Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,836 vulnerabilities found (page 381 of 1594)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 6fb07b77-3d8a-42c6-b62b-9567226333c5 | HIGH | 7.2 | The WordPress & WooCommerce Scraper Plugin, Import Data from Any WebSite. plugin for WordPress is vulnerable to Server-S… | — | wordfence | |
| 6f781533-b633-4452-95bd-c32ed0de2ea9 | < 1.8 |
HIGH | 7.2 | The Simple Membership WP user Import plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter… | — | wordfence |
| 6f4ea8c9-4e4b-41a7-a2ca-826cbd7d8c23 | < 250424 |
HIGH | 7.2 | The s2Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 250419 via the… | — | wordfence |
| 6ef8bf27-3b20-4d90-8d29-b9713d2c41d6 | < 1.7.31 |
HIGH | 7.2 | The Contact Form Maker plugin for WordPress is vulnerable to blind SQL Injection via the ‘form_id’ parameter in vers… | — | wordfence |
| 6ee675dd-5b43-439f-9717-6c531e9bf066 | < 5.3.3 |
HIGH | 7.2 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'outbound_resource' par… | — | wordfence |
| 6ecd0fa6-4fdb-4780-9560-0bb126800685 | < 2.5.8 |
HIGH | 7.2 | The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, an… | — | wordfence |
| 6eb19d3a-b180-4141-8c9b-bec436eeea6b | < 2.0.5 |
HIGH | 7.2 | The Ocean Extra plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.4 via … | — | wordfence |
| 6e8d9f73-8460-4bcb-a9f8-08eb058bcc09 | < 3.4.2 |
HIGH | 7.2 | The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include… | — | wordfence |
| 6e8646f0-8bd1-4cfd-85bb-86a054ab297f | < 1.2.13 |
HIGH | 7.2 | The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0]… | — | wordfence |
| 6e81cbe3-1310-4f6f-ae42-8d09b321657a | < 2.8 |
HIGH | 7.2 | Redirection version 2.7.3 contains a ACE via file inclusion vulnerability in Pass-through mode that can result in allows… | — | wordfence |
| 6e349cae-a996-4a32-807a-a98ebcb01edd | < 1.5.9 |
HIGH | 7.2 | The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable … | — | wordfence |
| 6e15a7b0-2b0e-468d-a245-cec2ed77d73b | HIGH | 7.2 | The Menu Item Visibility Control plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and incl… | — | wordfence | |
| 6e0384c0-9b34-4af8-af86-75ef1e8d933b | < 21.0426 |
HIGH | 7.2 | The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant … | — | wordfence |
| 6dda19a3-277e-49e6-b6fb-c4dd2df4aa38 | < 3.5.4 |
HIGH | 7.2 | The AliExpress Dropshipping Plugin for WooCommerce – AliNext plugin for WordPress is vulnerable to Open Redirect in al… | — | wordfence |
| 6dc69491-0f40-4bab-9215-b25f72110e26 | < 1.3.19 |
HIGH | 7.2 | The AIO Forms – Craft Complex Forms Easily plugin for WordPress is vulnerable to arbitrary file uploads due to missing… | — | wordfence |
| 6da7046e-2717-4a3c-bba9-88f27de29ede | < 2.5.2 |
HIGH | 7.2 | The PublishPress Capabilities plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includin… | — | wordfence |
| 6d5ef392-6aea-4fab-95ce-d36d1cd17026 | < 3.1.0 |
HIGH | 7.2 | The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to arbitrary… | — | wordfence |
| 6d374ccc-74f2-4064-8801-4adfcb200eb2 | HIGH | 7.2 | The EP4 More Embeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… | — | wordfence | |
| 6d2aa302-aaab-4bf1-9a79-144290b967de | < 2.6 |
HIGH | 7.2 | The Social Reviews & Recommendations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several param… | — | wordfence |
| 6d1b255f-d775-4bd5-892e-42bf82dd5632 | < 2.13.4 |
HIGH | 7.2 | The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ic… | — | wordfence |
| 6d0d4d06-95f7-4ecd-84a7-2d3996b16b1c | HIGH | 7.2 | The WP Mega Menu plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.2 via … | — | wordfence | |
| 6ce177e7-a009-4b5d-ba4c-971de5496dca | < 4.6.0 |
HIGH | 7.2 | The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin fo… | — | wordfence |
| 6cd9cbba-10b0-4fb0-ad49-4593a307a615 | < 9.2 |
HIGH | 7.2 | The WP Cerber Security plugin for WordPress is vulnerable to stored cross-site scripting via the log parameter when logg… | — | wordfence |
| 6cc83edb-44ce-4dc9-8cba-734775a94779 | < 3.3.1.0 |
HIGH | 7.2 | The fetch_product_ajax functionality in the Product Feed on WooCommerce WordPress plugin before 3.3.1.0 uses a `product_… | — | wordfence |
| 6cbaa1eb-5e16-4b39-b7fc-9ed8967274c8 | < 4.1.4 |
HIGH | 7.2 | The Personal Portfolio Resume Theme | Kerge theme for WordPress is vulnerable to Server-Side Request Forgery in all vers… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →