Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 35 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b6efe739-713b-4620-b78f-a8ec7b164cd1 | CRITICAL | 9.8 | The Support Ticket plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.… | — | wordfence | |
| b6ee571d-8db6-4e21-9a62-44e562b9a5fc | < 2.0.16 |
CRITICAL | 9.8 | … | — | wordfence |
| b6cab377-0a8a-45d2-a966-4c7f100b9409 | CRITICAL | 9.8 | The Portfolio Slideshow Pro plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in al… | — | wordfence | |
| b6c69a25-8986-4976-8753-ce8e5be311e2 | < 2.0.6 |
CRITICAL | 9.8 | The Absolute Privacy plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 2.0.5… | — | wordfence |
| b6c5cc05-b147-46f6-aaa9-4c82aae1b544 | < 1.0.1 |
CRITICAL | 9.8 | The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, an… | — | wordfence |
| b6b43503-e6f0-4097-9e41-eaae7011b17b | < 1.8 |
CRITICAL | 9.8 | The Nexos - Real Estate WordPress Theme theme for WordPress is vulnerable to generic SQL Injection via the ‘search_ord… | — | wordfence |
| b69c86f4-d81d-4e14-baff-3402008bb9c6 | < 4.19.1 |
CRITICAL | 9.8 | The CiyaShop - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to PHP Object Injection in all versions … | — | wordfence |
| b65cdbe0-e258-4bb5-9a36-cbf57b75ce77 | CRITICAL | 9.8 | The Custom Background plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… | — | wordfence | |
| b5ed8a39-50b0-4acf-9054-ba389c49f345 | < 8.4 |
CRITICAL | 9.8 | The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8… | — | wordfence |
| b5a1baaa-d593-4559-953c-9393bde8d711 | < 3.11 |
CRITICAL | 9.8 | The Ajax Search Lite plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.10 … | — | wordfence |
| b55567e9-24e6-4738-b7f7-b95b541e6067 | < 1.8.4.1 |
CRITICAL | 9.8 | The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the news… | — | wordfence |
| b550a140-0bdc-4840-806a-3eaceee7e42f | < 2.6.1 |
CRITICAL | 9.8 | The JobSearch WP Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi… | — | wordfence |
| b53066d3-2ff3-4460-896a-facd77455914 | < 4.7.6 |
CRITICAL | 9.8 | The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versio… | — | wordfence |
| b52fe73f-3e90-40d6-bccc-d535c3b426d0 | < 5.2.1 |
CRITICAL | 9.8 | The Essential Real Estate plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5… | — | wordfence |
| b52ae51d-7b9a-4047-82bf-723ea87d2375 | < 1.5.3 |
CRITICAL | 9.8 | The Flickr Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2 vi… | — | wordfence |
| b5165f60-6515-4a2c-a124-cc88155eaf01 | < 4.24.14 |
CRITICAL | 9.8 | The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi… | — | wordfence |
| b5136409-d843-4774-afe7-211a23f65da9 | < 1.4.7.1 |
CRITICAL | 9.8 | The Duplicator WordPress Plugin is vulnerable to Unauthenticated Backup Download in versions up to, and including, 1.4.7… | — | wordfence |
| b50d6fd0-3698-4e16-aa76-0344306bc705 | < 1.0.9 |
CRITICAL | 9.8 | The WP Sessions Time Monitoring Full Automatic plugin for WordPress is vulnerable to SQL Injection via request parameter… | — | wordfence |
| b5023e07-9976-44f3-81de-2eb4ba86b0ca | < 3.3.21.2 |
CRITICAL | 9.8 | The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page. | — | wordfence |
| b4cd5c42-bba2-4900-b450-a575c0007402 | < 2.5.8 |
CRITICAL | 9.8 | The Easy Digital Downloads plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, … | — | wordfence |
| b4b3b4a4-9a56-49b8-b3d3-7e50954b4487 | < 7.2.1 |
CRITICAL | 9.8 | The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress all… | — | wordfence |
| b46cd71f-046a-45b8-be8d-4a71e97586b4 | < 3.6.3 |
CRITICAL | 9.8 | The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to arbitrary file deletion in all ver… | — | wordfence |
| b412f60f-61ea-47b1-a3ef-17275f7951df | < 5.4.5 |
CRITICAL | 9.8 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to,… | — | wordfence |
| b4080bb7-9197-4c93-bcb1-cf7b5833771a | CRITICAL | 9.8 | The Dean's FCKEditor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation vi… | — | wordfence | |
| b3f7a88c-a09b-46ac-b345-139c2d20a3d2 | < 4.5.14.2 |
CRITICAL | 9.8 | Duplicator and Duplicator Pro for WordPress are vulnerable to Sensitive Information Exposure in various versions. This m… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →