Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,758 vulnerabilities found (page 38 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b39f4467-4764-4850-bdcc-b359a6544b42 | < 3.37.15 |
CRITICAL | 9.8 | LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution. | — | wordfence |
| b352b2e4-8d72-4ebd-8dcd-8e2740759f3e | CRITICAL | 9.8 | The WP Contacts Manager WordPress plugin through 2.2.4 fails to properly sanitize user supplied POST data before it is b… | — | wordfence | |
| b3451ed9-9a9a-443f-b1ce-dcd07bd3e6ce | CRITICAL | 9.8 | The WP MLM SOFTWARE PLUGIN plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… | — | wordfence | |
| b343269f-35f2-4cba-b539-3a4d8fd4baf4 | < 1.2.0 |
CRITICAL | 9.8 | The ShopMonitor.io β Automated Checkout & Form Monitoring plugin for WordPress is vulnerable to privilege escalation v… | — | wordfence |
| b2ea5e77-335a-4f40-9a04-9e1d4f3e1017 | CRITICAL | 9.8 | The WP images upload on piclect plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and i… | — | wordfence | |
| b2c03142-be30-4173-a140-14d73a16dd2b | < 5.0.2 |
CRITICAL | 9.8 | The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in … | — | wordfence |
| b29dcd7a-a0bc-4983-85ba-6ebf2c405ceb | < 8.1.5 |
CRITICAL | 9.8 | The Quiz and Survey Master plugin for WordPress is vulnerable to SQL Injection via the 'question_ids_[XX]' cookie in ver… | — | wordfence |
| b299a932-8167-4547-845b-637c4971360d | < 3.4.13 |
CRITICAL | 9.8 | The Post Grid Master β Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Paginat… | — | wordfence |
| b291ed6f-0998-40fc-a628-4df6416c9fc4 | < 3.0 |
CRITICAL | 9.8 | Directory traversal vulnerability in pageflipbook.php script from index.php in Page Flip Book plugin for WordPress (wppa… | — | wordfence |
| b280155e-6d07-448d-922c-4a0ea21f4992 | < 1.0.4 |
CRITICAL | 9.8 | The Biometric Login for WooCommerce plugin for WordPress is vulnerable to privilege escalation in versions up to, and in… | — | wordfence |
| b27995b1-3321-4997-8a25-80c9488b8405 | < 6.930 |
CRITICAL | 9.8 | The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does no… | — | wordfence |
| b26d61de-651c-43de-ba90-33ef170755e0 | CRITICAL | 9.8 | Vulnerability in wordpress plugin eventr v1.02.2, The edit.php form and attendees.php code do not sanitize input, this a… | — | wordfence | |
| b2143edf-5423-4e79-8638-a5b98490d292 | < 3.19.3 |
CRITICAL | 9.8 | The GiveWP β Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in al… | — | wordfence |
| b20f94c6-4e97-4fe8-a2a5-ce825bb120d3 | CRITICAL | 9.8 | The CiyaShop theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.18.0 via dese… | — | wordfence | |
| b1e98d2d-20b1-4fff-96d4-0fb8e0d2615a | CRITICAL | 9.8 | The Delete All Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… | — | wordfence | |
| b1e51951-0e4c-44f3-a11b-13c0be984a7f | < 2.7.0 |
CRITICAL | 9.8 | The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc… | — | wordfence |
| b1cdd6c6-f354-48d6-9493-08c67aaef9bd | CRITICAL | 9.8 | SQL injection vulnerability in myLDlinker.php in the myLinksDump Plugin 1.2 for WordPress allows remote attackers to exe… | — | wordfence | |
| b1a29180-901d-447e-8f82-63161b9e11e0 | CRITICAL | 9.8 | The Sayfa Sayac plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6 via… | — | wordfence | |
| b1782c82-bfdb-4104-a3f5-b1a07aede555 | CRITICAL | 9.8 | Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id v… | — | wordfence | |
| b170ac00-5d5c-46ef-95f3-e98ef4528999 | < 6.4.2 |
CRITICAL | 9.8 | WordPress Core is vulnerable to remote code execution via a PHP gadget in version 6.4.0 and 6.4.1. This is due to there … | — | wordfence |
| b12deaa4-246e-4502-8091-fcbe5a2eae15 | CRITICAL | 9.8 | The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php. | — | wordfence | |
| b1278291-9fef-40f5-a432-d96f4bed31fe | < 3.11 |
CRITICAL | 9.8 | The Rencontre plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.10.1. T… | — | wordfence |
| b121fdb4-93a8-400c-89c2-3195cb40e03c | < 2.0.0 |
CRITICAL | 9.8 | The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all ve… | — | wordfence |
| b113f475-3133-4ea3-9152-03bb84d79307 | < 1.0.4 |
CRITICAL | 9.8 | The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3… | — | wordfence |
| b10d01ec-54ef-456b-9410-ed013343a962 | CRITICAL | 9.8 | The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →