Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 4 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f5ad74c5-93ba-414c-98ad-0987547f172f | < 3.2.9 |
CRITICAL | 9.9 | The Simple Download Monitor plugin for WordPress is vulnerable to authorization bypass due to missing capability checks … | — | wordfence |
| f54cdad2-88db-4604-8064-fa6175176760 | < 2.3.4 |
CRITICAL | 9.9 | The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode … | — | wordfence |
| f3abba90-9503-484e-bc2b-c6105bec698b | < 1.1.5 |
CRITICAL | 9.9 | The CRM Perks Forms plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.4 due to i… | — | wordfence |
| f3805936-675e-474f-a3f7-acea69bd72f0 | < 2.1.12 |
CRITICAL | 9.9 | An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalatio… | — | wordfence |
| f31bf9cd-fbf3-4f7a-bddd-ddd44c899710 | < 2.12.0 |
CRITICAL | 9.9 | The WordPress Ad Widget plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1… | — | wordfence |
| ee6f936b-704a-486f-836b-9a1892271bfa | < 1.9.8 |
CRITICAL | 9.9 | The Woocommerce Addon by Greenshift plugin for WordPress is vulnerable to SQL Injection in versions up to 1.9.8 due to i… | — | wordfence |
| ee5acf1d-e405-4aa6-8355-b5aebbbb1d1d | < 3.4.3 |
CRITICAL | 9.9 | The WPtouch plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 3.4.2. This is… | — | wordfence |
| e89b40ec-1952-46e3-a91b-bd38e62f8929 | < 7.2.7 |
CRITICAL | 9.9 | The Image Optimizer, Resizer and CDN β Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missin… | — | wordfence |
| e7939401-822c-4d27-9d8c-c5680165e6a7 | < 4.6.0.4 |
CRITICAL | 9.9 | The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) t… | — | wordfence |
| e6e96578-d54b-4c45-91cd-f143311445ea | < 7.0.8 |
CRITICAL | 9.9 | The PayPlus Payment Gateway plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.0.7 … | — | wordfence |
| e604979e-81e0-4c9a-844c-381599bf226e | < 2.0.7 |
CRITICAL | 9.9 | The Zoho Campaigns plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.6 due t… | — | wordfence |
| d6ebb590-1291-45dc-818a-258143a2d9a2 | < 1.7.9 |
CRITICAL | 9.9 | The Slideshow Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.8 due to… | — | wordfence |
| d6eb094a-4f5a-418a-ba95-635765abfcff | CRITICAL | 9.9 | The WP Easy Gallery β WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_image… | — | wordfence | |
| d50d0e87-a4be-465b-8cc1-4b56201c9fc0 | CRITICAL | 9.9 | The AIKit plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.14.1 due to insufficie… | — | wordfence | |
| d4f29711-6aec-4481-a3bc-2303592bb79c | < 3.26.7 |
CRITICAL | 9.9 | The Wishlist Member plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and excluding, 3.… | — | wordfence |
| d33467d4-aabd-4030-ba10-68e2460b2ed2 | < 3.0.0 |
CRITICAL | 9.9 | PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress shortcodes, whi… | — | wordfence |
| d1a14fc2-cebe-4a0e-92b0-af2a9c805401 | CRITICAL | 9.9 | The WooCommerce Amazon Affiliates - Wordpress Plugin plugin for WordPress is vulnerable to SQL Injection in versions up … | — | wordfence | |
| ce3e5bc7-63e9-4c0e-ae66-c24c2b8be2da | < 1.2.6 |
CRITICAL | 9.9 | The Youzify plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.5 due to insuffici… | — | wordfence |
| c8eebc67-e590-4d7f-8925-e5e5090cedf0 | < 6.0.4 |
CRITICAL | 9.9 | The OSM β OpenStreetMap plugin for WordPress is vulnerable to SQL Injection via the 'tagged_filter' attribute of the '… | — | wordfence |
| c7a34c76-34f0-42db-af90-b477a45b84d7 | CRITICAL | 9.9 | The canvasio3D Light plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… | — | wordfence | |
| c75bfba9-b25a-4966-835c-8d22736de809 | < 1.9.51 |
CRITICAL | 9.9 | The UpdraftPlus WordPress Backup Plugin for WordPress is vulnerable to nonce leak which leads to authorization bypass in… | — | wordfence |
| c6f4ee5d-819d-4125-8cff-acf9811e2919 | < 4.0.14 |
CRITICAL | 9.9 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.… | — | wordfence |
| c6914c8c-50ae-482f-81cd-cbd28466f3a1 | < 1.7.3 |
CRITICAL | 9.9 | The Contact Form to DB by BestWebSoft β Messages Database Plugin For WordPress plugin for WordPress is vulnerable to S… | — | wordfence |
| c2054dcd-1a65-48bc-9dcf-824fa448921d | CRITICAL | 9.9 | The User Activity Log Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.3.4 du… | — | wordfence | |
| c1528125-9d26-40a2-9591-4220c18cef37 | < 3.11.2 |
CRITICAL | 9.9 | The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to SQL Injection via the save… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →