Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 40 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a7b1871d-9d26-4bdc-bd20-0535143902d4 | < 2.3 |
CRITICAL | 9.8 | The LWS Affiliation plugin for WordPress is vulnerable to Remote/Local File Inclusion in versions up to, and including, … | — | wordfence |
| a79bc789-ee03-4b7b-9835-5e20a4a70714 | CRITICAL | 9.8 | The Simen theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6. This makes it… | — | wordfence | |
| a76077c6-700a-4d21-a930-b0d6455d959c | < 3.0.5 |
CRITICAL | 9.8 | The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'w… | — | wordfence |
| a71a9aa0-ffe3-418d-ad18-285773ee01c1 | CRITICAL | 9.8 | The Delete Comments By Status plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… | — | wordfence | |
| a71a1a7b-6299-44c5-b686-65f214986c27 | < 1.3.8 |
CRITICAL | 9.8 | The InfiniteWP Client plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.7… | — | wordfence |
| a6f362c1-fe64-4be1-9713-14c0561a59ce | < 3.3.2 |
CRITICAL | 9.8 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to arbitrary file uploads due… | — | wordfence |
| a6d59ed7-a25e-4b96-a8de-9364aafdf72a | CRITICAL | 9.8 | The Do That Task plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all… | — | wordfence | |
| a6d474cb-36ca-4a99-82de-2e154b3ae6ac | < 2.0.22 |
CRITICAL | 9.8 | The Grow by Tradedoubler – Advertiser Plugin for WooCommerce plugin for WordPress is vulnerable to Local File Inclusio… | — | wordfence |
| a6bf60cc-4a07-4d5d-bff3-20d0115a5bd3 | < 1.8.20 |
CRITICAL | 9.8 | The Gravityforms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via th… | — | wordfence |
| a69236d1-2164-4702-96e3-abd80fb5ffbb | < 1.2.0 |
CRITICAL | 9.8 | The Api2Cart Bridge Connector plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includi… | — | wordfence |
| a672c18b-1426-49fd-9590-eab8204afd5f | < 7.11.18 |
CRITICAL | 9.8 | In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize… | — | wordfence |
| a636e865-9556-4afb-8726-4537a160f379 | < 1.8.7 |
CRITICAL | 9.8 | The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin… | — | wordfence |
| a6213e09-8a97-44cf-85ef-83179d79206c | < 4.0.5 |
CRITICAL | 9.8 | The LeagueManager plugin for WordPress is vulnerable to SQL Injection via the ‘match_id’ and 'league_id' parameters … | — | wordfence |
| a61cce43-0df7-4ca9-8897-24c7d131b505 | < 1.0.3 |
CRITICAL | 9.8 | The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and … | — | wordfence |
| a6196b07-a2fc-45ac-8700-a1ce2713a960 | < 1.3.2 |
CRITICAL | 9.8 | WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attack… | — | wordfence |
| a60a9c14-d14e-469a-9cc5-681ca25db37c | CRITICAL | 9.8 | The Easy CSV Importer BETA plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… | — | wordfence | |
| a5f24902-1336-4fcd-b42d-e29526e61b71 | CRITICAL | 9.8 | The Answer My Question plugin for WordPress is vulnerable to generic SQL Injection via the 'id' parameter in the 'modal.… | — | wordfence | |
| a5e45e96-3cfb-42a9-b8b7-519489bc03ad | < 4.29.5 |
CRITICAL | 9.8 | Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for Wor… | — | wordfence |
| a5c290a1-b58a-4b5c-8112-076d5b17d940 | < 1.2.5 |
CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remot… | — | wordfence |
| a5b7538f-891a-423f-97d1-b0212efcdb98 | < 4.2.153 |
CRITICAL | 9.8 | An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almos… | — | wordfence |
| a597d36c-72ce-44f0-af7b-2b9aad46957c | CRITICAL | 9.8 | The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does no… | — | wordfence | |
| a57b2afa-b943-419f-9819-d7b6835c4d10 | CRITICAL | 9.8 | The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to p… | — | wordfence | |
| a5763e3b-01b3-4541-8fef-80fcb7e7e88e | < 2.6.7 |
CRITICAL | 9.8 | The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authen… | — | wordfence |
| a5706025-962f-47e2-8d1d-16bafd937c92 | CRITICAL | 9.8 | The Amoveo Multipurpose Wordpress Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type v… | — | wordfence | |
| a56d5a2f-ae13-4523-bc4a-17bb2fb4c6f0 | < 3.1 |
CRITICAL | 9.8 | The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /i… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →