Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 37 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b170ac00-5d5c-46ef-95f3-e98ef4528999 | < 6.4.2 |
CRITICAL | 9.8 | WordPress Core is vulnerable to remote code execution via a PHP gadget in version 6.4.0 and 6.4.1. This is due to there … | — | wordfence |
| b12deaa4-246e-4502-8091-fcbe5a2eae15 | CRITICAL | 9.8 | The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php. | — | wordfence | |
| b1278291-9fef-40f5-a432-d96f4bed31fe | < 3.11 |
CRITICAL | 9.8 | The Rencontre plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.10.1. T… | — | wordfence |
| b121fdb4-93a8-400c-89c2-3195cb40e03c | < 2.0.0 |
CRITICAL | 9.8 | The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all ve… | — | wordfence |
| b113f475-3133-4ea3-9152-03bb84d79307 | < 1.0.4 |
CRITICAL | 9.8 | The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3… | — | wordfence |
| b10d01ec-54ef-456b-9410-ed013343a962 | CRITICAL | 9.8 | The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin… | — | wordfence | |
| b10a4561-1724-4e98-bff2-ca5416b217dc | CRITICAL | 9.8 | The Finalist plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all known versions due to… | — | wordfence | |
| b108ba89-56c4-44a8-af61-ccd6f7f73562 | CRITICAL | 9.8 | The AA-Team Premium SEO Pack plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includin… | — | wordfence | |
| b08198a6-10e8-44ca-a1c5-8d987d85c469 | < 2.6.04 |
CRITICAL | 9.8 | The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including… | — | wordfence |
| b0603621-4521-4eb0-b4dd-e2257c133cee | < 2.6.6 |
CRITICAL | 9.8 | The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'co… | — | wordfence |
| b04a5a8e-17ec-48e7-85b8-a14bd2222583 | CRITICAL | 9.8 | The Plugin Propagator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… | — | wordfence | |
| b0399b60-6e40-4f35-985f-845a32f69d64 | CRITICAL | 9.8 | The TerraClassifieds – Simple Classifieds Plugin plugin for WordPress is vulnerable to arbitrary file uploads in all v… | — | wordfence | |
| b0315b53-46a1-46b4-a53e-0d914866ca50 | CRITICAL | 9.8 | The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowe… | — | wordfence | |
| b0302a75-217f-4be9-876e-10ede3e3c20d | CRITICAL | 9.8 | The Adblocker Blocker plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… | — | wordfence | |
| b027c9f9-3144-4783-b646-ee1e02cd27ef | < 1.8.8 |
CRITICAL | 9.8 | The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7… | — | wordfence |
| aff754d6-8624-4068-8e31-738f6041d3a6 | < 1.2.42 |
CRITICAL | 9.8 | An issue was discovered in Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-… | — | wordfence |
| aff4f695-3c3b-48ee-8de1-674b588f332f | < 5.1.5.5 |
CRITICAL | 9.8 | The Evarisk plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upl… | — | wordfence |
| afe894b0-5e91-4aa2-bbd1-1f74274701cf | CRITICAL | 9.8 | The Sign In With Google plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including… | — | wordfence | |
| afe10c10-cace-4ce4-a813-6fda04c8d3dd | < 1.2.4 |
CRITICAL | 9.8 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass i… | — | wordfence |
| afd48bc8-d490-4a3e-97fc-70cf008cbf66 | < 3.8.1 |
CRITICAL | 9.8 | The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of … | — | wordfence |
| af90aef0-fd96-43ff-8400-09bd5cebed28 | < 2.67.2 |
CRITICAL | 9.8 | The WP-EMail Plugin for WordPress is vulnerable to SQL Injection via the ‘last_emailed’ parameter in versions before… | — | wordfence |
| af7345f9-6f62-424b-b02d-c145a90508ae | < 2.2.0 |
CRITICAL | 9.8 | The WordPress Zero Spam plugin for WordPress is vulnerable to Blind SQL Injection in versions up to, and including, 2.1.… | — | wordfence |
| af7163da-79b3-45df-a33c-01367205bb6f | < 1.1.0 |
CRITICAL | 9.8 | Vulnerability in Easy2map-photos WordPress Plugin v1.0.9 allows SQL Injection via unsanitized mapTemplateName, mapName, … | — | wordfence |
| af5eb3cd-f527-4b4e-a02e-699155f27b0d | < 1.1.4 |
CRITICAL | 9.8 | The Opal Woo Custom Product Variation plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient … | — | wordfence |
| af5a58d1-946a-451b-bc8b-a397345ae89a | < 4.4.4 |
CRITICAL | 9.8 | The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to PHP Object Injection in versions before 4.4.4 vi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →