Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,758 vulnerabilities found (page 36 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b8672fd2-dc7a-4717-9d25-84180ad9b134 | < 1.21.16 |
CRITICAL | 9.8 | The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFI… | — | wordfence |
| b8652b40-480c-4d53-b1c8-e1dcfbd8a4a4 | CRITICAL | 9.8 | The AREA53 Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the php.p… | — | wordfence | |
| b8347b4e-a5ba-49c5-9ae6-690a1a5c9aac | < 12.1 |
CRITICAL | 9.8 | The tagDiv Composer plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versi… | — | wordfence |
| b829b7a1-2891-402b-a48f-a7fb1202448e | < 2.8 |
CRITICAL | 9.8 | The Shortcode Factory plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7 v… | — | wordfence |
| b812a0d7-99a1-4f61-b78a-78cea6a2ada1 | < 4.79 |
CRITICAL | 9.8 | The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin… | — | wordfence |
| b811f085-9374-41e7-a9ab-fecff0b9e19d | < 3.1.0 |
CRITICAL | 9.8 | Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_qui… | — | wordfence |
| b80c2a5a-49f2-4b93-a1eb-a0be53aa921d | CRITICAL | 9.8 | The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available… | — | wordfence | |
| b803ee40-733a-49bf-a134-406747541eb6 | < 0.5.0 |
CRITICAL | 9.8 | The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parame… | — | wordfence |
| b7f3b469-9a6c-4cc1-bb27-bd57bbae7208 | < 6.8.2 |
CRITICAL | 9.8 | The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to… | — | wordfence |
| b7b1620e-a26b-454d-890c-37dfa90abfad | CRITICAL | 9.8 | The CWW Portfolio theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.1. Thi… | — | wordfence | |
| b78eb275-bede-44f0-bf72-6931c37d78bf | < 1.3.4 |
CRITICAL | 9.8 | The TS Poll – Best Poll Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass due to a missi… | — | wordfence |
| b77c3d65-23c0-4bda-afea-9cad00fc04d6 | < 1.3.19 |
CRITICAL | 9.8 | The Invite Anyone plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.18 vi… | — | wordfence |
| b772a695-658f-41aa-b40e-b5a91a6d01a4 | CRITICAL | 9.8 | The Booking Calendar and Notification plugin for WordPress is vulnerable to authentication bypass in all versions up to,… | — | wordfence | |
| b771199e-937f-46d5-9906-4cbbbcd748cd | CRITICAL | 9.8 | The 4ECPS Web Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence | |
| b71706a7-e101-4d50-a2da-1aeeaf07cf4b | < 7.6.25 |
CRITICAL | 9.8 | The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includi… | — | wordfence |
| b71348c8-9e86-432e-b05e-96884344cef6 | < 1.1.4 |
CRITICAL | 9.8 | The LogDash Activity Log plugin for WordPress is vulnerable to SQL Injection via the username parameter in all versions … | — | wordfence |
| b70f5416-06e0-4b6f-b61d-b7c23575a171 | < 3.9.1 |
CRITICAL | 9.8 | The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues. | — | wordfence |
| b6efe739-713b-4620-b78f-a8ec7b164cd1 | CRITICAL | 9.8 | The Support Ticket plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.… | — | wordfence | |
| b6ee571d-8db6-4e21-9a62-44e562b9a5fc | < 2.0.16 |
CRITICAL | 9.8 | … | — | wordfence |
| b6cab377-0a8a-45d2-a966-4c7f100b9409 | CRITICAL | 9.8 | The Portfolio Slideshow Pro plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in al… | — | wordfence | |
| b6c69a25-8986-4976-8753-ce8e5be311e2 | < 2.0.6 |
CRITICAL | 9.8 | The Absolute Privacy plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 2.0.5… | — | wordfence |
| b6c5cc05-b147-46f6-aaa9-4c82aae1b544 | < 1.0.1 |
CRITICAL | 9.8 | The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, an… | — | wordfence |
| b6b43503-e6f0-4097-9e41-eaae7011b17b | < 1.8 |
CRITICAL | 9.8 | The Nexos - Real Estate WordPress Theme theme for WordPress is vulnerable to generic SQL Injection via the ‘search_ord… | — | wordfence |
| b69c86f4-d81d-4e14-baff-3402008bb9c6 | < 4.19.1 |
CRITICAL | 9.8 | The CiyaShop - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to PHP Object Injection in all versions … | — | wordfence |
| b65cdbe0-e258-4bb5-9a36-cbf57b75ce77 | CRITICAL | 9.8 | The Custom Background plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →