Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 315 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 4c4d5902-2d01-4e8f-8d98-65e7be32f5c0 | < 3.1.5 |
HIGH | 7.5 | The WP-BusinessDirectory plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.4 due… | — | wordfence |
| 4c447dbb-f8fb-4b46-9c47-20ab7330bbaa | < 2.4.15 |
HIGH | 7.5 | The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all version… | — | wordfence |
| 4bfa2246-41a8-4d06-8dc9-57fc4be8e1c4 | < 1.0.9 |
HIGH | 7.5 | The IMDB Profile Widget plugin for WordPress is vulnerable to Local File Inclusion in versions up to 1.0.9 via the 'url'… | — | wordfence |
| 4beafd91-1b89-484b-8053-b1bffdaf163a | < 2.0 |
HIGH | 7.5 | The Aspose.Words β Import and Export word documents plugin for WordPress is vulnerable to Arbitrary File Download in v… | — | wordfence |
| 4b9a325d-1291-458a-aa6c-f2ee55b3b6cd | < 3.0.5 |
HIGH | 7.5 | The Graphina plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.4. T… | — | wordfence |
| 4b800842-f757-4e1c-8c93-ef21f90a11c7 | < 3.6.0 |
HIGH | 7.5 | The SSL Wireless SMS Notification plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … | — | wordfence |
| 4b34dd60-359c-44a0-9e47-dc8c4e66b50e | < 0.9.4 |
HIGH | 7.5 | The script pub/sns.php in the W3 Total Cache plugin (versions 0.9.2.6 through 0.9.3) allows remote attackers to read arb… | — | wordfence |
| 4b15c991-5256-405c-8382-85dba6f032ba | < 2.0.3 |
HIGH | 7.5 | The Live Composer β Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all v… | — | wordfence |
| 4ac3dae6-1890-44ba-9671-84f77807ffe5 | < 3.0.0 |
HIGH | 7.5 | The OneLogin SAML SSO for WordPress is vulnerable to DDoS in versions up to, and including, 2.8.0. This is due to an XML… | — | wordfence |
| 4ac18db7-324f-41f0-b03a-59635dd97d22 | HIGH | 7.5 | The MinimogWP theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.9.6. This ma… | — | wordfence | |
| 4aa8342f-1f36-4eb5-8b69-ab90fd85e5cb | < 1.4.5 |
HIGH | 7.5 | The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Inject… | — | wordfence |
| 4a1a4186-216e-4ed1-860c-fe345ac6e62a | < 3.4.1 |
HIGH | 7.5 | includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary… | — | wordfence |
| 49fe8e8b-95fa-4c25-89cf-49566543206c | < 3.1.66 |
HIGH | 7.5 | The Ditty β Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in … | — | wordfence |
| 49b36cde-39d8-4a69-8d7c-7b850b76a7cd | < 3.6.2 |
HIGH | 7.5 | The Slider & Popup Builder by Depicter plugin for WordPress is vulnerable to generic SQL Injection via the βs' paramet… | — | wordfence |
| 498f7ece-e33a-4489-aeb9-1660abe0b4a5 | < 3.4 |
HIGH | 7.5 | The Awake Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 3.3. This is du… | — | wordfence |
| 4985680e-f7ba-40c7-bca9-f347f1c1cb3b | < 2.9.1 |
HIGH | 7.5 | The TI WooCommerce Wishlist plugin for WordPress is vulnerable to SQL Injection via the 'lang' parameter in all versions… | — | wordfence |
| 497cfc87-85ac-41d0-aeea-63c5fc64db0d | < 4.1.2 |
HIGH | 7.5 | The Team - WordPress Team Member Showcase Plugin for WordPress is vulnerable to directory traversal via the 'resources/d… | — | wordfence |
| 492ce5d0-02b5-4b11-a4a0-ca1a6438faad | < 1.12.1 |
HIGH | 7.5 | The belingoGeo plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.12.0 vi… | — | wordfence |
| 48ebb9d6-05d5-4197-8fa4-cc7154c00669 | HIGH | 7.5 | The Golo Framework plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.3. T… | — | wordfence | |
| 48cda7b8-edc8-4c2d-bef9-3ee12dc0ea32 | < 12.8.1.1 |
HIGH | 7.5 | The The7 theme for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 12.8.1.1. This make… | — | wordfence |
| 488f1a2f-01c8-40cf-b52f-d707271105f5 | HIGH | 7.5 | The External Login plugin for WordPress is vulnerable to SQL Injection via the 'log' parameter in all versions up to, an… | — | wordfence | |
| 48715526-f423-40ce-8c7f-d7713c57ce36 | < 5.9.2 |
HIGH | 7.5 | The Podlove Web Player plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.9.… | — | wordfence |
| 48400e64-40b4-4f96-8346-1a104ae89761 | < 4.2.0 |
HIGH | 7.5 | The Houzez Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inclu… | — | wordfence |
| 47a00c6f-958f-41c7-a213-c858d8fac2ed | < 3.5.1 |
HIGH | 7.5 | The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integ… | — | wordfence |
| 4794858f-ebaf-4adf-ab08-309964c18c00 | < 2.5.5 |
HIGH | 7.5 | A flaw in Give before 2.5.5, a WordPress plugin, allowed unauthenticated users to bypass API authentication methods and … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →