Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 301 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 898c5554-fd02-47a2-a1f9-1c488cfab57e | < 1.5.1 |
HIGH | 7.5 | The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… | — | wordfence |
| 894080c3-f00a-491b-bebf-469e35118965 | HIGH | 7.5 | The Download Media Library plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a… | — | wordfence | |
| 88f8fa25-e3d5-4dfd-aae5-68b5880ffd53 | < 3.5.2 |
HIGH | 7.5 | The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for Word… | — | wordfence |
| 88f1eb9a-f3bb-4b62-975f-a6cb95850966 | < 8.3.10 |
HIGH | 7.5 | The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing fi… | — | wordfence |
| 88b3a69d-2c94-48e6-b965-8a67b2fe42b2 | < 2.3.11 |
HIGH | 7.5 | The WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3.10 via … | — | wordfence |
| 88a46a24-6d46-44cc-ac01-70a1c329cb51 | < 6.11.11 |
HIGH | 7.5 | The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a mis… | — | wordfence |
| 886b612a-d0d1-4880-b423-eb62410a28cd | < 8.3.2 |
HIGH | 7.5 | The Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions plugin for WordPress … | — | wordfence |
| 883e1f3c-7e47-4522-ae8c-a9a6b4160be2 | < 2.10.8 |
HIGH | 7.5 | The PowerPack Pro for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… | — | wordfence |
| 8815abff-6bd5-4ce4-9adf-afd699f628c4 | < 2.6.3 |
HIGH | 7.5 | The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related t… | — | wordfence |
| 87d4dd4a-b1e2-4d08-aef1-77e58aa7531d | < 3.3.30 |
HIGH | 7.5 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function… | — | wordfence |
| 875b15a1-c747-4a74-a77e-d541f92468a3 | < 1.5.8 |
HIGH | 7.5 | The Maps Marker Pro plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.5.7. This a… | — | wordfence |
| 8755ab3f-ee77-44ea-8620-590f1f1cb333 | < 3.18.1 |
HIGH | 7.5 | The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … | — | wordfence |
| 871f6611-3b5e-4e36-992c-726b31e88c95 | HIGH | 7.5 | The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of th… | — | wordfence | |
| 86d8ea64-39a7-46c1-bc21-39814c2ac869 | < 11.6.8 |
HIGH | 7.5 | The RSVPMarker plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 11.6.7 due to insu… | — | wordfence |
| 86a5adaf-02b7-4b42-a048-8bc01f07656b | < 1.14.10 |
HIGH | 7.5 | The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Se… | — | wordfence |
| 85fdf21b-0d16-4404-aad0-a2eae12f5db5 | < 2.2.6 |
HIGH | 7.5 | The Frontend Dashboard plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.2.5 due t… | — | wordfence |
| 85abf905-ec47-4847-b3d6-8570fd5eb287 | < 4.0.4 |
HIGH | 7.5 | The BackWPup – WordPress Backup Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all ver… | — | wordfence |
| 8520ae92-0b37-4f7a-afd1-427e1a9a31f1 | HIGH | 7.5 | The Kids Heaven theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.2 via dese… | — | wordfence | |
| 8457c5e1-9c31-4a1a-a221-36647753a877 | < 5.1.2 |
HIGH | 7.5 | In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Aut… | — | wordfence |
| 843ef712-6ca6-44d2-825f-7ce9a82d74e6 | < 1.4.7.1 |
HIGH | 7.5 | The Duplicator – WordPress Migration Plugin WordPress plugin is vulnerable to Unauthenticated System Information Discl… | — | wordfence |
| 83e396c3-e843-4337-bf90-894d9d7de2a8 | < 1.4.1 |
HIGH | 7.5 | When visiting a site running Web-Stat < 1.4.1, the "wts_web_stat_load_init" function used the visitor’s browser to sen… | — | wordfence |
| 83c4a78e-f3e9-442d-99de-915a64132c32 | < 3.0.8 |
HIGH | 7.5 | The JobSearch plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 3.0.8. This m… | — | wordfence |
| 83b0534e-1b8d-46a8-9698-e7ca73e5ab57 | < 2.6.1 |
HIGH | 7.5 | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side reques… | — | wordfence |
| 838ccf02-2b01-42f8-b5bf-6fafbb2db673 | < 2.9.10 |
HIGH | 7.5 | The plugin Simple Job Board for WordPress is vulnerable to Information Disclosure in versions up to, and including, 2.9.… | — | wordfence |
| 836bac94-fd74-4ef9-a79b-4ea13de8f44f | < 0.9.2.5 |
HIGH | 7.5 | W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →