Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 298 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 96ad872f-9831-4113-99ae-322bcd2b6fbd | < 3.2.16 |
HIGH | 7.5 | The Cost Calculator Builder PRO plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘data’ … | — | wordfence |
| 968ead80-eed6-4a42-a3cd-73cf4cbbb1e5 | < 0.94 |
HIGH | 7.5 | The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation. | — | wordfence |
| 964601d5-8460-41c5-9791-ff9e3af964e3 | < 2.9.4.116 |
HIGH | 7.5 | The Simple Ads Manager Plugin for WordPress is vulnerable to Denial of Service in versions before 2.9.4.116. This is due… | — | wordfence |
| 9645b17e-6a7c-4cdd-ae43-7d2c84b624cc | < 3.1 |
HIGH | 7.5 | The Classic Addons – WPBakery Page Builder plugin for WordPress is vulnerable to Limited Local PHP File Inclusion in a… | — | wordfence |
| 95d2bf1a-0993-4553-a00e-6f555c3f15be | < 5.27.0 |
HIGH | 7.5 | The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subs… | — | wordfence |
| 95cd2bae-4ab7-4a0c-bb71-c17b119eaaa9 | < 2.0.5 |
HIGH | 7.5 | The All-in-One WP Migration plugin for WordPress is vulnerable to authorization bypass due to a missing capability check… | — | wordfence |
| 95b36b47-dbb7-47f7-ba0d-ce4c6b183617 | < 1.0.9 |
HIGH | 7.5 | The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to SQL… | — | wordfence |
| 959f7e13-ef58-4b02-a721-7bb10373aaaa | < 1.0.7 |
HIGH | 7.5 | The Wholesale Market for WooCommerce plugin for WordPress is vulnerable to arbitrary file download due to missing capabi… | — | wordfence |
| 959a086e-15f0-492a-a19b-3160ad47f1be | HIGH | 7.5 | The North theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.7.5 via deserial… | — | wordfence | |
| 9594b351-52ba-48a7-a875-a914b70ce7b8 | < 4.4.8 |
HIGH | 7.5 | The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to PHP Object Injection in versions up t… | — | wordfence |
| 9545cff3-fa65-4f2e-8a9f-98d884e5608f | < 4.0 |
HIGH | 7.5 | In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an… | — | wordfence |
| 953e10a1-df11-40d3-869c-2974a344630e | < 2.7.7 |
HIGH | 7.5 | The Advanced AJAX Page Loader plugin before 2.7.7 for WordPress has no protection against the reading of uploaded files … | — | wordfence |
| 9529babf-bf5e-4de1-bf84-2eae11832379 | < 3.0.2 |
HIGH | 7.5 | The Decent Comments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 3.0.2 (ex… | — | wordfence |
| 951b2a15-04c1-4c5b-9cef-146628079c36 | < 2.731 |
HIGH | 7.5 | The Post Pay Counter plugin before 2.731 for WordPress has no permissions check for an update-settings action. | — | wordfence |
| 94932f9a-89d4-47f1-941e-eb1bdd2df63f | HIGH | 7.5 | The Dental Care CPT plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 20.2 vi… | — | wordfence | |
| 93e0a1a1-fba6-4209-b679-e66d77870be2 | < 2.1.4 |
HIGH | 7.5 | The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPr… | — | wordfence |
| 93ca1959-1747-4141-9b48-1ae782b9700a | HIGH | 7.5 | The Devnex Addons For Elementor plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… | — | wordfence | |
| 936d8c03-31e4-4fd6-94f6-8b81afce315f | HIGH | 7.5 | The WP Google Review Slider plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.1 du… | — | wordfence | |
| 93224641-2079-4eb5-bf8f-82298d9d5ef6 | < 2.8.2 |
HIGH | 7.5 | The Meloo theme for WordPress is vulnerable to PHP Object Injection in versions up to 2.8.2 via deserialization of untru… | — | wordfence |
| 92e404ab-fe2b-45b3-b8ff-672f7888b747 | < 6.15.17.1 |
HIGH | 7.5 | The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.… | — | wordfence |
| 92dd10fa-0241-4238-9ed2-31de0dc450d7 | < 3.7.9 |
HIGH | 7.5 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to,… | — | wordfence |
| 92dbc405-a11c-4c2e-a98c-8dcb4e0b64e8 | HIGH | 7.5 | The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and i… | — | wordfence | |
| 92cdf0ca-8e63-4b2a-8bbc-d4ddf87eb6ca | HIGH | 7.5 | The Electio Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4 due to insuff… | — | wordfence | |
| 9264d7f3-cbd2-4528-8222-93a456332e9c | < 1.0.6 |
HIGH | 7.5 | The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to SQL Injection in versions up to… | — | wordfence |
| 925402a5-e203-4976-b0a9-88c974b540b9 | < 6.6.4 |
HIGH | 7.5 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injec… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →