Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 335 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| bd72ce7e-027c-49bd-8bcf-3ccda2c9b184 | < 1.2 |
HIGH | 7.3 | The All Video Gallery plugin for WordPress is vulnerable to blind SQL Injection via the ‘ vid’ and 'pid' parameters … | — | wordfence |
| bbb24ae0-41d6-4d8f-917c-dfd058a7a49d | < 1.2.0.5 |
HIGH | 7.3 | The The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to arbitrary shortcode exec… | — | wordfence |
| bad0cd3f-88ea-4a1d-b400-0a450b07a546 | < 7.1.6 |
HIGH | 7.3 | The The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for … | — | wordfence |
| ba584e02-5242-4869-a452-21e6b8995bd8 | < 1.3.3.4 |
HIGH | 7.3 | The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in … | — | wordfence |
| ba52c97e-9f2a-4e48-a133-79ed31cfbf3a | HIGH | 7.3 | HC Custom WP-Admin URL versions up to 1.4 set the admin login slug via the admin_init hook with no capability checks. Th… | — | wordfence | |
| b8133d84-e28c-4132-9eb5-941800320f84 | < 5.7.26 |
HIGH | 7.3 | The Quick Paypal Payments plugin for WordPress is vulnerable to unauthorized access and modification of data due to a mi… | — | wordfence |
| b6cf27d9-c0be-4cff-8867-19297f6d79d7 | < 4.9.4 |
HIGH | 7.3 | The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ… | — | wordfence |
| b5c6f351-477b-4384-9863-fe3b45ddf21d | < 2.4.2.1 |
HIGH | 7.3 | The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to unauthorized access due to mi… | — | wordfence |
| b524e239-0a7c-4515-8126-4fd298e43bdd | < 2.4.3 |
HIGH | 7.3 | The OneLogin SAML SSO plugin for WordPress is potentially vulnerable to SAML Signature Wrapping attack due to use of a l… | — | wordfence |
| b30ab159-ff3c-4d46-b182-f8938097b837 | < 7.2.2 |
HIGH | 7.3 | The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPre… | — | wordfence |
| b1a193b7-21e5-4f57-aaa6-e55c79f8e957 | < 5.4.9 |
HIGH | 7.3 | The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up … | — | wordfence |
| b028a70d-f103-4232-b854-17b88d4dc7d9 | < 3.0.4 |
HIGH | 7.3 | The OAuth client Single Sign On for WordPress ( OAuth 2.0 SSO ) plugin for WordPress is vulnerable to authorization bypa… | — | wordfence |
| afffd5e2-798b-42b5-b0b9-ac7d6d06edbb | < 1.5.0 |
HIGH | 7.3 | The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable… | — | wordfence |
| aee6fea2-dbf6-4155-ba3f-f85ea3520504 | < 2.10.1 |
HIGH | 7.3 | The Beautiful Cookie Consent Banner plugin for WordPress is vulnerable to authorization bypass due to a missing capabili… | — | wordfence |
| a7faa800-3b29-4b79-8b94-1e7985acb50d | < 1.7.6 |
HIGH | 7.3 | The The WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup plugin for WordP… | — | wordfence |
| a7e8eb75-ba48-4385-9ddd-800d9bb907f1 | < 3.7.15 |
HIGH | 7.3 | WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vec… | — | wordfence |
| a6c842bb-914a-47c1-aaac-e748f58e12ef | < 8.6.8 |
HIGH | 7.3 | The The Soledad theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,… | — | wordfence |
| a3a402f4-3b4d-4397-807b-c5f1c33d52aa | < 1.9 |
HIGH | 7.3 | The RokIntroScroller plugin for WordPress is vulnerable to Abuse of Functionality via the 'src' parameter in the 'thumb.… | — | wordfence |
| a263e79e-b1d4-4f04-8a93-aad6ca76eaf8 | HIGH | 7.3 | The The WP-Asambleas plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and incl… | — | wordfence | |
| a2447cf4-0261-4ef2-98ec-98fa02dc8b87 | < 2.2.1 |
HIGH | 7.3 | The Flynax Bridge plugin for WordPress is vulnerable to limited Privilege Escalation due to a missing capability check o… | — | wordfence |
| 9d0a8be3-6630-4cf7-b6cb-cdc86b99acb3 | < 4.0.2 |
HIGH | 7.3 | The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the … | — | wordfence |
| 9c6577a2-6722-4d3b-958d-1143dca414cd | < 2.10.1 |
HIGH | 7.3 | The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to… | — | wordfence |
| 9c4e5c12-6f12-40cb-ac0a-389ad3715503 | < 0.4.4 |
HIGH | 7.3 | The reSmush.it plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several AJ… | — | wordfence |
| 9bb9bab2-4f47-41ed-b42e-5272981927a8 | < 1.2.35.2 |
HIGH | 7.3 | The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerabl… | — | wordfence |
| 9b8b5363-2450-42b5-8295-78ced3682b14 | < 1.26 |
HIGH | 7.3 | The WordPress RokStories plugin is vulnerable to Abuse of Functionality via the 'src' parameter in the 'thumb.php' file … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →