Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 337 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 7addc83b-cde5-4f91-b286-70db6f384a9f | < 2.1.25.2 |
HIGH | 7.3 | Multiple plugins by Crocoblock for WordPress are vulnerable to unauthorized access due to a missing capability check on … | — | wordfence |
| 76fe8746-582e-49a5-b0c1-19d2aaef44df | < 1.0.22 |
HIGH | 7.3 | The Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling plugin for WordPress… | — | wordfence |
| 74841c33-83fa-465e-a5a9-88c34bbc9f6c | < 1.2.1 |
HIGH | 7.3 | The Floating Action Button plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, … | — | wordfence |
| 71d63f0d-ce01-489e-bcc4-7632f1a4bb04 | < 2.0.23 |
HIGH | 7.3 | Unspecified vulnerability in the MainWP Dashboard and MainWP Child plugins in versions up to and including 2.0.22 for Wo… | — | wordfence |
| 70f2c885-14b6-4ac3-b819-502bc618d9c9 | < 9.7 |
HIGH | 7.3 | The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, w… | — | wordfence |
| 6fe8b2c8-3bb1-463a-a64c-15d7bcc29985 | < 1.2.0 |
HIGH | 7.3 | The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… | — | wordfence |
| 6edf91de-9553-4aa1-a29f-89771c8e852e | < 1.0.6.8 |
HIGH | 7.3 | The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to unaut… | — | wordfence |
| 6eb57c97-f560-42d1-87bd-b19c60700956 | < 1.8.12 |
HIGH | 7.3 | The Wolmart | Multi-Vendor Marketplace WooCommerce Theme theme for WordPress is vulnerable to arbitrary shortcode execut… | — | wordfence |
| 6e5e9249-9705-4cfa-9c8e-2e002190562b | < 3.5.4.6 |
HIGH | 7.3 | The Tickera β WordPress Event Ticketing plugin for WordPress is vulnerable to arbitrary shortcode execution in all ver… | — | wordfence |
| 6ca9eaf7-261b-42ab-a779-9e11dde5763b | < 2.5.15 |
HIGH | 7.3 | The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,… | — | wordfence |
| 6c4f8798-c0f9-4d05-808e-375864a0ad95 | < 5.1.2 |
HIGH | 7.3 | The UserPro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to… | — | wordfence |
| 6bd74c3f-3caf-4238-9478-81a4cfa50410 | HIGH | 7.3 | The WP OAuth2 Server plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.1… | — | wordfence | |
| 6b08105d-711e-49ea-a0bc-7179eb021300 | < 2.0 |
HIGH | 7.3 | Unspecified vulnerabilities in the SS Quiz plugin before 1.12.2 for WordPress have unspecified impact and attack vectors… | — | wordfence |
| 67ad04d4-49ef-4bc4-b3b0-f2752566145e | < 1.1.15 |
HIGH | 7.3 | The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file access controls in near… | — | wordfence |
| 669c50b8-316c-4f63-8b78-361cfcfd4d5f | < 2.17.4 |
HIGH | 7.3 | LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per I… | — | wordfence |
| 65d15ceb-ab39-4088-a289-7244063aedf8 | HIGH | 7.3 | The The Show Me The Cookies plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, a… | — | wordfence | |
| 63412848-6b1f-460a-8776-cd1cc5eb002e | < 3.0.2 |
HIGH | 7.3 | The Ldap WP Login / Active Directory Integration plugin for WordPress is vulnerable to authorization bypass and Cross-Si… | — | wordfence |
| 6205b0fe-6c68-4550-b9aa-87c3fbc88ddf | < 2.1.1 |
HIGH | 7.3 | The Simple Slideshow Manager for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… | — | wordfence |
| 61bd2f32-23a2-4dfe-90f3-81d597b97592 | < 3.8.12 |
HIGH | 7.3 | The Multivendor Marketplace Solution for WooCommerce plugin has multiple unprotected AJAX actions that lack capability o… | — | wordfence |
| 6150c355-1046-483e-aa8b-463c3752021d | < 2.0.5.4.1 |
HIGH | 7.3 | The Master Addons for Elementor plugin for WordPress is vulnerable to unauthorized functionality access due to a missing… | — | wordfence |
| 5dea49fb-2703-4754-9abd-5f4e526d5570 | < 5.4.10.2 |
HIGH | 7.3 | The The kk Star Ratings β Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode… | — | wordfence |
| 5cdbd5fd-bb12-4202-b6c7-f314ad8987f5 | < 9.4 |
HIGH | 7.3 | The Client Invoicing by Sprout Invoices β Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable… | — | wordfence |
| 5b2840ee-3b48-415e-9bed-d34d0b6e36d7 | < 4.13.2 |
HIGH | 7.3 | The ProfilePress plugin for WordPress is vulnerable to limited privilege escalation in versions up to, and including, 4.… | — | wordfence |
| 59c5b6e7-74b0-430d-8b4a-5a42220f3ec9 | < 4.15.4 |
HIGH | 7.3 | The MStore API β Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user… | — | wordfence |
| 5966a86c-f1e6-4d53-b32a-fa1440d65819 | < 1.3.2 |
HIGH | 7.3 | The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.1 for WordPress allows CSV injection in… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →