Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 329 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 083dd550-6d62-4e2e-8571-ef3c5597e816 | < 3.8.11 |
HIGH | 7.5 | The JetEngine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.10.2 due to insu… | — | wordfence |
| 0838daec-6e83-4e19-93e1-a7645daf1294 | < 1.0.4 |
HIGH | 7.5 | The FormGent β Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress i… | — | wordfence |
| 0823d1d9-4f3b-4ac0-8cd1-ad208ebc325f | < 7.90 |
HIGH | 7.5 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to,… | — | wordfence |
| 081bd3a9-2139-416f-bb36-b86aef6fa6db | < 1.7.0 |
HIGH | 7.5 | The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that… | — | wordfence |
| 0814e7b3-404a-4db5-b564-46c9086ec048 | < 5.1.17 |
HIGH | 7.5 | The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner… | — | wordfence |
| 07ebb176-a1f8-4a5c-8d81-a83fda4b0af3 | HIGH | 7.5 | The Assistant for NextGEN Gallery plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient… | — | wordfence | |
| 07cdc2db-e748-40c9-a2fe-31aef0725dad | < 2.2.6 |
HIGH | 7.5 | The WP Human Resource Management plugin before 2.2.6 for WordPress does not ensure that a leave modification occurs in t… | — | wordfence |
| 07b34541-25df-407b-8d56-16e3e510d83a | < 1.0.5 |
HIGH | 7.5 | guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header par… | — | wordfence |
| 07aee46a-a32d-4d31-9541-4e183299b09c | < 1.2 |
HIGH | 7.5 | The ebook-download plugin before 1.2 for WordPress has directory traversal via ebookdownloadurl parameter. | — | wordfence |
| 0788e172-c9f0-4aa5-806b-183491f92bc3 | < 4.2.2.1 |
HIGH | 7.5 | The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner β Groundhogg plugin for WordPress is vuln… | — | wordfence |
| 077c36f3-91ee-4fac-8303-2222816e4707 | < 2.2.7 |
HIGH | 7.5 | The WBW Product Table PRO plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.2.6 du… | — | wordfence |
| 075709e0-5f00-4d7b-80f6-96e3b4b4a895 | < 2.10 |
HIGH | 7.5 | The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Expo… | — | wordfence |
| 0733261f-a2e1-4bd1-a57d-fdaaa8c904db | < 2.5 |
HIGH | 7.5 | The CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon plugin for WordPress is vu… | — | wordfence |
| 06fc92e9-b2c0-46a0-99b2-10cf0d564f7b | < 1.4.110 |
HIGH | 7.5 | The Motors β Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Local File Inclusion in… | — | wordfence |
| 06e4d7e3-c800-4b3d-9504-c69aa9a918fb | < 2.0.2 |
HIGH | 7.5 | WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) default-… | — | wordfence |
| 06dcb84f-8293-403d-a3f2-7c5bea7aaae3 | < 1.5 |
HIGH | 7.5 | The Construct Theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 1.4. This i… | — | wordfence |
| 069bd7ab-1b78-4465-8e13-5ef903f7e45f | < 2.2.6 |
HIGH | 7.5 | admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/a… | — | wordfence |
| 06919817-a2ce-4914-bf1c-7763c1cde543 | < 1.9.9.5.3 |
HIGH | 7.5 | The WPLMS plugin for WordPress is vulnerable to SQL Injection in versions up to 1.9.9.5.3 due to insufficient escaping o… | — | wordfence |
| 06900b4b-6607-4b25-b4bc-2e2906160421 | < 1.7.2 |
HIGH | 7.5 | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and in… | — | wordfence |
| 0640538c-b076-453c-a32e-f33b4e1c77ae | < 1.1.0.54 |
HIGH | 7.5 | The BizCalendar Web plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1… | — | wordfence |
| 063abf5d-d704-4e16-8ee7-58a3370993b9 | HIGH | 7.5 | The Hospital Management System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 47.… | — | wordfence | |
| 06359274-37ae-47f5-824c-25600c5b06eb | HIGH | 7.5 | The Blogger 301 Redirect plugin for WordPress is vulnerable to blind time-based SQL Injection via the βbrβ parameter… | — | wordfence | |
| 0605bc15-3a97-46f4-8244-29220ed5ab31 | HIGH | 7.5 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via… | — | wordfence | |
| 05d633f5-151a-4462-a6a0-5a638d7c3404 | < 2.8.7 |
HIGH | 7.5 | The My Sticky Bar plugin for WordPress is vulnerable to SQL injection via the `stickymenu_contact_lead_form` AJAX action… | — | wordfence |
| 05d063e3-4863-4dd5-9219-6240b9b3f939 | < 1.15.39 |
HIGH | 7.5 | The Form Maker by 10Web β Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL I… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →