Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 374 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 8b430f0a-d50c-4923-8916-2c26bf5d619a | < 5.2.0 |
HIGH | 7.2 | WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto versions below 5.2 are vulnerable to C… | — | wordfence |
| 8b2d42ab-46c1-4c3e-b99a-1cdcade1b5bb | HIGH | 7.2 | The Video List Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7 due to … | — | wordfence | |
| 8b213c3b-3907-47d9-9826-379936f15078 | < 2.1.7 |
HIGH | 7.2 | The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's … | — | wordfence |
| 8ae734d1-0cd4-4ff5-8448-828b0fb64f70 | HIGH | 7.2 | The SMTP Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, … | — | wordfence | |
| 8ad7c3d5-fce8-4214-a7f8-5aa2b9fe0934 | < 5.8.22 |
HIGH | 7.2 | The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL st… | — | wordfence |
| 8acb86fa-50b4-45b3-9bf8-ef65679b85ac | < 5.2.1 |
HIGH | 7.2 | Authenticated (admin or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Herd Effects plugin … | — | wordfence |
| 8a303875-ad8c-40ed-a3ab-4a63080c9845 | < 4.1.8 |
HIGH | 7.2 | The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a … | — | wordfence |
| 8a1179bc-6f8d-4223-a80b-9834adc08d3b | HIGH | 7.2 | The ark-commenteditor plugin for WordPress is vulnerable to iFrame Injection in versions up to, and including 2.15.6 due… | — | wordfence | |
| 8a106ebb-f3ec-4995-9717-358b91d468b4 | < 4.16.4 |
HIGH | 7.2 | The GiveWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.16.3 du… | — | wordfence |
| 89fe030b-253f-4fbc-b593-fb92fb7eb323 | < 5.0.1 |
HIGH | 7.2 | The Autopay / Blue Media for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… | — | wordfence |
| 89e2962a-b884-4577-a29b-92087e10ce58 | HIGH | 7.2 | The Synergy Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… | — | wordfence | |
| 89655e84-acb5-40f2-a22f-a483a1bb29df | < 7.9.7 |
HIGH | 7.2 | The NEX-Forms plugin for WordPress is vulnerable to SQL Injection via the ‘form_id’ parameter in versions up to, and… | — | wordfence |
| 88fe46bf-8e85-4550-92ad-bdd426e5a745 | < 2.9 |
HIGH | 7.2 | The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' paramet… | — | wordfence |
| 88b0e98b-3416-40d1-9901-6ab0dfb7dea1 | < 3.26.7 |
HIGH | 7.2 | The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … | — | wordfence |
| 884b97b7-d023-4752-81b1-086ab022f85e | < 4.8.0 |
HIGH | 7.2 | The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parame… | — | wordfence |
| 8848a247-52a6-48de-9ad5-deef89c2c599 | HIGH | 7.2 | The Wow Forms WordPress plugin through 3.1.3 does not sanitise or escape a 'did' GET parameter before using it in a SQL … | — | wordfence | |
| 87f7b9c3-f3aa-4ace-ab67-c32fa92fcffe | < 5.0.0 |
HIGH | 7.2 | The Dynamic Pricing With Discount Rules for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… | — | wordfence |
| 87e408c4-55da-4765-8ca6-e709b9045c8b | HIGH | 7.2 | The fs-shopping-cart plugin 2.07.02 for WordPress has SQL injection via the pid parameter. | — | wordfence | |
| 879df622-ca6a-45ea-b8f9-e3882d4bfff7 | < 1.6.12.11 |
HIGH | 7.2 | The Simply Schedule Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… | — | wordfence |
| 87950d16-dba6-4759-b15f-57c495cdda67 | < 1.18.4 |
HIGH | 7.2 | The GlobalPayments Gateway Provider for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in… | — | wordfence |
| 874130f0-7dc9-49fe-a7b0-e0be432799bd | < 3.2.9 |
HIGH | 7.2 | The Google XML Sitemaps Generator plugin for WordPress is vulnerable to PHP Code Injection in versions before 3.2.9 via … | — | wordfence |
| 8727f4fa-b6a9-4da7-b2a5-5d74ddcc082f | < 2.12.3 |
HIGH | 7.2 | The WP Debugging plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1… | — | wordfence |
| 87178c7c-343b-487a-9adb-7ff13aae81df | < 3.1.51 |
HIGH | 7.2 | The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerabl… | — | wordfence |
| 870bf5fe-00c6-48fe-b9e6-e8233c689b71 | HIGH | 7.2 | The Gerador de Certificados – DevApps plugin for WordPress is vulnerable to arbitrary file uploads due to missing file… | — | wordfence | |
| 870ae326-a7c9-4201-bf0d-0fbda663a694 | < 1.3.73 |
HIGH | 7.2 | The Appointment Hour Booking plugin for WordPress is vulnerable to iFrame Injection via the ‘email’ or general field… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →