Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 364 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b15b10a4-04fd-4860-9cc9-cefcdbbbf507 | < 1.0.8 |
HIGH | 7.2 | The User Rights Access Manager plugin for WordPress is vulnerable to Access Restriction Bypass via the 'page' parameter … | — | wordfence |
| b100ba5a-8aad-4aa1-98bf-a09c5bde7bc1 | HIGH | 7.2 | The Resume Submissions & Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… | — | wordfence | |
| b0e582e3-9ca3-4601-81f2-cb6ef827a468 | < 1.7.2 |
HIGH | 7.2 | The Contact Form to DB by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in versi… | — | wordfence |
| b0c12678-1d91-4916-aa11-20292d9e384b | < 5.2.2 |
HIGH | 7.2 | The Meta pixel for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… | — | wordfence |
| b0c01e62-7a31-49de-851c-f52ce578bd95 | < 8.1.00 |
HIGH | 7.2 | The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log co… | — | wordfence |
| b06201bd-4f8e-41e5-89e1-b1f47757799b | < 5.6.8 |
HIGH | 7.2 | The AutomatorWP β Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for Wor… | — | wordfence |
| b034605b-284c-478a-baec-224c4533b2e0 | < 3.5.9 |
HIGH | 7.2 | The Proxy & VPN Blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… | — | wordfence |
| b02ab0cf-8bdf-4415-bae3-2193c3d75741 | HIGH | 7.2 | The Giveaway WordPress plugin through 1.2.2 is vulnerable to an SQL Injection issue which allows an administrative user … | — | wordfence | |
| afe6d4ac-1712-415e-9995-cb7c8fe4e1a0 | < 5.0.9 |
HIGH | 7.2 | The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites β PostX plugin for WordPress is vulnerable to Server… | — | wordfence |
| afc6aec8-e486-4c35-9e58-da6e04d88c25 | < 4.0.0 |
HIGH | 7.2 | The Login by Auth0 plugin before 4.0.0 for WordPress allows stored XSS on multiple pages, a different issue than CVE-202… | — | wordfence |
| afbfef8e-cdea-4ca0-bd28-08cc30eeec6e | < 4.0.9 |
HIGH | 7.2 | The Visual Website Collaboration, Feedback & Project Management β Atarim plugin for WordPress is vulnerable to Stored … | — | wordfence |
| afbfabfc-b923-4fe9-9e8f-0cf159f488db | < 5.3.5 |
HIGH | 7.2 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' and 'resource' … | — | wordfence |
| af7dbb61-90b1-4a61-819e-bcef88b12b7f | < 1.7.26 |
HIGH | 7.2 | The Multi Step Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via… | — | wordfence |
| af6a7052-6dab-42f0-a2af-0cf459d309d7 | < 2.1.5.2 |
HIGH | 7.2 | The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.… | — | wordfence |
| af5ed47e-f183-4e72-a916-15020e2bc91e | < 1.0.229 |
HIGH | 7.2 | The Rank Math SEO β AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to PHP Object Injection i… | — | wordfence |
| af187180-0f10-4fc0-8376-0e224a44d7eb | < 4.0.13 |
HIGH | 7.2 | The Easy Form Builder by WhiteStudio β Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Sit… | — | wordfence |
| aefa868e-64ee-4852-bdbc-2de118b9e991 | < 5.1.0 |
HIGH | 7.2 | The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripti… | — | wordfence |
| aef312be-85d6-45e7-a34f-7f7cc415df3b | < 1.5.3 |
HIGH | 7.2 | The WP User Merger plugin for WordPress is vulnerable to generic SQL Injection via 'reassign_user' parameter versions up… | — | wordfence |
| aebdd464-10b9-4d43-bf38-f0e8ae25625f | < 14.0.1 |
HIGH | 7.2 | The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scrip… | — | wordfence |
| ae9df4e5-b1d2-400b-89c7-eac5fbf2a8d5 | HIGH | 7.2 | The Visitors WordPress plugin through 0.3 is affected by an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerabil… | — | wordfence | |
| ae9cd51f-e6c8-4aec-a044-376075e9540a | < 0.8.8.7 |
HIGH | 7.2 | The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters … | — | wordfence |
| ae603b13-dc09-4f83-8741-943d62615b3c | < 2.0.1 |
HIGH | 7.2 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo… | — | wordfence |
| ae058c5b-b90b-4a1e-9f56-d56dbd2d3607 | < 2.1.10 |
HIGH | 7.2 | The Pretty Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various IP headers as well as the… | — | wordfence |
| ade73ae0-4193-47e3-a545-2563fd19fb54 | < 1.2.7 |
HIGH | 7.2 | The Geeky Bot β AI Sales Assistant for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting i… | — | wordfence |
| ade06c00-43b7-48b3-9c9d-4921fb52cc66 | HIGH | 7.2 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →