Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 34 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b8dd6008-e9b8-4a87-b1c7-0dc272850cbd | CRITICAL | 9.8 | The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and incl… | — | wordfence | |
| b8cbd521-f2d4-4cf6-a50f-ed42f4d21989 | CRITICAL | 9.8 | The PHP Shell plugin for WordPress is used for Remote Code Execution in all versions up to, and including, 1.0. This all… | — | wordfence | |
| b8c18081-1ee3-4072-89f1-b6eb1518916e | < 2.7.6 |
CRITICAL | 9.8 | The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the… | — | wordfence |
| b8bbb54d-7607-4d19-bf2d-2d52a6de1287 | < 1.1.1 |
CRITICAL | 9.8 | SQL injection vulnerability in lib/optin/optin_page.php in the Lead Octopus plugin before 1.1.1 for WordPress allows rem… | — | wordfence |
| b8b443bb-4b23-48a1-9859-953b3cd84ca6 | < 29.0.2 |
CRITICAL | 9.8 | The Contest Gallery Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including,… | — | wordfence |
| b894473b-b2ed-475b-892e-603db609f88a | < 3.4.3 |
CRITICAL | 9.8 | The JupiterX Core plugin for WordPress is vulnerable to privilege escalation due to insufficient validation in versions … | — | wordfence |
| b884d3c9-7d84-44eb-9e94-b415625b479d | < 0.60 |
CRITICAL | 9.8 | The Album and Image Gallery with Lightbox β Flagallery Photo Portfolio plugin for WordPress is vulnerable to generic S… | — | wordfence |
| b883681e-5e14-4100-989b-4776456246bf | CRITICAL | 9.8 | The SSV Events plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.2.7. This … | — | wordfence | |
| b8672fd2-dc7a-4717-9d25-84180ad9b134 | < 1.21.16 |
CRITICAL | 9.8 | The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFI… | — | wordfence |
| b8652b40-480c-4d53-b1c8-e1dcfbd8a4a4 | CRITICAL | 9.8 | The AREA53 Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the php.p… | — | wordfence | |
| b8347b4e-a5ba-49c5-9ae6-690a1a5c9aac | < 12.1 |
CRITICAL | 9.8 | The tagDiv Composer plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versi… | — | wordfence |
| b829b7a1-2891-402b-a48f-a7fb1202448e | < 2.8 |
CRITICAL | 9.8 | The Shortcode Factory plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7 v… | — | wordfence |
| b812a0d7-99a1-4f61-b78a-78cea6a2ada1 | < 4.79 |
CRITICAL | 9.8 | The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin… | — | wordfence |
| b811f085-9374-41e7-a9ab-fecff0b9e19d | < 3.1.0 |
CRITICAL | 9.8 | Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_qui… | — | wordfence |
| b80c2a5a-49f2-4b93-a1eb-a0be53aa921d | CRITICAL | 9.8 | The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available… | — | wordfence | |
| b803ee40-733a-49bf-a134-406747541eb6 | < 0.5.0 |
CRITICAL | 9.8 | The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parame… | — | wordfence |
| b7f3b469-9a6c-4cc1-bb27-bd57bbae7208 | < 6.8.2 |
CRITICAL | 9.8 | The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to… | — | wordfence |
| b7b1620e-a26b-454d-890c-37dfa90abfad | CRITICAL | 9.8 | The CWW Portfolio theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.1. Thi… | — | wordfence | |
| b78eb275-bede-44f0-bf72-6931c37d78bf | < 1.3.4 |
CRITICAL | 9.8 | The TS Poll β Best Poll Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass due to a missi… | — | wordfence |
| b77c3d65-23c0-4bda-afea-9cad00fc04d6 | < 1.3.19 |
CRITICAL | 9.8 | The Invite Anyone plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.18 vi… | — | wordfence |
| b772a695-658f-41aa-b40e-b5a91a6d01a4 | CRITICAL | 9.8 | The Booking Calendar and Notification plugin for WordPress is vulnerable to authentication bypass in all versions up to,… | — | wordfence | |
| b771199e-937f-46d5-9906-4cbbbcd748cd | CRITICAL | 9.8 | The 4ECPS Web Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence | |
| b71706a7-e101-4d50-a2da-1aeeaf07cf4b | < 7.6.25 |
CRITICAL | 9.8 | The Comments β wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includi… | — | wordfence |
| b71348c8-9e86-432e-b05e-96884344cef6 | < 1.1.4 |
CRITICAL | 9.8 | The LogDash Activity Log plugin for WordPress is vulnerable to SQL Injection via the username parameter in all versions … | — | wordfence |
| b70f5416-06e0-4b6f-b61d-b7c23575a171 | < 3.9.1 |
CRITICAL | 9.8 | The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues. | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →