.3.8 |
HIGH | 7.5 | The MDTF plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.3.7 due to insufficie… | — | wordfence |
| a646da21-9ccb-427b-9d06-7d295c8b5d18 | HIGH | 7.5 | The WP Cloud plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.3. This make… | — | wordfence | |
| a644ac90-6cc4-495c-b880-4ebbc237bb57 | HIGH | 7.5 | The Chocolate WP β Responsive Photography Theme for WordPress is vulnerable to Denial of Service and Abuse of Function… | — | wordfence | |
| a63b2091-1502-4d9f-98c4-ce9d2f923dc4 | < 1.3.9 |
HIGH | 7.5 | The Logo Showcase Ultimate β Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to PHP Object I… | — | wordfence |
| a61d8d2a-742f-45f1-9146-f733b80ef195 | < 1.1.5 |
HIGH | 7.5 | The VidShop β Shoppable Videos for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the … | — | wordfence |
| a5da47f6-4cfe-480e-9472-bd5efc8bac71 | < 3.0.2 |
HIGH | 7.5 | The Verowa Connect plugin for WordPress is vulnerable to SQL Injection via the 'search_string' parameter in all versions… | — | wordfence |
| a5c7a019-953f-441e-b4d5-26f406f9853d | < 1.9 |
HIGH | 7.5 | The aDirectory β WordPress Directory Listing Plugin plugin for WordPress is vulnerable to PHP Object Injection in all … | — | wordfence |
| a594ae11-3e8f-4cb6-b0c6-65f4e68d8b90 | HIGH | 7.5 | The Stockholm Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.6. T… | — | wordfence | |
| a56874fe-cb2b-4024-a8db-9cf6c4d0012a | < 1.1.1 |
HIGH | 7.5 | The "Accio | Responsive Onepage Parallax Agency WordPress Theme" theme for WordPress is vulnerable to sensitive informat… | — | wordfence |
| a52fb5f4-60ba-4077-95cd-e160a6d9a419 | < 2.2.51 |
HIGH | 7.5 | The Post Grid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on mul… | — | wordfence |
| a482f6bb-5277-480b-8ec9-230dd4135f7c | < 1.10.12 |
HIGH | 7.5 | The Court Reservation β Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection … | — | wordfence |
| a4766651-92a6-42c9-81bc-7ea25350f561 | < 5.5.3 |
HIGH | 7.5 | The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… | — | wordfence |
| a39dccb6-b635-44af-b0e0-c3010b719773 | < 1.3.4 |
HIGH | 7.5 | The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is… | — | wordfence |
| a3808160-7291-4833-ade6-c60b7feef81a | HIGH | 7.5 | The Cookiteer theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.8. This ma… | — | wordfence | |
| a37478a1-3e3e-4be0-aa96-ddafac0ff6c1 | < 2.5 |
HIGH | 7.5 | The DejaVu Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.4. This is d… | — | wordfence |
| a36c9a7e-830d-4a92-a330-29279387b3be | HIGH | 7.5 | The Riaxe Product Customizer plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter keys within… | — | wordfence | |
| a33af8c8-09a7-4f2d-9af3-c0c49a53a0e9 | HIGH | 7.5 | The Boutique theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.3. This mak… | — | wordfence | |
| a2f9da0c-aff8-4b48-901c-1199c95afdeb | < 2.24120000-WP6.7.1 |
HIGH | 7.5 | The Click & Pledge Connect Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … | — | wordfence |
| a2e7a86b-8c5d-46d1-a51e-1368c6a880fd | < 4.7.11 |
HIGH | 7.5 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to SQL Injection in versions up to,… | — | wordfence |
| a2c4b389-4a43-4b6d-ad19-1d6c201580cc | < 1.24.0 |
HIGH | 7.5 | The Gmedia Photo Gallery plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.… | — | wordfence |
| a241db4e-bd13-461f-9603-d3a28ba9e018 | HIGH | 7.5 | The Crete Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.3 due to insuff… | — | wordfence | |
| a23bb496-06f0-4c4b-91db-c82b07824213 | < 1.1.12 |
HIGH | 7.5 | The Premmerce Wishlist for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and includ… | — | wordfence |
| a1f258b0-041e-4795-95a4-66431f8c84b2 | HIGH | 7.5 | The WPAMS plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 44.0 (17-08-2023) due to… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →