Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 311 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 5c0f3248-fef6-48a5-b2e1-f2778528fba1 | < 3.9.30 |
HIGH | 7.5 | The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… | — | wordfence |
| 5c0f02ad-f5f1-42b1-8116-e391aaa85430 | < 3.7.1 |
HIGH | 7.5 | The BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the `get_current_letter_docs` and `docs_sort_… | — | wordfence |
| 5c03c07f-8f41-47c2-bc95-d92a623f5f7c | < 2.10.5 |
HIGH | 7.5 | The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4… | — | wordfence |
| 5be9d0ff-5d9c-4e80-a4d7-66ef4859a959 | < 1.9.8 |
HIGH | 7.5 | The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to… | — | wordfence |
| 5bcf1f02-0946-4e96-a81b-00c7c48d64b3 | HIGH | 7.5 | The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,… | — | wordfence | |
| 5bae7516-e9dd-4c0c-b687-9cbe09b4c8bc | < 1.0 |
HIGH | 7.5 | Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress… | — | wordfence |
| 5baa15a6-c2c5-412d-a065-f13d431df4a5 | HIGH | 7.5 | The Woodly Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4 due to insuffi… | — | wordfence | |
| 5b9e037d-30bd-479b-9c4f-4c9082a04e08 | < 1.5 |
HIGH | 7.5 | The Construct Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.4. This i… | — | wordfence |
| 5b9a0751-934f-4830-80c9-39260ec1cb4f | < 1.8.13 |
HIGH | 7.5 | An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially… | — | wordfence |
| 5b8fb306-cb48-4667-b2b5-e5014ef485e2 | HIGH | 7.5 | The Print Science Designer plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.… | — | wordfence | |
| 5b826595-c977-4550-aa52-93bcd4a365fe | HIGH | 7.5 | The Antioch theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to lib/scripts… | — | wordfence | |
| 5b23bd5c-db27-4d63-8461-1f36958a2ff6 | HIGH | 7.5 | The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the… | — | wordfence | |
| 5b1b0dbd-084a-44e5-b711-1d5bafb0a300 | HIGH | 7.5 | Directory traversal vulnerability in wp-download.php in the WP Custom Pages module 0.5.0.1 for WordPress allows remote a… | — | wordfence | |
| 5b050546-fe37-4c3b-a9e4-46a65f19e64d | < 6.4.1 |
HIGH | 7.5 | The Elessi theme for WordPress is vulnerable to Local File Inclusion in versions up to 6.4.1. This makes it possible for… | — | wordfence |
| 5ae32a38-5be3-47d0-9c56-2fcda7662c71 | < 2.29.0 |
HIGH | 7.5 | The AffiliateWP plugin for WordPress is vulnerable to SQL Injection via the ajax_get_affiliate_id_from_login function in… | — | wordfence |
| 5ac49a00-dabc-4cd9-9032-c038ede3fd8f | < 2.0 |
HIGH | 7.5 | The Bricks theme for WordPress is vulnerable to blind SQL Injection via the βpβ parameter in all versions up to, and… | — | wordfence |
| 5a349c4f-d2e7-47af-9013-3cfa496b3b8c | < 2.5.6 |
HIGH | 7.5 | The Request a Quote plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.5.5 via the… | — | wordfence |
| 59fe7630-ab94-419f-aca5-39b74d86ae4e | < 1.8.8 |
HIGH | 7.5 | The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is… | — | wordfence |
| 59ee0ca2-846d-4ae8-ad19-7c3826861aeb | < 2.13.3 |
HIGH | 7.5 | The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… | — | wordfence |
| 59da86c4-1a68-4077-8b56-9c6c8afe26ad | < 7.1.0 |
HIGH | 7.5 | The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via … | — | wordfence |
| 59b949ef-6ab2-4381-abf9-aa0c72b654c3 | HIGH | 7.5 | The Kriya theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.4 via deserializ… | — | wordfence | |
| 5991c86b-6785-41a6-a5df-c65e8a28201c | < 1.9.180 |
HIGH | 7.5 | The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versi… | — | wordfence |
| 5979f2eb-2ca8-4b06-814c-c4236bb81af0 | < 2.12.4 |
HIGH | 7.5 | The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type vali… | — | wordfence |
| 5970b8d6-0041-4c30-a6ce-fe67ebf415f5 | < 1.6.10.0 |
HIGH | 7.5 | The Appointment Booking Calendar β Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized acc… | — | wordfence |
| 5900d571-dc97-4c81-8ff3-7d7350b4c89f | < 1.9 |
HIGH | 7.5 | The RokIntroScroller plugin for WordPress is vulnerable to Full Path Disclosure via the 'src' parameter in the 'thumb.ph… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →