Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 33 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| bb6182e8-ba5c-4873-aa18-45a79191c8c5 | < 3.7.23 |
CRITICAL | 9.8 | WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading t… | — | wordfence |
| bb3f2af4-b5cc-43c0-8425-224281300d66 | CRITICAL | 9.8 | The Grand Restaurant WordPress theme for WordPress is vulnerable to PHP Object Injection in versions up to, and includin… | — | wordfence | |
| bb00eae9-645d-4827-b691-2408fd24aa75 | < 1.22.21 |
CRITICAL | 9.8 | The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to authentication bypass in all versions up… | — | wordfence |
| bae5f22d-5085-4230-a7fc-5db85aa6fbdb | < 67.2.0 |
CRITICAL | 9.8 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing … | — | wordfence |
| bac8c35b-2afa-4347-b86e-2f16db19a4d3 | < 5.0.13 |
CRITICAL | 9.8 | The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. Thi… | — | wordfence |
| babbe506-3abd-462a-b5b8-5979696eb6e6 | < 20230914 |
CRITICAL | 9.8 | The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… | — | wordfence |
| bab67a5c-3390-4423-8fa9-b5ffbc98324d | < 1.3.84 |
CRITICAL | 9.8 | The Ultimate Member plugin for WordPress is vulnerable to Executing Arbitrary WordPress Shortcodes in versions up to, an… | — | wordfence |
| baab579f-2d77-4dbe-979a-54956dfdcb77 | < 3.2.5 |
CRITICAL | 9.8 | The Zephyr Project Manager plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up to,… | — | wordfence |
| ba8d377f-d216-40e4-97f2-ed3eac0ec33e | < 1.6.4 |
CRITICAL | 9.8 | The Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ss… | — | wordfence |
| ba84711f-bdbe-46d3-a9a3-cc2b1dcefd1a | < 2.0.2 |
CRITICAL | 9.8 | The Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includin… | — | wordfence |
| ba6d8be6-e7a6-4275-b5f1-86e2ea85ff76 | < 3.9.51 |
CRITICAL | 9.8 | The Locatoraid Store Locator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including… | — | wordfence |
| ba502aac-13f7-40e2-9672-bf26a0fefef7 | < 5.3.9 |
CRITICAL | 9.8 | The XStore Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.3.8 v… | — | wordfence |
| ba1a25e9-bac3-4f76-8324-3035be94da4c | < 1.0.41 |
CRITICAL | 9.8 | The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPres… | — | wordfence |
| ba18bd0c-ba6c-4f98-ac29-660a79affa6c | < 1.5.2 |
CRITICAL | 9.8 | The Simple Inventory Management β just scan barcode to manage products and orders. For WooCommerce plugin for WordPres… | — | wordfence |
| ba1004c7-52f4-4fea-b820-dd11b2264e15 | CRITICAL | 9.8 | The MoneyTheme theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'u… | — | wordfence | |
| b9d9d05f-0de7-473f-ae33-a97967c6fcf7 | CRITICAL | 9.8 | The PDF-Rechnungsverwaltung plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including,… | — | wordfence | |
| b994bb62-436f-4edc-8891-281483428ac0 | CRITICAL | 9.8 | The IWS - Geo Form Fields plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to… | — | wordfence | |
| b98179c3-8b32-4d75-9f3f-2367215a740b | < 1.7.8 |
CRITICAL | 9.8 | The Pie Register - Social Sites Login (Add on) plugin for WordPress is vulnerable to authentication bypass in versions u… | — | wordfence |
| b97b1c86-22a4-462b-9140-55139cf02c7a | < 1.9.6.1 |
CRITICAL | 9.8 | The Bricks theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.9.6. This … | — | wordfence |
| b97805de-1b47-4c9f-baae-2e37c1b78570 | CRITICAL | 9.8 | The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_i… | — | wordfence | |
| b9371b37-53c5-4a4f-a500-c6d58d4d3c5a | < 84.4 |
CRITICAL | 9.8 | The WooCommerce Upload Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… | — | wordfence |
| b9119e20-8615-4447-9eb8-4a0259319eb4 | CRITICAL | 9.8 | The WordPress Events Calendar Registration & Tickets plugin for WordPress is vulnerable to PHP Object Injection in versi… | — | wordfence | |
| b905b8ec-d13d-4455-9c5f-61aaa09d75ba | < 1.3.4.3 |
CRITICAL | 9.8 | The HUSKY β Products Filter for WooCommerce (formerly WOOF) plugin for WordPress is vulnerable to generic SQL Injectio… | — | wordfence |
| b8eeeed6-bb8c-47d3-afa5-84eb7ed2c971 | < 1.6 |
CRITICAL | 9.8 | Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3) media-… | — | wordfence |
| b8eb3aa9-fe60-48b6-aa24-7873dd68b47e | < 3.16.4 |
CRITICAL | 9.8 | The GiveWP β Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in al… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →