Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,758 vulnerabilities found (page 39 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| b10a4561-1724-4e98-bff2-ca5416b217dc | CRITICAL | 9.8 | The Finalist plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all known versions due to… | — | wordfence | |
| b108ba89-56c4-44a8-af61-ccd6f7f73562 | CRITICAL | 9.8 | The AA-Team Premium SEO Pack plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includin… | — | wordfence | |
| b0e19fc5-5e79-4383-827d-edd16443e596 | < 6.3.1 |
CRITICAL | 9.8 | The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Remote Code Execution in … | — | wordfence |
| b08198a6-10e8-44ca-a1c5-8d987d85c469 | < 2.6.04 |
CRITICAL | 9.8 | The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including… | — | wordfence |
| b0603621-4521-4eb0-b4dd-e2257c133cee | < 2.6.6 |
CRITICAL | 9.8 | The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'co… | — | wordfence |
| b04a5a8e-17ec-48e7-85b8-a14bd2222583 | CRITICAL | 9.8 | The Plugin Propagator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… | — | wordfence | |
| b03b7ea8-6485-495d-b815-2b7b882a75a2 | < 1.6.7 |
CRITICAL | 9.8 | The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all ve… | — | wordfence |
| b0399b60-6e40-4f35-985f-845a32f69d64 | CRITICAL | 9.8 | The TerraClassifieds – Simple Classifieds Plugin plugin for WordPress is vulnerable to arbitrary file uploads in all v… | — | wordfence | |
| b0315b53-46a1-46b4-a53e-0d914866ca50 | CRITICAL | 9.8 | The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowe… | — | wordfence | |
| b0302a75-217f-4be9-876e-10ede3e3c20d | CRITICAL | 9.8 | The Adblocker Blocker plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… | — | wordfence | |
| b027c9f9-3144-4783-b646-ee1e02cd27ef | < 1.8.8 |
CRITICAL | 9.8 | The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7… | — | wordfence |
| aff754d6-8624-4068-8e31-738f6041d3a6 | < 1.2.42 |
CRITICAL | 9.8 | An issue was discovered in Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-… | — | wordfence |
| aff4f695-3c3b-48ee-8de1-674b588f332f | < 5.1.5.5 |
CRITICAL | 9.8 | The Evarisk plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upl… | — | wordfence |
| afe894b0-5e91-4aa2-bbd1-1f74274701cf | CRITICAL | 9.8 | The Sign In With Google plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including… | — | wordfence | |
| afe10c10-cace-4ce4-a813-6fda04c8d3dd | < 1.2.4 |
CRITICAL | 9.8 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass i… | — | wordfence |
| afd48bc8-d490-4a3e-97fc-70cf008cbf66 | < 3.8.1 |
CRITICAL | 9.8 | The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of … | — | wordfence |
| af90aef0-fd96-43ff-8400-09bd5cebed28 | < 2.67.2 |
CRITICAL | 9.8 | The WP-EMail Plugin for WordPress is vulnerable to SQL Injection via the ‘last_emailed’ parameter in versions before… | — | wordfence |
| af7345f9-6f62-424b-b02d-c145a90508ae | < 2.2.0 |
CRITICAL | 9.8 | The WordPress Zero Spam plugin for WordPress is vulnerable to Blind SQL Injection in versions up to, and including, 2.1.… | — | wordfence |
| af7163da-79b3-45df-a33c-01367205bb6f | < 1.1.0 |
CRITICAL | 9.8 | Vulnerability in Easy2map-photos WordPress Plugin v1.0.9 allows SQL Injection via unsanitized mapTemplateName, mapName, … | — | wordfence |
| af5eb3cd-f527-4b4e-a02e-699155f27b0d | < 1.1.4 |
CRITICAL | 9.8 | The Opal Woo Custom Product Variation plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient … | — | wordfence |
| af5a58d1-946a-451b-bc8b-a397345ae89a | < 4.4.4 |
CRITICAL | 9.8 | The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to PHP Object Injection in versions before 4.4.4 vi… | — | wordfence |
| af37f301-d97f-47d3-b6a8-88cb41344541 | < 5.4.4 |
CRITICAL | 9.8 | Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication b… | — | wordfence |
| af008739-3b75-4e79-ac4a-3829986b7bf0 | CRITICAL | 9.8 | The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Privileg… | — | wordfence | |
| aefbebce-9433-455d-b27c-93088b0c8494 | < 1.24 |
CRITICAL | 9.8 | The LeadSnap plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.23 via deser… | — | wordfence |
| ae50aa5d-95e3-4650-9dbf-118b4ba3abda | < 9.644 |
CRITICAL | 9.8 | The WP Cost Estimation plugin for WordPress is vulnerable to arbitrary file uploads and deletion due to missing file typ… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →