Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 326 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 16f5a104-dce0-4249-91b9-67f99cce16d3 | < 3.5.26.1 |
HIGH | 7.5 | The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 … | — | wordfence |
| 1680078c-0dbe-4586-b793-3bf2ddea96ba | HIGH | 7.5 | Server-side request forgery (SSRF) vulnerability in proxy.php in the jRSS Widget plugin 1.2 and earlier for WordPress al… | — | wordfence | |
| 1663be8e-a6b8-4e0d-97d0-af7db2a2875c | < 5.7.2 |
HIGH | 7.5 | The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date… | — | wordfence |
| 1661bb28-e5b4-4319-84bb-6cbeac266147 | HIGH | 7.5 | The CF Internal Link Shortcode plugin for WordPress is vulnerable to SQL Injection via the 'post_title' parameter in all… | — | wordfence | |
| 15abde72-515a-4e1c-af4c-d9da56a5cbe2 | < 3.1.2 |
HIGH | 7.5 | The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in th… | — | wordfence |
| 15a533e6-675f-4c32-9b88-111e6a5f6bf7 | < 6.5.1 |
HIGH | 7.5 | The PDF for Contact Form 7 + Drag and Drop Template Builder plugin for WordPress is vulnerable to PHP Object Injection i… | — | wordfence |
| 159e14fc-0512-421a-8bbe-d16c0b04ddf9 | < 1.15.9 |
HIGH | 7.5 | The Total Upkeep β WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to un… | — | wordfence |
| 158000e9-b8bd-4adb-b634-534d31471def | HIGH | 7.5 | The OneLife theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.9 via deserial… | — | wordfence | |
| 157d473d-68f6-40ff-b73c-17e3ca528ee4 | HIGH | 7.5 | The JS Job Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.2 due to in… | — | wordfence | |
| 156eb99d-087b-4716-8ba8-3a1bdc008f58 | HIGH | 7.5 | The WPB Category Slider for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up to, an… | — | wordfence | |
| 14d84ad4-904b-4000-af82-b1b68c724aa2 | < 2.5 |
HIGH | 7.5 | The Elegance Theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.4. This is… | — | wordfence |
| 14894c36-f657-4368-bc7f-60121ec08c13 | < 1.4.3 |
HIGH | 7.5 | The Photo Gallery β Responsive Photo Gallery, Image Gallery, Portfolio Gallery, Logo Gallery And Team Gallery plugin f… | — | wordfence |
| 1485dda6-bf83-4076-80c9-dc7ea9d58155 | < 2.1.2 |
HIGH | 7.5 | The EventON plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, … | — | wordfence |
| 1479071c-85c3-41fd-8ad7-f0dee32f201b | < 4.0.27 |
HIGH | 7.5 | The Event Manager, Events Calendar, Tickets, Registrations β Eventin plugin for WordPress is vulnerable to arbitrary f… | — | wordfence |
| 1462f52b-98f0-40de-8f95-717992c7cbc6 | < 7.3.7 |
HIGH | 7.5 | The Events Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.3.6 due to in… | — | wordfence |
| 1410ee86-90ec-4913-bc74-d8954d141d72 | < 2.11.1 |
HIGH | 7.5 | The WPGraphQL plugin for WordPress is vulnerable to SQL Injection in versions up to 2.11.1 due to insufficient escaping … | — | wordfence |
| 13d07e9d-0e28-4d28-b1e9-168a83e98bf6 | HIGH | 7.5 | The Vino theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9. This makes it … | — | wordfence | |
| 13bde27a-8741-4b86-a45b-7acbaf7d6dde | HIGH | 7.5 | The apptha-slider-gallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including… | — | wordfence | |
| 13b79de0-9ef9-4b7f-aa57-75877b4a39c0 | < 2.9.3 |
HIGH | 7.5 | The JS Help Desk plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.2 due to insu… | — | wordfence |
| 13728336-42b8-4857-9753-c91b7cb028fa | < 2.7.8.4 |
HIGH | 7.5 | The Participants Database plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.7.8.3 … | — | wordfence |
| 134e09a8-f89a-4282-b2e8-09b84f04aae7 | HIGH | 7.5 | The wptf-image-gallery plugin for WordPress is vulnerable to Arbitrary File Downloads in versions up to, and including, … | — | wordfence | |
| 1301c8af-d81a-40f1-96fa-e8252309d8a4 | < 3.2.90 |
HIGH | 7.5 | The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization … | — | wordfence |
| 12f0394a-de18-4f61-b93d-34b30ae6106a | < 4.9.2 |
HIGH | 7.5 | The WP Maps β Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulne… | — | wordfence |
| 12c29a44-f9e4-439a-bc3f-18a3640f7924 | < 2.22.8 |
HIGH | 7.5 | The Tourfic β AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerabl… | — | wordfence |
| 12bebb01-74ea-4722-99ed-2322d35da8c2 | HIGH | 7.5 | The WPJobster theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.3.5 due to insuffic… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →