Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 32 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| be2ba063-140e-4c92-a57d-79f366631b3d | CRITICAL | 9.8 | The Login with Salesforce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includi… | — | wordfence | |
| be1ab218-37bd-407a-8cb9-66f761849c21 | < 3.1.2 |
CRITICAL | 9.8 | The Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This i… | — | wordfence |
| be0a6471-a78e-4fab-8ef5-93d16859bff4 | < 4.4 |
CRITICAL | 9.8 | The WooCommerce Dropshipping Premium plugin for WordPress is vulnerable to SQL Injection via an unauthenticated REST end… | — | wordfence |
| bd9e5654-387e-4fc3-a6eb-2eface298a9c | < 3.5.3 |
CRITICAL | 9.8 | The Amazon Product in a Post plugin for WordPress is vulnerable to generic SQL Injection via the ‘appip-cache-id’ pa… | — | wordfence |
| bd7ee2d7-4588-4cb9-86ca-0daef421dd86 | CRITICAL | 9.8 | The Hungred Post Thumbnail plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… | — | wordfence | |
| bd332f49-5aa9-4207-89db-84692a6430e0 | < 0.9.2.6 |
CRITICAL | 9.8 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in… | — | wordfence |
| bd2ad909-a254-461d-a24f-e9803353bae4 | CRITICAL | 9.8 | The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to privilege escalation via account … | — | wordfence | |
| bcd7932d-8298-43d2-bc03-932e551a2ec6 | CRITICAL | 9.8 | The WP Dropbox Dropins plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including… | — | wordfence | |
| bcbbbd31-3205-4466-96f5-f9cd7e7cf083 | CRITICAL | 9.8 | The CouponXxL theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.0.0. Thi… | — | wordfence | |
| bcb756d0-425e-48ae-bd7f-ec9404679aea | < 3.0.8 |
CRITICAL | 9.8 | The Feedweb plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in versions up to, and includ… | — | wordfence |
| bca8b173-8e7c-41ad-9316-b38cc2ce0e66 | < 1.4.0 |
CRITICAL | 9.8 | The WP Pipes plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.33 due to insuffic… | — | wordfence |
| bca0bc1d-c373-4ccf-928e-14f3bd4bc53c | < 2.2.4 |
CRITICAL | 9.8 | The Healsoul theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.3. This mak… | — | wordfence |
| bc7e6844-23e2-4523-8261-21d4cba87db3 | < 1.0.2 |
CRITICAL | 9.8 | The Theme per user plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 1.0.2 (exclusive) vi… | — | wordfence |
| bc72fc26-c291-4e57-8038-babaa51c1b73 | CRITICAL | 9.8 | The Matix Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privile… | — | wordfence | |
| bc656765-1eac-4a96-99e9-c22d64984923 | CRITICAL | 9.8 | The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and includ… | — | wordfence | |
| bc3efc42-7cf5-4dcd-9653-891deaae19c3 | < 7.0.5 |
CRITICAL | 9.8 | A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo… | — | wordfence |
| bbeb32a8-5acf-4a68-859d-98652e8ff5d1 | < 4.0 |
CRITICAL | 9.8 | The Email Before Download plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, … | — | wordfence |
| bbd1e68f-1f84-40d6-9ecd-34280c3c5099 | < 1.8.7 |
CRITICAL | 9.8 | The Yet Another Stars Rating plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including… | — | wordfence |
| bbcd1f31-4952-4c96-9080-804fc7d70c28 | CRITICAL | 9.8 | The QRcode Login for WeChat plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includ… | — | wordfence | |
| bbc2a1f7-4c3c-4f37-a187-572f40e9b792 | < 13.1.5 |
CRITICAL | 9.8 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t… | — | wordfence |
| bbaac6b6-0871-4745-b981-55d7e9219467 | < 1.2.1 |
CRITICAL | 9.8 | The Rapyd Payment Extension for WooCommerce theme for WordPress is vulnerable to PHP Object Injection in versions up to,… | — | wordfence |
| bba4f30f-fc21-4387-a29e-4e4a115d7c3c | < 21.2.8 |
CRITICAL | 9.8 | The Apocalypse Meow plugin for WordPress is vulnerable to Authentication Bypass in versions 21.1.3 - 21.2.7. This is due… | — | wordfence |
| bb979c91-6795-4365-a61b-2cf67a9c8223 | CRITICAL | 9.8 | The thecotton theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the up… | — | wordfence | |
| bb8232cd-4fd5-4e0f-90d0-91e5eb7e70c8 | < 1.2.1 |
CRITICAL | 9.8 | SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to ex… | — | wordfence |
| bb6cd3a6-565e-4acf-82f0-25e85f0678bb | CRITICAL | 9.8 | The User Control plugin for WordPress is vulnerable to generic SQL Injection via the 'users' parameter in versions up to… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →