Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 3 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 54a37c4a-44c7-47fd-8f2d-486372fb643c | CRITICAL | 10.0 | The Viral Signup β limited opt-in with viral refferal sharing plugin for WordPress is vulnerable to SQL Injection in a… | — | wordfence | |
| 5432bdd1-9b56-4f74-a468-011f942bdd89 | CRITICAL | 10.0 | The Slash WP theme for WordPress is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in all vers… | — | wordfence | |
| 51fd6124-4954-4827-a665-c2d94d74a512 | < 1.4.1 |
CRITICAL | 10.0 | The VikRentCar plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.0 due to insuff… | — | wordfence |
| 43a7f1b0-c2c0-4832-9819-22625c8b727e | < 2.5.27 |
CRITICAL | 10.0 | The HTML5 Video Player β Best WordPress Video Player Plugin and Block plugin for WordPress is vulnerable to SQL Inject… | — | wordfence |
| 4143febf-92b3-42e7-9499-9ea83d7727d9 | < 7.3 |
CRITICAL | 10.0 | The Chauffeur Taxi Booking System for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to miss… | — | wordfence |
| 3df23ba9-337f-49ac-9d1f-6b993430a1ce | CRITICAL | 10.0 | The Propovoice Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.0.3 due to … | — | wordfence | |
| 3aca0d51-6f70-4f35-873a-e23b4d7bae41 | CRITICAL | 10.0 | The WpStickyBar β Sticky Bar, Sticky Header plugin for WordPress is vulnerable to SQL Injection via the 'banner_id' pa… | — | wordfence | |
| 32df7bdb-d99d-4548-8960-3fefdf635753 | < 1.94 |
CRITICAL | 10.0 | The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to SQL Injection via the 'onesignal_ext… | — | wordfence |
| 312a6601-c914-4661-82ff-6f8bac849442 | CRITICAL | 10.0 | The Woo Inquiry plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 0.1 due to ins… | — | wordfence | |
| 2eaa5a5c-c11f-40d0-be69-c3ec8029a819 | < 2.0.0 |
CRITICAL | 10.0 | The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… | — | wordfence |
| 2c4c13c9-6f43-4a4d-b825-e246bf9a1e9c | < 5.7.9 |
CRITICAL | 10.0 | The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.8 due to insu… | — | wordfence |
| 25999d1f-9085-4410-b76a-3570f2517bdd | < 1.7.0 |
CRITICAL | 10.0 | The Docket (WooCommerce Collections / Wishlist / Watchlist) plugin for WordPress is vulnerable to SQL Injection in versi… | — | wordfence |
| 226e772e-6973-4ff0-9a02-5be503f292c8 | < 2.0.1 |
CRITICAL | 10.0 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ… | — | wordfence |
| 21da3c10-72b9-4c04-8586-dcf6dcf55852 | < 7.0.1 |
CRITICAL | 10.0 | The Woocommerce OpenPos plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.4.4 due … | — | wordfence |
| 20fdbe6b-45a8-41f4-8dde-35a0f9ea04a1 | < 3.3.1 |
CRITICAL | 10.0 | The Easy Digital Downloads plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.12 … | — | wordfence |
| 1feb3fa0-5fd9-443a-830c-cb1700ff30df | < 1.8 |
CRITICAL | 10.0 | The Layouts for Elementor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check… | — | wordfence |
| 191c3c86-0704-4d3c-b7ba-22cefbdc65f1 | < 3.26.7 |
CRITICAL | 10.0 | The WishList Member X plugin for WordPress is vulnerable SQL Injection in versions up to, and including, 3.25.1 due to i… | — | wordfence |
| 1829b4b7-5042-4972-ad05-e9a7adbf3026 | < 2.7.97 |
CRITICAL | 10.0 | Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attacke… | — | wordfence |
| 1261ad29-e4c1-4385-9f41-d3f3eecbb7dc | CRITICAL | 10.0 | The Feather12 theme for WordPress is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in all ver… | — | wordfence | |
| 10bad8bc-ee0a-48e6-b7f9-6651a7ab3049 | < 6.6 |
CRITICAL | 10.0 | The ARforms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all vers… | — | wordfence |
| 1081eeb1-3240-478d-8679-7bf9293b5a95 | < 2.1.12 |
CRITICAL | 10.0 | An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalat… | — | wordfence |
| 050b6ad4-f1e4-403f-9e0e-7fc18504f661 | < 5.3.9 |
CRITICAL | 10.0 | The XStore Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.3.8 due to insuf… | — | wordfence |
| fc085413-db43-43e3-9b60-aeb341eed4e1 | < 9.0.2 |
CRITICAL | 9.9 | The Quiz And Survey Master β Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL… | — | wordfence |
| f7fc91cc-e529-4362-8269-bf7ee0766e1e | < 4.6.13 |
CRITICAL | 9.9 | The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Tw… | — | wordfence |
| f600361c-cf7a-498c-aa3d-beeb28d27101 | < 1.5.67 |
CRITICAL | 9.9 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file upl… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →