Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,758 vulnerabilities found (page 35 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ba1a25e9-bac3-4f76-8324-3035be94da4c | < 1.0.41 |
CRITICAL | 9.8 | The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPres… | — | wordfence |
| ba18bd0c-ba6c-4f98-ac29-660a79affa6c | < 1.5.2 |
CRITICAL | 9.8 | The Simple Inventory Management β just scan barcode to manage products and orders. For WooCommerce plugin for WordPres… | — | wordfence |
| ba1004c7-52f4-4fea-b820-dd11b2264e15 | CRITICAL | 9.8 | The MoneyTheme theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'u… | — | wordfence | |
| b9f75a13-76be-45b5-8ec3-a89cbb6e0256 | < 6.0.9.9 |
CRITICAL | 9.8 | The RegistrationMagic β Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … | — | wordfence |
| b9d9d05f-0de7-473f-ae33-a97967c6fcf7 | CRITICAL | 9.8 | The PDF-Rechnungsverwaltung plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including,… | — | wordfence | |
| b9d11eb9-5e18-459f-a9d4-cccb1d593402 | < 1.17.9 |
CRITICAL | 9.8 | The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted Fi… | — | wordfence |
| b994bb62-436f-4edc-8891-281483428ac0 | CRITICAL | 9.8 | The IWS - Geo Form Fields plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to… | — | wordfence | |
| b98179c3-8b32-4d75-9f3f-2367215a740b | < 1.7.8 |
CRITICAL | 9.8 | The Pie Register - Social Sites Login (Add on) plugin for WordPress is vulnerable to authentication bypass in versions u… | — | wordfence |
| b97b1c86-22a4-462b-9140-55139cf02c7a | < 1.9.6.1 |
CRITICAL | 9.8 | The Bricks theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.9.6. This … | — | wordfence |
| b97805de-1b47-4c9f-baae-2e37c1b78570 | CRITICAL | 9.8 | The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_i… | — | wordfence | |
| b9690fc8-cd0c-42e4-aa21-5c71243565f0 | CRITICAL | 9.8 | The Frontegg SAML SSO plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, … | — | wordfence | |
| b9371b37-53c5-4a4f-a500-c6d58d4d3c5a | < 84.4 |
CRITICAL | 9.8 | The WooCommerce Upload Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… | — | wordfence |
| b9119e20-8615-4447-9eb8-4a0259319eb4 | CRITICAL | 9.8 | The WordPress Events Calendar Registration & Tickets plugin for WordPress is vulnerable to PHP Object Injection in versi… | — | wordfence | |
| b905b8ec-d13d-4455-9c5f-61aaa09d75ba | < 1.3.4.3 |
CRITICAL | 9.8 | The HUSKY β Products Filter for WooCommerce (formerly WOOF) plugin for WordPress is vulnerable to generic SQL Injectio… | — | wordfence |
| b8eeeed6-bb8c-47d3-afa5-84eb7ed2c971 | < 1.6 |
CRITICAL | 9.8 | Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3) media-… | — | wordfence |
| b8eb3aa9-fe60-48b6-aa24-7873dd68b47e | < 3.16.4 |
CRITICAL | 9.8 | The GiveWP β Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in al… | — | wordfence |
| b8dd6008-e9b8-4a87-b1c7-0dc272850cbd | CRITICAL | 9.8 | The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and incl… | — | wordfence | |
| b8cbd521-f2d4-4cf6-a50f-ed42f4d21989 | CRITICAL | 9.8 | The PHP Shell plugin for WordPress is used for Remote Code Execution in all versions up to, and including, 1.0. This all… | — | wordfence | |
| b8c18081-1ee3-4072-89f1-b6eb1518916e | < 2.7.6 |
CRITICAL | 9.8 | The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the… | — | wordfence |
| b8bbb54d-7607-4d19-bf2d-2d52a6de1287 | < 1.1.1 |
CRITICAL | 9.8 | SQL injection vulnerability in lib/optin/optin_page.php in the Lead Octopus plugin before 1.1.1 for WordPress allows rem… | — | wordfence |
| b8b443bb-4b23-48a1-9859-953b3cd84ca6 | < 29.0.2 |
CRITICAL | 9.8 | The Contest Gallery Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including,… | — | wordfence |
| b8a7a925-2b9e-43bc-b649-c7ec518e063c | < 0.9.2.7 |
CRITICAL | 9.8 | The Advanced Custom Fields: Extended PRO plugin for WordPress is vulnerable to Limited Code Injection in all versions up… | — | wordfence |
| b894473b-b2ed-475b-892e-603db609f88a | < 3.4.3 |
CRITICAL | 9.8 | The JupiterX Core plugin for WordPress is vulnerable to privilege escalation due to insufficient validation in versions … | — | wordfence |
| b884d3c9-7d84-44eb-9e94-b415625b479d | < 0.60 |
CRITICAL | 9.8 | The Album and Image Gallery with Lightbox β Flagallery Photo Portfolio plugin for WordPress is vulnerable to generic S… | — | wordfence |
| b883681e-5e14-4100-989b-4776456246bf | CRITICAL | 9.8 | The SSV Events plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.2.7. This … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →