Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 343 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f3fddcb8-b56f-4d5d-8843-fb78064e9cbb | HIGH | 7.2 | The Oxygen theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.8.… | — | wordfence | |
| f3ebbf7f-61f2-403f-8131-8cedeb13c2d4 | < 2.1.4 |
HIGH | 7.2 | The Mail logging β WP Mail Catcher plugin for WordPress is vulnerable to SQL Injection via several parameters in all v… | — | wordfence |
| f3c4ba08-a9fa-439a-a887-b8c113f78e20 | HIGH | 7.2 | The WP Content Security Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blocked-uri and… | — | wordfence | |
| f3ba06f9-de51-49ea-87c1-4583e939314b | < 1.13.0 |
HIGH | 7.2 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is… | — | wordfence |
| f3ae3bca-d363-4c4b-809f-0625385bc9a6 | < 7.3.15 |
HIGH | 7.2 | The AWeber β Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth plugin … | — | wordfence |
| f367a3d2-8ee6-4897-b7bf-a44f57142347 | < 1.1.9 |
HIGH | 7.2 | The Portfolio Gallery β Photo Gallery for WordPress is vulnerable to SQL Injection via the 'search_events_by_title' pa… | — | wordfence |
| f3584b5b-ff93-4a47-b6e6-f95335ee88b6 | < 2.4.9 |
HIGH | 7.2 | The Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the administration interface in versi… | — | wordfence |
| f3555702-4427-4569-8fd6-f84113593e9d | < 1.2.9.1 |
HIGH | 7.2 | The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' para… | — | wordfence |
| f324b272-1e2f-4951-a8ae-5210a8d4dcbd | < 2.9.3 |
HIGH | 7.2 | The HandL UTM Grabber / Tracker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… | — | wordfence |
| f315fff8-d616-4a5c-91bc-d8b0ec0f028f | < 5.2.3 |
HIGH | 7.2 | The Wordfence plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Referer Header in versions up to… | — | wordfence |
| f2d97646-27a8-4302-be70-7b4fb1a12300 | < 2.2.4 |
HIGH | 7.2 | The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to miss… | — | wordfence |
| f2a6f8ec-6a3e-453d-9ef4-794b5791ac2b | < 1.5.3 |
HIGH | 7.2 | The WP User Merger plugin for WordPress is vulnerable to generic SQL Injection via 'user_id' parameter (in function 'wpu… | — | wordfence |
| f25cd403-77a4-437b-b9ba-93137bf9c936 | < 2.7.1 |
HIGH | 7.2 | The POST SMTP Mailer β Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress… | — | wordfence |
| f1b14fa8-04a0-43e3-a908-db98cb2c5e16 | < 2.5 |
HIGH | 7.2 | The CF7 Auto Responder Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… | — | wordfence |
| f1abab37-7397-407c-bcbb-4597b289ce80 | < 1.7.1 |
HIGH | 7.2 | The Kapee theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.7.1 due to insufficient i… | — | wordfence |
| f18daec4-0b1f-48d8-b6f2-788c8caad17f | HIGH | 7.2 | The Bulk Featured Image plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… | — | wordfence | |
| f10a11d8-1ef8-427b-b256-ffe8769d61bb | < 3.2.1 |
HIGH | 7.2 | The One Click Demo Import plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includin… | — | wordfence |
| f105f6bf-3224-4f5c-8334-1a53ff9af9c0 | < 3.6.4 |
HIGH | 7.2 | The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in all versi… | — | wordfence |
| f0e6b405-0843-4469-ae60-7023dea0786f | < 5.3.9 |
HIGH | 7.2 | The Classified Listing β AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to S… | — | wordfence |
| f0d05295-182c-4c4a-bb0d-15831fe7e691 | < 6.5.7 |
HIGH | 7.2 | The CTX Feed β WooCommerce Product Feed Manager Plugin plugin for WordPress is vulnerable to unauthorized modification… | — | wordfence |
| f093dfc8-8a2f-4614-b7c1-4fbf1afa9589 | < 5.4 |
HIGH | 7.2 | The Demon image annotation plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up t… | — | wordfence |
| f08ad322-6458-4608-b53a-6aaed38a9ef2 | < 6.8 |
HIGH | 7.2 | The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET pa… | — | wordfence |
| f082a21e-0239-45fc-a7f2-9600f215783a | < 2.8.9 |
HIGH | 7.2 | The Ezoic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in versions up to, and includin… | — | wordfence |
| f05a55ba-8068-4f6e-a7b1-f3d5d17e54ee | < 2.12.4 |
HIGH | 7.2 | The Registrations for the Events Calendar β Event Registration Plugin plugin for WordPress is vulnerable to Stored Cro… | — | wordfence |
| f041dbd3-c053-4720-955d-327863275286 | < 1.1.45 |
HIGH | 7.2 | The Hydra Booking β Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →