Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,652 vulnerabilities found (page 350 of 1587)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| d906992f-8675-4170-8643-48799ae7ac7c | < 1.6.8 |
HIGH | 7.2 | The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parame… | — | wordfence |
| d8ceb4a1-9354-4ed3-9a8f-45ba2057a810 | < 0.9.117 |
HIGH | 7.2 | The Migration, Backup, Staging β WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploa… | — | wordfence |
| d8a81c01-495f-4861-b66f-000072e99512 | < 2.7.5 |
HIGH | 7.2 | The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'app… | — | wordfence |
| d8a4feb3-908f-4fff-84f2-099f56d46f5b | < 21.8.0.100 |
HIGH | 7.2 | The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to unauthorized modification of data … | — | wordfence |
| d8624f48-9938-4114-a55a-e635ca0dff2c | HIGH | 7.2 | The Buddybadges plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.0 due to insu… | — | wordfence | |
| d8616189-5ab8-4db0-ab9e-768cc738aeb6 | < 3.5.3 |
HIGH | 7.2 | The Jetpack plugin for WordPress, in versions up to 3.5.2, is vulnerable to DOM based Cross-Site Scripting via the file … | — | wordfence |
| d8351204-da6d-443a-98b5-0608bfb1e9d0 | < 14.15.5 |
HIGH | 7.2 | The WP Statistics β The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to Stored Cr… | — | wordfence |
| d7c0b933-469e-4f8b-94b2-8823568c5d45 | HIGH | 7.2 | The Rough Chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a Chart Data Label in versions up … | — | wordfence | |
| d77666b5-956d-420b-93ed-a15cdbfcced7 | < 6.2.0 |
HIGH | 7.2 | The WooCommerce Product Add-ons plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includ… | — | wordfence |
| d774af46-4928-4e86-b0e0-1a73f39a8f09 | < 1.10.0 |
HIGH | 7.2 | The FormGent β Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress i… | — | wordfence |
| d76229c9-39e6-48ab-b038-be40b36aa7bd | < 4.16.18 |
HIGH | 7.2 | The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Cross-Site Scripting in version… | — | wordfence |
| d759d7ab-74d5-4195-9258-7281f49b5132 | < 0.4.2.6 |
HIGH | 7.2 | The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the d… | — | wordfence |
| d7576dd9-198b-49a7-950e-fc301e4bc5f8 | < 5.4.5 |
HIGH | 7.2 | The Zero Spam plugin for WordPress is vulnerable to SQL Injection parameter in versions up to, and including, 5.4.4 due … | — | wordfence |
| d71caa62-6f77-44a6-8645-a27a08a48a78 | HIGH | 7.2 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor… | — | wordfence | |
| d6e16234-ec7b-466f-bc11-e80e63dec49f | < 1.3.47 |
HIGH | 7.2 | The Favicon by RealFaviconGenerator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… | — | wordfence |
| d6cbec61-cbe8-44a6-8cc8-8603393ed6b0 | < 2.2.4 |
HIGH | 7.2 | The WooCommerce Beta Tester plugin for WordPress is vulnerable to SQL Injection in versions prior to 2.2.4 due to insuff… | — | wordfence |
| d68e74c2-3732-40ae-b589-3a9159aff93d | < 2.9.0 |
HIGH | 7.2 | The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests l… | — | wordfence |
| d678eca4-ad6d-4511-9f6d-37269dcf0ecb | < 3.4.6 |
HIGH | 7.2 | The WP-CRM System plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.4.5 via… | — | wordfence |
| d66df15e-1a0a-49e9-bcf9-67091499b24e | < 2.6.4 |
HIGH | 7.2 | The plugin is vulnerable to PHP Object Injection in versions up to and including, 2.6.3 via deserialization of untrusted… | — | wordfence |
| d667bafc-5f19-4889-a988-236df050c013 | < 3.8.2 |
HIGH | 7.2 | The WP Post Author β Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post … | — | wordfence |
| d62bd2bd-db01-479f-89e4-8031d69a912f | HIGH | 7.2 | The Dropbox Folder Share plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and includ… | — | wordfence | |
| d619d300-8bba-45a1-bd0a-d82e9066a43d | < 4.6.16 |
HIGH | 7.2 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to arbitrary file uploads due to mi… | — | wordfence |
| d606cada-fd3d-4763-9751-5378e81969f0 | < 6.5.38 |
HIGH | 7.2 | The YOP Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.5.37 … | — | wordfence |
| d5f372bf-6b13-4ba7-8b8b-9d3b500e4420 | < 1.1.0 |
HIGH | 7.2 | The Lana Email Logger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions… | — | wordfence |
| d57e4c3b-6e0d-40d5-bcf3-10af797d2f1b | HIGH | 7.2 | The Shiny Buttons WordPress plugin through 1.1.0 does not have any authorisation and CSRF in place when saving a templat… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →