Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 299 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 9232b77e-e23f-4e91-8ea3-5e740956f51e | HIGH | 7.5 | The PhotoStack Gallery plugin for WordPress is vulnerable to SQL Injection via the 'postid' parameter in all versions up… | — | wordfence | |
| 922fd4a4-88ea-417e-90c2-0062b5859a14 | < 2.1.2 |
HIGH | 7.5 | The Active Woot Products Tables for WooCommerce. 100% FREE plugin for WordPress is vulnerable to SQL Injection in vers… | — | wordfence |
| 91d52a64-8dc1-4923-be0b-06800382151e | < 28.1.5 |
HIGH | 7.5 | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to bli… | — | wordfence |
| 917c70f5-154c-4c49-b06b-109cc0277a1a | < 1.1.25 |
HIGH | 7.5 | The SMTP Mailer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… | — | wordfence |
| 9169931c-a679-4801-b33b-08c4f464dc43 | HIGH | 7.5 | The Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App plugin for WordPress is vulnerable to … | — | wordfence | |
| 9167e4bd-74be-46c9-b06e-566c13c02c7d | < 2.10.4 |
HIGH | 7.5 | In the WP Rocket plugin 2.10.3 for WordPress, the Local File Inclusion mitigation technique is to trim traversal charact… | — | wordfence |
| 91654765-6631-4eb4-9971-32b7db7933e1 | < 3.1.4 |
HIGH | 7.5 | The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in al… | — | wordfence |
| 91221712-8f66-4c6f-94fb-75c34a7f1fa8 | < 8.7.5 |
HIGH | 7.5 | The BackupBuddy plugin for WordPress is vulnerable to unauthenticated arbitrary file downloads via the 'local-download' … | — | wordfence |
| 907a02b8-6965-4d0b-b4bf-c8fc0201ee12 | HIGH | 7.5 | Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn't check that the user is authoriz… | — | wordfence | |
| 90775c17-4cd5-47e5-afa9-9413988b8638 | < 1.6.7 |
HIGH | 7.5 | The WerkStatt plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.6. This m… | — | wordfence |
| 9040e2bb-e30a-4e18-b486-76aa601ae888 | HIGH | 7.5 | The BookPro - Appointment Booking WordPress Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to … | — | wordfence | |
| 901e015c-58fc-40ac-b078-f7040cbed274 | < 9.1.08.002 |
HIGH | 7.5 | The WP Photo Album Plus plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.1.08.001… | — | wordfence |
| 9013e816-1f5c-48cc-b79b-37cd9a75c2f6 | < 1.22.16 |
HIGH | 7.5 | Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authe… | — | wordfence |
| 8f9cf8d3-ebc1-4d94-909e-938beb58601e | < 4.4.9 |
HIGH | 7.5 | The WpEvently plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.4.8 via des… | — | wordfence |
| 8f630a7c-9082-400d-9d09-1280330ffbc6 | HIGH | 7.5 | The Advance Seat Reservation Management for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions … | — | wordfence | |
| 8f562e33-2aef-46f0-8a65-691155ede9e7 | < 5.3.8 |
HIGH | 7.5 | The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.3.7. T… | — | wordfence |
| 8f539e25-5483-417d-a3c5-e7034c03c673 | < 2.10.2 |
HIGH | 7.5 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… | — | wordfence |
| 8f491d48-935c-4fd9-a342-44d98c5601b3 | < 1.7.7 |
HIGH | 7.5 | The WPCOM Member plugin for WordPress is vulnerable to time-based SQL Injection via the ‘user_phone’ parameter in al… | — | wordfence |
| 8f18e3b1-4f91-4718-8da8-ad23c8d6da75 | < 2.5.5 |
HIGH | 7.5 | The Houzez Property Feed plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.5.… | — | wordfence |
| 8efe2ccf-33cb-4db3-bc3d-ead826adb7d0 | HIGH | 7.5 | The Easy Captcha plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… | — | wordfence | |
| 8efe0759-a3b6-43b7-b333-0e72df1ff96d | HIGH | 7.5 | The PeakShops theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.9 via dese… | — | wordfence | |
| 8ea2ce90-6c8c-4a31-8faa-4ab99879d8b8 | < 6.15.1.1 |
HIGH | 7.5 | The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all … | — | wordfence |
| 8e8d7aa4-d2df-47ec-a5dc-c2cfd74763aa | < 2.2.7 |
HIGH | 7.5 | The Digiqole theme for WordPress is vulnerable to Local File Inclusion in versions up to 2.2.7. This makes it possible f… | — | wordfence |
| 8e68ec8c-e46a-4886-b386-9664a8e5ba26 | HIGH | 7.5 | The CarZone - A Complete Car Dealer HTML Wire-Frame theme for WordPress is vulnerable to PHP Object Injection in all ver… | — | wordfence | |
| 8e361473-8ed6-41d0-b409-2436189c1120 | < 5.16.5 |
HIGH | 7.5 | Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not proper… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →