Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 330 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 05b44698-c55f-48ff-8f98-8478b2564e38 | < 3.9.5 |
HIGH | 7.5 | The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to SQL Injection in versions up to, and … | — | wordfence |
| 056a8372-82f3-4707-8bff-1ab91595f8dc | HIGH | 7.5 | The Puca theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.6.39. This makes … | — | wordfence | |
| 05153b11-2f26-425e-99ab-93216861802b | < 3.0.9 |
HIGH | 7.5 | The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy' parameter of the /wp-js… | — | wordfence |
| 04f37062-da7e-4c26-ab15-50dcef8ca301 | < 1.0.2 |
HIGH | 7.5 | The ThemeMakers Diplomat | Political theme through 1.0.1 for WordPress allows remote attackers to obtain sensitive infor… | — | wordfence |
| 04a46249-b5b2-4082-b520-cdc4a1370bb1 | < 2.1.4 |
HIGH | 7.5 | The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/c… | — | wordfence |
| 048a55a4-f4b3-4203-8c0a-8778189a6a18 | < 3.2.1 |
HIGH | 7.5 | The Traveler theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.0 due to insuffici… | — | wordfence |
| 042f78a4-2256-4286-aa03-8bd8b7a79530 | < 4.5.5.1 |
HIGH | 7.5 | The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlatlng' and 'nelatlng' parameters in all ve… | — | wordfence |
| 042f7090-2eab-44d2-82b2-ecabdb1d3f99 | < 3.2.15 |
HIGH | 7.5 | The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering. | — | wordfence |
| 040ae20d-93e3-4c65-ba74-4ff0b5c1afc7 | < 5.5.4 |
HIGH | 7.5 | The WordPress Infinite Scroll β Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted inpu… | — | wordfence |
| 03e845c0-5845-4d74-88e6-376c703b6145 | HIGH | 7.5 | The TheGem Theme Elements plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5… | — | wordfence | |
| 03a96b11-ffda-40a9-897e-657847fc0d40 | HIGH | 7.5 | The Improved Sale Badges β Free Version plugin for WordPress is vulnerable to Local File Inclusion in all versions up … | — | wordfence | |
| 0394e4a9-28dc-4e20-8bc3-ed486172dcb8 | < 2.5.13 |
HIGH | 7.5 | The Urna theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.5.12. This makes … | — | wordfence |
| 0368ec17-107c-476c-9627-b6a7ebc3c365 | < 5.1.8 |
HIGH | 7.5 | The Iptanus File Upload plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.1.7 due … | — | wordfence |
| 031c2a61-3547-4c33-8ab8-c52585c8066a | HIGH | 7.5 | The OpenInviter for WordPress plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and inclu… | — | wordfence | |
| 0315f5de-7a46-4e16-b080-557ddfd180a2 | < 4.2.0 |
HIGH | 7.5 | The Javascript library moment.js is vulnerable to a path traversal vulnerability in versions up to, and including, 2.29.… | — | wordfence |
| 0307dbb7-4f82-429b-9be5-9e7c75603074 | HIGH | 7.5 | The Simply Poll plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.1 due to insuf… | — | wordfence | |
| 02e918f8-8380-44f6-bd4f-4f58fd47d69a | HIGH | 7.5 | The Eventer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.9.6 due to insuffici… | — | wordfence | |
| 029719d5-d7b8-48f5-af97-7a4f55892c4f | HIGH | 7.5 | The WPCRM - CRM for Contact form CF7 & WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to… | — | wordfence | |
| 02888538-c2c7-4cba-acf3-77d76cef255e | < 2.1.3 |
HIGH | 7.5 | The Organici Library plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.2 … | — | wordfence |
| 01e41573-9329-48e1-9191-e8e1532f7afc | < 1.2.7 |
HIGH | 7.5 | The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing cap… | — | wordfence |
| 01d2ebc1-43f1-440f-afde-058e26270066 | < 3.1.3 |
HIGH | 7.5 | The WPC Product Options for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up to, an… | — | wordfence |
| 01b3013f-60b9-449b-a2a9-64e37a1454ef | < 6.2 |
HIGH | 7.5 | The JM Twitter Cards plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 6.1… | — | wordfence |
| 0180bf61-fdb4-40b3-bbb6-6bc76a85ed4e | HIGH | 7.5 | The Entrada theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.7 due to insufficie… | — | wordfence | |
| 0139661f-75d2-44b7-8278-e31c24935a85 | < 2.3.3 |
HIGH | 7.5 | The ZoloBlocks plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.2. This … | — | wordfence |
| 011d654a-637f-418c-8bd3-e87fd889f1ab | < 3.3.0 |
HIGH | 7.5 | The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for Word… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →