Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 309 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 65c8ea6c-85f1-4e96-995f-57200819280e | < 2.1 |
HIGH | 7.5 | The Myriad Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.1. This is d… | — | wordfence |
| 659eb886-dbee-4e5f-a769-17447aad8f33 | < 9.3 |
HIGH | 7.5 | The LMS theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.2 due to insufficient esc… | — | wordfence |
| 6565e345-3374-43d9-9789-f0d9138dc3e8 | < 5.0.5 |
HIGH | 7.5 | The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' para… | — | wordfence |
| 653e20ae-f018-41b5-a973-f73fddae70e5 | < 1.2.13 |
HIGH | 7.5 | The Quentn WP plugin for WordPress is vulnerable to SQL Injection via the 'qntn_wp_access' cookie in all versions up to,… | — | wordfence |
| 653ab9cb-7084-47e4-b5e3-6788fa5d7496 | < 2.2.5 |
HIGH | 7.5 | The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX acti… | — | wordfence |
| 649cbd38-d926-4638-9fb9-6704befa1660 | < 0.9.7 |
HIGH | 7.5 | Absolute path traversal vulnerability in reviews.php in the WP AmASIN - The Amazon Affiliate Shop plugin 0.9.6 and earli… | — | wordfence |
| 648941b8-d1ab-4587-bd87-f23008ac9a00 | HIGH | 7.5 | The Infility Global plugin for WordPress is vulnerable to unauthenticated SQL Injection via the 'infility_get_data' API … | — | wordfence | |
| 6481f4c7-2a62-457f-b21e-57e762aab29e | < 3.0.5 |
HIGH | 7.5 | The BuddyBoss Platform plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.… | — | wordfence |
| 640d36ac-7a25-437e-8b0a-8c5beceb14bf | < 2.1 |
HIGH | 7.5 | The Myriad Theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.0. This is d… | — | wordfence |
| 6404476e-0c32-4f8e-882f-6a1785ba5748 | < 7.9.9 |
HIGH | 7.5 | The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure via Directory Listing… | — | wordfence |
| 63ae3a9d-1e6b-4784-8429-04be2a89b6cb | < 1.9 |
HIGH | 7.5 | The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the … | — | wordfence |
| 6351d3f7-2d10-4fcf-b7c1-88ce529cd9f4 | < 2.3.1 |
HIGH | 7.5 | The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the … | — | wordfence |
| 634f6c42-6708-4e39-afdc-7838d3368fb4 | HIGH | 7.5 | The Schedule plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.0 due to insuffic… | — | wordfence | |
| 62eb136f-3cb0-40dc-a154-015a7fa1077b | < 1.2.6 |
HIGH | 7.5 | The ContentStudio plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including,… | — | wordfence |
| 62e223a5-768f-4743-99a5-2797fff7e976 | < 8.14.1 |
HIGH | 7.5 | The MapSVG – Vector maps, Image maps, Google Maps plugin for WordPress is vulnerable to SQL Injection in versions up t… | — | wordfence |
| 62bb2fef-60aa-4c88-8cef-a832d65b4945 | HIGH | 7.5 | The WordPress Upload Files Anywhere plugin for WordPress is vulnerable to Path Traversal in all versions up to, and incl… | — | wordfence | |
| 62b56147-4cb2-4824-aa49-74ef80d373e1 | HIGH | 7.5 | The Soledad theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 8.7.0. This make… | — | wordfence | |
| 62654952-830d-430c-b852-11ba8652716d | < 3.5 |
HIGH | 7.5 | The Wilmër theme for WordPress is vulnerable to Local File Inclusion in versions up to 3.5. This makes it possible for … | — | wordfence |
| 6122682d-6725-422c-9be8-339e4fb039a7 | HIGH | 7.5 | The Boldermail plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.4.0 via de… | — | wordfence | |
| 6113e51e-d842-433a-ab0a-92ea108917a3 | < 6.2.1 |
HIGH | 7.5 | The WP OAuth Server ( Login with WordPress ) plugin for WordPress is vulnerable to SQL Injection in versions up to, and … | — | wordfence |
| 60e2f3d3-c9f0-4d06-960a-6d796a280433 | < 5.6 |
HIGH | 7.5 | The Limit Login Attempts (Spam Protection) plugin for WordPress is vulnerable to SQL Injection in all versions up to, an… | — | wordfence |
| 60cd2178-858e-4e24-8967-13b04f675d2d | HIGH | 7.5 | The ArielBrailovsky-ViralAd plugin for WordPress is vulnerable to SQL Injection via the 'text' and 'id' parameters of th… | — | wordfence | |
| 608d46e3-ef56-48b1-b965-b324e68e8a8b | < 2.3.4 |
HIGH | 7.5 | The Fraud Prevention For WooCommerce and EDD plugin for WordPress is vulnerable to unauthorized access due to a missing … | — | wordfence |
| 607073ad-3a4a-4a21-af0f-3ade81382605 | < 1.5.4 |
HIGH | 7.5 | The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensit… | — | wordfence |
| 603f0c9d-6964-4911-b4a5-bdad24a1a8dd | HIGH | 7.5 | The Kiwiz - Certification de facturation - Woocommerce plugin for WordPress is vulnerable to unauthenticated arbitrary f… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →