Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,758 vulnerabilities found (page 33 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| bf88e79b-262e-4fee-9cef-85d96d300972 | < 2.2.0021 |
CRITICAL | 9.8 | The BePro Listings plugin for WordPress is vulnerable to unauthenticated arbitrary file uploads in versions up to, and i… | — | wordfence |
| bf6b7d8d-fb13-4eb4-b0b4-d0a10ad2a21e | < 2.4.2.4 |
CRITICAL | 9.8 | The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposur… | — | wordfence |
| bf43d81f-2d34-4343-8b2a-e3288b1e21c5 | < 12.40 |
CRITICAL | 9.8 | The DZS Video Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 12.39… | — | wordfence |
| bf2a57fa-28f8-4fd0-814b-a4c9ae77817a | < 2.3.2 |
CRITICAL | 9.8 | The VR Calendar plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.2.2 via … | — | wordfence |
| bf203cb9-db7c-4794-b9b7-c054fe7fc0d2 | CRITICAL | 9.8 | The Fish House theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.7 via des… | — | wordfence | |
| bf037e4a-2dd7-4296-b86b-635901d2d68f | < 3.8.4 |
CRITICAL | 9.8 | The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ… | — | wordfence |
| bec7d613-b1cd-4a4e-bbd9-62bca3a864a2 | < 5.7.0 |
CRITICAL | 9.8 | The WPJobBoard plugin for WordPress is vulnerable to SQL Injections via the 'type' and 'category' parameters in versions… | — | wordfence |
| bec50640-a550-49a8-baf6-2dd53995f90b | CRITICAL | 9.8 | The IQ Testimonials plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validatio… | — | wordfence | |
| be97e1ca-6c9c-4641-ba7c-bbb14a58d99e | < 4.2.1 |
CRITICAL | 9.8 | The rtMedia for WordPress, BuddyPress and bbPress for WordPress is vulnerable to Direct file access in versions up to, a… | — | wordfence |
| be8afa0c-af65-46d7-af07-de67353eddb5 | < 1.2.4 |
CRITICAL | 9.8 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Privilege Escalation i… | — | wordfence |
| be2c1555-4616-4759-bd9b-12f8b3c3a3d4 | < 1.2.1 |
CRITICAL | 9.8 | The "Swape - App Showcase & App Store WordPress Theme" theme for WordPress is vulnerable to authorization bypass due to … | — | wordfence |
| be2ba063-140e-4c92-a57d-79f366631b3d | CRITICAL | 9.8 | The Login with Salesforce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includi… | — | wordfence | |
| be1ab218-37bd-407a-8cb9-66f761849c21 | < 3.1.2 |
CRITICAL | 9.8 | The Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This i… | — | wordfence |
| be0a6471-a78e-4fab-8ef5-93d16859bff4 | < 4.4 |
CRITICAL | 9.8 | The WooCommerce Dropshipping Premium plugin for WordPress is vulnerable to SQL Injection via an unauthenticated REST end… | — | wordfence |
| bd9e5654-387e-4fc3-a6eb-2eface298a9c | < 3.5.3 |
CRITICAL | 9.8 | The Amazon Product in a Post plugin for WordPress is vulnerable to generic SQL Injection via the ‘appip-cache-id’ pa… | — | wordfence |
| bd7ee2d7-4588-4cb9-86ca-0daef421dd86 | CRITICAL | 9.8 | The Hungred Post Thumbnail plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… | — | wordfence | |
| bd332f49-5aa9-4207-89db-84692a6430e0 | < 0.9.2.6 |
CRITICAL | 9.8 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in… | — | wordfence |
| bd2ad909-a254-461d-a24f-e9803353bae4 | CRITICAL | 9.8 | The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to privilege escalation via account … | — | wordfence | |
| bcd7932d-8298-43d2-bc03-932e551a2ec6 | CRITICAL | 9.8 | The WP Dropbox Dropins plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including… | — | wordfence | |
| bcbbbd31-3205-4466-96f5-f9cd7e7cf083 | CRITICAL | 9.8 | The CouponXxL theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.0.0. Thi… | — | wordfence | |
| bcb756d0-425e-48ae-bd7f-ec9404679aea | < 3.0.8 |
CRITICAL | 9.8 | The Feedweb plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in versions up to, and includ… | — | wordfence |
| bca8b173-8e7c-41ad-9316-b38cc2ce0e66 | < 1.4.0 |
CRITICAL | 9.8 | The WP Pipes plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.33 due to insuffic… | — | wordfence |
| bca0bc1d-c373-4ccf-928e-14f3bd4bc53c | < 2.2.4 |
CRITICAL | 9.8 | The Healsoul theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.3. This mak… | — | wordfence |
| bc7fab0a-78bc-4ca8-86f9-19785b00ba65 | CRITICAL | 9.8 | The Embed HTML5 Game plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1… | — | wordfence | |
| bc7e6844-23e2-4523-8261-21d4cba87db3 | < 1.0.2 |
CRITICAL | 9.8 | The Theme per user plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 1.0.2 (exclusive) vi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →