Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 39 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ab4c7656-544c-4f2f-a42f-264ac90e3b61 | < 1.1.5 |
CRITICAL | 9.8 | The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.… | — | wordfence |
| ab46b494-e7c5-42fd-9906-2a7a529e2794 | < 2022.03.01 |
CRITICAL | 9.8 | The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using i… | — | wordfence |
| ab340c65-35eb-4a85-8150-3119b46c7f35 | < 6.5.8.4 |
CRITICAL | 9.8 | The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all v… | — | wordfence |
| ab19f79b-0cf6-4a5d-9e7e-a248728b4566 | < 1.3.1 |
CRITICAL | 9.8 | The Consulting Elementor Widgets plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i… | — | wordfence |
| aab3016d-5834-4b4a-a206-0b626884b335 | CRITICAL | 9.8 | The All in One B2B for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and inc… | — | wordfence | |
| aab0bb92-5474-429d-b6ff-2a7662183a27 | < 9.7 |
CRITICAL | 9.8 | The Stockholm theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.6. This … | — | wordfence |
| aaacd8be-448f-4020-943c-9ba442ba9730 | CRITICAL | 9.8 | The Datasets Manager by Arttia Creative plugin for WordPress is vulnerable to arbitrary file uploads due to missing file… | — | wordfence | |
| aa385a1f-1623-4f0a-bb2f-d4564b8f91bf | CRITICAL | 9.8 | The Sala - Startup & SaaS WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover… | — | wordfence | |
| aa262ff5-2b6c-421b-b155-a75d01005534 | < 2.4.1 |
CRITICAL | 9.8 | The Ultimate Store Kit – Elementor powered WooCommerce Builder, 80+ Widgets and Template Builder plugin for WordPress … | — | wordfence |
| aa14909c-58f6-40f1-af50-eb1a0d2333de | < 3.1.37.14 |
CRITICAL | 9.8 | The Event Espresso Free/Lite plugin for WordPress is vulnerable to Time-Based Blind SQL Injection via the ‘recurrence_… | — | wordfence |
| aa080b36-01ce-496a-9938-9715f0131e29 | < 3.0.7 |
CRITICAL | 9.8 | The Canto plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.0.6 via th… | — | wordfence |
| a9ddbb9c-c2c9-4e34-ac22-2afe8050e15b | < 2.1 |
CRITICAL | 9.8 | SQL injection vulnerability in the WP-RecentComments plugin 2.0.7 for WordPress allows remote attackers to execute arbit… | — | wordfence |
| a9d95af5-96da-4259-98c6-e2c4c574a896 | < 1.3.79 |
CRITICAL | 9.8 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to arbitrary file uploads in all versions up… | — | wordfence |
| a9c7d539-2ea7-4f72-b0d2-6082e26918ce | < 1.3.59 |
CRITICAL | 9.8 | The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin plugin for WordPress is v… | — | wordfence |
| a9b7a73c-6fba-4b5d-9f82-c3710cc8555d | < 4.1.1 |
CRITICAL | 9.8 | The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter be… | — | wordfence |
| a96c9047-9dea-4bc7-8982-8983930f7cfa | CRITICAL | 9.8 | The Augmented reality plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient direct access res… | — | wordfence | |
| a9077714-bddd-4b94-b01d-054f55f18da1 | CRITICAL | 9.8 | The Giveaway Boost plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.… | — | wordfence | |
| a8e6f2fe-25f7-46e4-871e-e6770d5fb00b | CRITICAL | 9.8 | The ZIJ KART plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1. This make… | — | wordfence | |
| a8c6c17a-9eaa-445b-b7ec-c36e15fc5b1b | CRITICAL | 9.8 | The WP Food ordering and Restaurant Menu plugin for WordPress is vulnerable to Local File Inclusion in versions up to, a… | — | wordfence | |
| a8c08878-0f9f-4203-8110-a3772eb8de63 | < 1.2.1 |
CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in includes/update.php in the Support Ticket System plugin before 1.2.1 for WordP… | — | wordfence |
| a8b319be-f312-4d02-840f-e2a91c16b67a | < 3.92.1 |
CRITICAL | 9.8 | The Automatic plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.92.0 due to insuf… | — | wordfence |
| a882c3d9-b4c1-4743-b930-382ca1081bab | < 1.0.8 |
CRITICAL | 9.8 | The WowShipping Pro plugin for WordPress was injected with a backdoor in version 1.0.6. This is due to a supply chain co… | — | wordfence |
| a85fbaff-d566-4ed2-8943-c174e0c4d2d8 | < 4.2.1 |
CRITICAL | 9.8 | The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to pri… | — | wordfence |
| a856a96a-68d2-462d-b523-840668980807 | < 1.1 |
CRITICAL | 9.8 | The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,… | — | wordfence |
| a8082c60-436d-42e3-8aa5-cd2cb8ce6355 | CRITICAL | 9.8 | includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes. | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →