Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 327 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 12be30fc-2d7e-4326-b949-45138796c1a9 | < 5.3.7 |
HIGH | 7.5 | The Event Booking Manager for WooCommerce β Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPre… | — | wordfence |
| 121a65ba-2d14-462e-bf2b-10210430e07a | HIGH | 7.5 | The Ronneby Theme Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.… | — | wordfence | |
| 11e7e798-9fb9-4cff-a96f-a0003f203f5f | < 2.0.1 |
HIGH | 7.5 | The Shipping Rate By Cities plugin for WordPress is vulnerable to SQL Injection via the 'city' parameter in all versions… | — | wordfence |
| 119fe499-88c4-413f-a44a-2b3acfdbdeb5 | HIGH | 7.5 | The Administrative Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and incl… | — | wordfence | |
| 1134c9ea-bbec-4f5d-acb0-1ae978346cfc | < 3.9.5 |
HIGH | 7.5 | The WP Travel Gutenberg Blocks plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.9… | — | wordfence |
| 110f4ca6-3e59-4348-bb45-6e5fcfa81491 | < 0.9.2.5 |
HIGH | 7.5 | W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download th… | — | wordfence |
| 10ee015a-c60b-4236-bb7a-9d3ffd944bf9 | < 2.2.0 |
HIGH | 7.5 | The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provision… | — | wordfence |
| 10ea2183-3f4e-44bd-a726-0910fe71df13 | HIGH | 7.5 | The Video List Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7 due to … | — | wordfence | |
| 10e4c52d-c82f-4393-9a56-5714b3a108d1 | < 1.16 |
HIGH | 7.5 | The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1… | — | wordfence |
| 1079b96d-0435-42f1-b5b2-d36e674c0c9c | < 6.4.4 |
HIGH | 7.5 | The ShortPixel Image Optimizer β Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object… | — | wordfence |
| 1057b1ee-9bcb-4b3b-bbc0-3262e658bb97 | < 3.1.3 |
HIGH | 7.5 | The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to SQL Injection in versions up to 3.1.3 du… | — | wordfence |
| 102ed3c9-33ed-462a-83df-5a57f2621780 | < 3.1.1 |
HIGH | 7.5 | Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remo… | — | wordfence |
| 1005eb8c-da5a-4422-9d65-0f341ad755b2 | < 1.3.9.7 |
HIGH | 7.5 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading t… | — | wordfence |
| 0ff96c12-1388-48a9-adf4-feca77a37ba7 | < 3.8.4 |
HIGH | 7.5 | Sliced Invoices plugin for WordPress 3.8.3 and earlier allows unauthenticated information disclosure and authenticated S… | — | wordfence |
| 0fe89884-b428-4caf-b67a-5aaa41fafa9d | < 1.2.18 |
HIGH | 7.5 | The Hara theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.17. This makes … | — | wordfence |
| 0fbc5cd6-7a81-4c85-b51b-9a3f27b923e2 | < 4.0.4.2 |
HIGH | 7.5 | The JetBooking plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.4.1 due to insu… | — | wordfence |
| 0fa4585d-9ffa-4a32-aeb7-60cdad63187b | HIGH | 7.5 | The WP Backup+ plugin for WordPress is vulnerable to Sensitive Data Exposure via the temp directory. This can allow unau… | — | wordfence | |
| 0f8c0697-73dc-481e-8d9b-d3e0de4bded3 | HIGH | 7.5 | The Billey theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.8. This makes… | — | wordfence | |
| 0f54f61c-f75d-4640-8150-e8b60b26dcf9 | < 2.0.1 |
HIGH | 7.5 | The Corpkit theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0. This makes … | — | wordfence |
| 0f4c9abb-d42d-4f59-8364-f1fb4d06ffbc | < 3.1 |
HIGH | 7.5 | The Addon Jobsearch Chat plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0 due t… | — | wordfence |
| 0f3b74db-22a4-4638-8662-0c8cfbee6493 | < 1.14.2.2 |
HIGH | 7.5 | The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal. | — | wordfence |
| 0e725ec0-4897-4ba7-a803-80e8aafacbd1 | < 8.0.4 |
HIGH | 7.5 | The WPCargo Track & Trace plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.0.3 du… | — | wordfence |
| 0e22815e-1f06-4a46-90eb-98125ae97ba4 | < 2.6.32 |
HIGH | 7.5 | The LikeBtn WordPress Like Button Rating β₯ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Fu… | — | wordfence |
| 0e0ebe1d-b6cf-4ff5-ae6c-c8c226a000d4 | HIGH | 7.5 | The Emailing Subscription plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.1 du… | — | wordfence | |
| 0d50f217-7a53-49bf-9ce9-9922d0b3e18b | < 3.7.1 |
HIGH | 7.5 | The WP Ultimate CSV Importer plugin for WordPress is vulnerable to authorization bypass due to a missing capability chec… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →