Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 360 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| bce9ba42-f574-47c1-9ea5-1e56f9da8e71 | < 1.0.16 |
HIGH | 7.2 | The User Feedback β Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulne… | — | wordfence |
| bcd50211-447c-4097-9281-551a3caad1a6 | < 1.8.0 |
HIGH | 7.2 | The WangGuard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_ip' variable in version 1.… | — | wordfence |
| bcb68038-96a6-40b6-a37c-757fc19cbe0c | < 13.1.6 |
HIGH | 7.2 | The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization o… | — | wordfence |
| bc972855-6bd5-43cd-96e6-3b1aa1c6255b | < 1.5.0 |
HIGH | 7.2 | The Easy WP SMTP plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.9 via … | — | wordfence |
| bc5f1b00-acee-4dc8-acd7-2d3f3493f253 | HIGH | 7.2 | The MpOperationLogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the IP Request Headers in vers… | — | wordfence | |
| bc5cd81b-3182-45fb-a93a-471ecf770e42 | < 7.5 |
HIGH | 7.2 | The Team Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.4. This m… | — | wordfence |
| bc38990f-0079-46de-8197-0187189d90d9 | < 4.9.24 |
HIGH | 7.2 | The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … | — | wordfence |
| bbe8c101-5e0a-4ba7-8ff7-4c8ed01e9ef5 | < 2.1.3 |
HIGH | 7.2 | The Nginx Cache Purge Preload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and inc… | — | wordfence |
| bbdca292-89b6-4e62-bc68-4fdcd57fd504 | < 4.0 |
HIGH | 7.2 | process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_fil… | — | wordfence |
| bbd580fe-dba4-4662-b7d5-cf0298279079 | < 1.1.9 |
HIGH | 7.2 | The BEAR β Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulne… | — | wordfence |
| bbd48a92-dc8f-4f51-b799-f7cedac34661 | HIGH | 7.2 | The Bakery Autoresponder Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … | — | wordfence | |
| bbc1b46e-139a-4e1a-a0c7-e45e10adada5 | < 2.6.7 |
HIGH | 7.2 | The get_reports() function in the Secure Copy Content Protection and Content Locking WordPress plugin before 2.6.7 did n… | — | wordfence |
| bbaba6cb-a829-4c07-b068-bdcb6a646450 | < 1.3.6.3 |
HIGH | 7.2 | The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via th… | — | wordfence |
| bba8007f-7254-4201-8f94-7bf921a33a27 | < 4.4.0 |
HIGH | 7.2 | The Cookie Banner for GDPR / CCPA β WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Script… | — | wordfence |
| bb927aba-a96d-47b9-ba35-60945ea5cfe5 | < 1.8.97 |
HIGH | 7.2 | The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inclu… | — | wordfence |
| bb6f3607-d44f-452a-b3ad-55f036033480 | < 1.6.7.43 |
HIGH | 7.2 | The Appointment Booking Calendar β Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to R… | — | wordfence |
| bb1def67-ad83-4ad5-bb11-fbd1c02ece47 | < 1.7.6.3 |
HIGH | 7.2 | The Propovoice CRM β Best CRM & Invoicing Plugin to Manage Leads, Clients and Billings automation plugin for WordPres… | — | wordfence |
| bb14a79a-32ba-4d7a-b706-4e602a25e9cf | < 1.1.1 |
HIGH | 7.2 | The Enable SVG, WebP & ICO Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type … | — | wordfence |
| bb03aeb8-32ab-4962-bc95-b10fb7bd7fcf | < 3.9.4 |
HIGH | 7.2 | The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to m… | — | wordfence |
| bad00612-d98e-4b5e-88e8-664064588bdd | < 3.0.7 |
HIGH | 7.2 | The Extensions For CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… | — | wordfence |
| bacfa993-2fc1-43bc-b4f0-f463ba28b4ed | < 1.5.2.1 |
HIGH | 7.2 | The Landing Page Builder β Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress… | — | wordfence |
| bacd7942-99f6-46e0-85ef-863ab1bdfa6a | < 1.1.6 |
HIGH | 7.2 | The CP Contact Form with PayPal plugin for WordPress is vulnerable to SQL Injection via the 'cp_contactformpp_id' parame… | — | wordfence |
| baa063b7-8b79-4de3-84b1-6dec024fa395 | < 1.0.6 |
HIGH | 7.2 | The Event Management Tickets Booking By Event Monster plugin for WordPress is vulnerable to Stored Cross-Site Scripting … | — | wordfence |
| ba6312b9-1b66-4b4f-a78d-515fa4aab63b | < 2.12.4 |
HIGH | 7.2 | The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.… | — | wordfence |
| ba5485be-7612-406d-870d-6827f6c7ea71 | HIGH | 7.2 | The Sticky Anything plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →