Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 362 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b7d85921-9d70-4812-9c5f-11ee1d0821be | < 1.12.9 |
HIGH | 7.2 | The WP ERP plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in versions up to, and including, 1… | — | wordfence |
| b7c70db1-5058-45e5-bd12-3e2cab0338ad | < 3.3.2 |
HIGH | 7.2 | Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors… | — | wordfence |
| b7c0efd8-08c0-4283-a0bf-2f6ca3998668 | < 1.0.3 |
HIGH | 7.2 | The Plezi WordPress plugin before 1.0.3 has a REST endpoint allowing unauthenticated users to update the plz_configurati… | — | wordfence |
| b77e31cf-f5fd-4ae4-84bd-e92fe34690da | < 1.4 |
HIGH | 7.2 | The Traveler Layout Essential For Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all ver… | — | wordfence |
| b73edf8f-7017-4239-8ddc-038481d3f65f | < 3.5.0 |
HIGH | 7.2 | The AI Engine β The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalati… | — | wordfence |
| b72cfc20-b133-4682-91e1-497236aba035 | HIGH | 7.2 | The WP-TopBar plugin for WordPress is vulnerable to blind SQL Injection in versions up to, and including, 5.36 due to in… | — | wordfence | |
| b6fe5f1a-787e-4662-915f-c6f04961e194 | HIGH | 7.2 | The WH Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters such as wh… | — | wordfence | |
| b6f0fe85-1b70-49b4-9c89-d00584362459 | < 1.7.6 |
HIGH | 7.2 | The tagDiv Opt-In Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… | — | wordfence |
| b6e587fb-118b-44b6-a2bb-1d621f02845c | HIGH | 7.2 | The Popup Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.… | — | wordfence | |
| b6e4d8c3-f3ab-40f9-a8d2-77b53a8dba72 | < 13.2.9 |
HIGH | 7.2 | The WP Statistics plugin for WordPress is vulnerable to SQL Injection via the $search_engine value in versions up to, an… | — | wordfence |
| b6d448c2-5acc-47f8-8e86-9ef10fa01513 | HIGH | 7.2 | The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 … | — | wordfence | |
| b6ca5856-9010-4bb3-a024-92b3b4d500b4 | HIGH | 7.2 | The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save… | — | wordfence | |
| b6310a0c-5a96-4dbc-940e-025c9b907c7d | HIGH | 7.2 | The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, … | — | wordfence | |
| b6056cc5-1848-4c0c-8de2-9c6310687902 | < 1.6.15 |
HIGH | 7.2 | The Product Addons β WowAddons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… | — | wordfence |
| b5f09c7a-a8f5-4885-97fe-9347d20b8817 | < 7.6.60 |
HIGH | 7.2 | The wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.6.59 … | — | wordfence |
| b5bb14c1-8713-4aa1-b50a-53bed07a5f80 | < 1.3.1 |
HIGH | 7.2 | The Easy Email Subscription plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter i… | — | wordfence |
| b591b7df-8492-4f66-8884-b4b27c0f0a11 | < 2.37 |
HIGH | 7.2 | The Advanced Woo Labels β Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to Remote Code Ex… | — | wordfence |
| b56a3e53-ae1a-4bec-8350-3df157c4ab3c | < 3.8.13.1 |
HIGH | 7.2 | The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.13… | — | wordfence |
| b556bb3b-0fea-48a9-a893-3ad015559f3d | < 1.7.1 |
HIGH | 7.2 | The GD Security Headers plugin for WordPress is vulnerable to union-based SQL Injection via the 'filter-vd' and 'filter-… | — | wordfence |
| b5318c2d-7b58-4830-bbc0-6d160968290f | HIGH | 7.2 | The WassUp Real Time Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via spoofed IP Addresse… | — | wordfence | |
| b526b331-8c02-44b1-9555-156afe7ad45a | < 2.8.3 |
HIGH | 7.2 | WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability | — | wordfence |
| b4f2554d-c047-4be2-a4e6-2ae51f077376 | < 2.7.11.1 |
HIGH | 7.2 | The Groundhogg plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.7.11 due to insuf… | — | wordfence |
| b4e61162-dba8-4cb8-b953-031b963de208 | < 1.5.3 |
HIGH | 7.2 | The Form Vibes β Save Contact Form 7 & Elementor Form Entries to Database plugin for WordPress is vulnerable to Stored… | — | wordfence |
| b4e1638a-ddfb-44e5-951e-3e779971a3a7 | < 3.3.1 |
HIGH | 7.2 | The Better Search β Relevant search results for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scri… | — | wordfence |
| b4b2587a-e84e-4149-b9ac-ecf36451f815 | < 1.5.5 |
HIGH | 7.2 | The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form pa… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →