Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 304 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 7a9cfd7a-7e6a-4a1f-86bc-b53ef461dde2 | HIGH | 7.5 | The Recent Backups plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 0.7 via t… | — | wordfence | |
| 7a7677a4-0cd5-496e-82cb-f6582e63475d | < 1.5.9 |
HIGH | 7.5 | includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes … | — | wordfence |
| 7a5e08d8-c6ef-42a3-9599-28c3bfb35017 | < 2.9.18 |
HIGH | 7.5 | The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in … | — | wordfence |
| 7a46c049-367d-4a67-9607-c74ef0b96c71 | < 3.6.75 |
HIGH | 7.5 | The Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including… | — | wordfence |
| 7a1a46b3-77a1-4d69-9a0d-90794e78f828 | HIGH | 7.5 | The Apptha Slider Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.5… | — | wordfence | |
| 7a140b07-e8b4-48a5-8585-79ad2744f3f3 | HIGH | 7.5 | The GG Bought Together for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and includ… | — | wordfence | |
| 7a0ed307-091a-473f-a95f-f270ec4dc2f1 | < 10.3.1 |
HIGH | 7.5 | The SmartMag theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 10.3.0. This ma… | — | wordfence |
| 79ffe548-0005-4f5e-873f-a1afec64a251 | < 1.3.8.9 |
HIGH | 7.5 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in … | — | wordfence |
| 795002a5-1233-4472-93fe-78e33e53aa80 | HIGH | 7.5 | The WP Multistore Locator plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5.2 du… | — | wordfence | |
| 793e650c-27f7-4eff-9922-8e01ba24e96d | < 2.1.1 |
HIGH | 7.5 | Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers t… | — | wordfence |
| 793a2096-3332-412e-a45a-a7367b1209a3 | < 1.1.2 |
HIGH | 7.5 | The AL Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the check_act… | — | wordfence |
| 7914ebe6-b5e1-4a1a-8794-80f515e6c9f6 | < 2.9.1.7 |
HIGH | 7.5 | The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_… | — | wordfence |
| 790f93b0-eb69-473f-a726-bfe215f5d870 | < 10.14.9 |
HIGH | 7.5 | The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' param… | — | wordfence |
| 7908d167-f831-4ed0-b754-2b390b5c3b2c | < 4.4.6.1 |
HIGH | 7.5 | The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versio… | — | wordfence |
| 78f964a7-bed3-435e-94c5-750883a0c836 | HIGH | 7.5 | The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type param… | — | wordfence | |
| 78e7b65d-91f8-477e-b992-3148c1b65d7b | < 1.0.8 |
HIGH | 7.5 | The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Sensitive Information Exp… | — | wordfence |
| 78ba132c-b5b4-4999-a0ec-67d17ae2857f | < 4.1.12 |
HIGH | 7.5 | The Social Web Suite – Social Media Auto Post, Social Media Auto Publish plugin for WordPress is vulnerable to Directo… | — | wordfence |
| 78914fef-6ab4-49b8-8c67-3a634759194c | < 1.1.0 |
HIGH | 7.5 | The Tinymce Thumbnail Gallery plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… | — | wordfence |
| 788422c4-e070-48aa-a85d-a5d5a25a6a1d | < 1.52.2 |
HIGH | 7.5 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Tra… | — | wordfence |
| 786b1b8f-7f63-4ac4-a808-668b38bf0fb4 | < 2.2.1 |
HIGH | 7.5 | The Vibes plugin for WordPress is vulnerable to time-based SQL Injection via the ‘resource’ parameter in all version… | — | wordfence |
| 784998a7-550d-4299-9995-af01e5ee1d21 | HIGH | 7.5 | The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the emdedSc() functi… | — | wordfence | |
| 782d91d4-4e52-4ce6-9fd3-8f9a816856ce | < 2.32.7 |
HIGH | 7.5 | The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is … | — | wordfence |
| 7809f5ec-0b76-4244-ab9d-b6a90cf74716 | HIGH | 7.5 | The WP AutoKeyword plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to insu… | — | wordfence | |
| 77d6d38a-f590-4188-8941-ea6936ae5cf4 | < 3.8.9.1 |
HIGH | 7.5 | The JetEngine plugin for WordPress is vulnerable to SQL Injection in versions up to 3.8.9.1 due to insufficient escaping… | — | wordfence |
| 77cea6a1-d5e8-459c-97cc-9dc8f7c0f48f | < 1.0 |
HIGH | 7.5 | Absolute path traversal vulnerability in lib/download.php in the IBS Mappro plugin before 1.0 for WordPress allows remot… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →