Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 38 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| af37f301-d97f-47d3-b6a8-88cb41344541 | < 5.4.4 |
CRITICAL | 9.8 | Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication b… | — | wordfence |
| af008739-3b75-4e79-ac4a-3829986b7bf0 | CRITICAL | 9.8 | The Spreadsheet Price Changer for WooCommerce and WP E-commerce β Light plugin for WordPress is vulnerable to Privileg… | — | wordfence | |
| aefbebce-9433-455d-b27c-93088b0c8494 | < 1.24 |
CRITICAL | 9.8 | The LeadSnap plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.23 via deser… | — | wordfence |
| ae50aa5d-95e3-4650-9dbf-118b4ba3abda | < 9.644 |
CRITICAL | 9.8 | The WP Cost Estimation plugin for WordPress is vulnerable to arbitrary file uploads and deletion due to missing file typ… | — | wordfence |
| ae4d47b3-59c3-46d1-80c2-d11c98fb9b1e | CRITICAL | 9.8 | The Digital Lottery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence | |
| ae46be82-570f-4172-9c3f-746b894b84b9 | < 3.4.29 |
CRITICAL | 9.8 | The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and in… | — | wordfence |
| ae12f71d-0f53-4942-83a7-856633e665ca | CRITICAL | 9.8 | The Plg Novana plugin for WordPress is vulnerable to generic SQL Injection via the βidβ parameter in all versions du… | — | wordfence | |
| ae07ca12-e827-43f9-8cbb-275b9abbd4c3 | CRITICAL | 9.8 | The WP Query Console plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1… | — | wordfence | |
| ae07af10-e5fc-4f28-a343-f56c0e2bc324 | CRITICAL | 9.8 | The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1… | — | wordfence | |
| add12281-7c2b-4b79-a744-36e9fd923611 | CRITICAL | 9.8 | The SSV MailChimp plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.1.5. Th… | — | wordfence | |
| adb4644c-6ef6-4899-b0f1-2629ffacd19c | < 1.6.5 |
CRITICAL | 9.8 | The Gmedia Photo Gallery plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.… | — | wordfence |
| ad4acbcb-5044-4752-9db0-74bd6f99a963 | < 5.0.5 |
CRITICAL | 9.8 | The Dokan Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.4. Th… | — | wordfence |
| ad4878fb-dd0f-473b-9887-d993a89fedd2 | < 4.3.8 |
CRITICAL | 9.8 | The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it i… | — | wordfence |
| ad39d797-9230-41d9-a335-864845b56aa0 | < 16.7 |
CRITICAL | 9.8 | The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p… | — | wordfence |
| ad0d60f2-6354-4c2c-aaab-23fc9b8065fe | CRITICAL | 9.8 | The HelpGent plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.4 via dese… | — | wordfence | |
| acebc874-5853-405c-adb3-c6582d8c5e42 | < 3.3.2 |
CRITICAL | 9.8 | The Gutenberg Blocks plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.3.1.… | — | wordfence |
| ace7ab05-799a-412c-8c0b-3429852f0263 | CRITICAL | 9.8 | The Service Finder Bookings plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includ… | — | wordfence | |
| ac53af7e-0c50-413c-90de-0d50d5c17463 | < 2.5.2 |
CRITICAL | 9.8 | The Tastyc theme for WordPress is vulnerable to Local File Inclusion in versions up to 2.5.2. This makes it possible for… | — | wordfence |
| ac1f9d9c-4d4e-4036-95b1-50d09b5cac7c | CRITICAL | 9.8 | The ThisWay Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the uplo… | — | wordfence | |
| abef988c-1fd2-45dc-8eac-447b0baad5aa | < 1.1.7 |
CRITICAL | 9.8 | The Mags theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.6. This makes i… | — | wordfence |
| abe73ecd-1325-4d6d-8545-d27f6116ca43 | < 1.2.9 |
CRITICAL | 9.8 | The Realteo - Real Estate Plugin by Purethemes plugin for WordPress, used by the Findeo Theme, is vulnerable to authenti… | — | wordfence |
| abdd6aaa-830e-4a79-acfb-93dc4a26f599 | < 2.0.15 |
CRITICAL | 9.8 | The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Remote Code Execution in ve… | — | wordfence |
| abcc1ed6-1871-4e8c-9469-c44dbfca5a17 | CRITICAL | 9.8 | The WP MLM SOFTWARE PLUGIN plugin for WordPress is vulnerable to privilege in all versions up to, and including, 4.0. Th… | — | wordfence | |
| ab9a5d89-16be-4dc7-9361-2b1be2324239 | < 2.14.15.1 |
CRITICAL | 9.8 | The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before usi… | — | wordfence |
| ab721099-677d-48f4-83ba-f4c409374e80 | < 1.6.9 |
CRITICAL | 9.8 | The Accounting for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →