Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,758 vulnerabilities found (page 42 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a85fbaff-d566-4ed2-8943-c174e0c4d2d8 | < 4.2.1 |
CRITICAL | 9.8 | The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to pri… | — | wordfence |
| a856a96a-68d2-462d-b523-840668980807 | < 1.1 |
CRITICAL | 9.8 | The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,… | — | wordfence |
| a80f3c4c-1aa3-441a-9058-65ba4c7ccaef | < 4.21.0 |
CRITICAL | 9.8 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Privilege Escalat… | — | wordfence |
| a8082c60-436d-42e3-8aa5-cd2cb8ce6355 | CRITICAL | 9.8 | includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes. | — | wordfence | |
| a7b1871d-9d26-4bdc-bd20-0535143902d4 | < 2.3 |
CRITICAL | 9.8 | The LWS Affiliation plugin for WordPress is vulnerable to Remote/Local File Inclusion in versions up to, and including, … | — | wordfence |
| a79bc789-ee03-4b7b-9835-5e20a4a70714 | CRITICAL | 9.8 | The Simen theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6. This makes it… | — | wordfence | |
| a76077c6-700a-4d21-a930-b0d6455d959c | < 3.0.5 |
CRITICAL | 9.8 | The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'w… | — | wordfence |
| a71a9aa0-ffe3-418d-ad18-285773ee01c1 | CRITICAL | 9.8 | The Delete Comments By Status plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… | — | wordfence | |
| a71a1a7b-6299-44c5-b686-65f214986c27 | < 1.3.8 |
CRITICAL | 9.8 | The InfiniteWP Client plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.7… | — | wordfence |
| a6f362c1-fe64-4be1-9713-14c0561a59ce | < 3.3.2 |
CRITICAL | 9.8 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to arbitrary file uploads due… | — | wordfence |
| a6d59ed7-a25e-4b96-a8de-9364aafdf72a | CRITICAL | 9.8 | The Do That Task plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all… | — | wordfence | |
| a6d474cb-36ca-4a99-82de-2e154b3ae6ac | < 2.0.22 |
CRITICAL | 9.8 | The Grow by Tradedoubler – Advertiser Plugin for WooCommerce plugin for WordPress is vulnerable to Local File Inclusio… | — | wordfence |
| a6bf60cc-4a07-4d5d-bff3-20d0115a5bd3 | < 1.8.20 |
CRITICAL | 9.8 | The Gravityforms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via th… | — | wordfence |
| a6aeafd3-15be-49a3-be60-e33e909f32ca | CRITICAL | 9.8 | The The Pressengine plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.… | — | wordfence | |
| a69236d1-2164-4702-96e3-abd80fb5ffbb | < 1.2.0 |
CRITICAL | 9.8 | The Api2Cart Bridge Connector plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includi… | — | wordfence |
| a672c18b-1426-49fd-9590-eab8204afd5f | < 7.11.18 |
CRITICAL | 9.8 | In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize… | — | wordfence |
| a636e865-9556-4afb-8726-4537a160f379 | < 1.8.7 |
CRITICAL | 9.8 | The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin… | — | wordfence |
| a6213e09-8a97-44cf-85ef-83179d79206c | < 4.0.5 |
CRITICAL | 9.8 | The LeagueManager plugin for WordPress is vulnerable to SQL Injection via the ‘match_id’ and 'league_id' parameters … | — | wordfence |
| a61cce43-0df7-4ca9-8897-24c7d131b505 | < 1.0.3 |
CRITICAL | 9.8 | The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and … | — | wordfence |
| a61b2ecc-d4e1-4e71-9187-ddc3d3616a29 | < 3.6.2.1 |
CRITICAL | 9.8 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all ver… | — | wordfence |
| a6196b07-a2fc-45ac-8700-a1ce2713a960 | < 1.3.2 |
CRITICAL | 9.8 | WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attack… | — | wordfence |
| a60a9c14-d14e-469a-9cc5-681ca25db37c | CRITICAL | 9.8 | The Easy CSV Importer BETA plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… | — | wordfence | |
| a5f24902-1336-4fcd-b42d-e29526e61b71 | CRITICAL | 9.8 | The Answer My Question plugin for WordPress is vulnerable to generic SQL Injection via the 'id' parameter in the 'modal.… | — | wordfence | |
| a5e45e96-3cfb-42a9-b8b7-519489bc03ad | < 4.29.5 |
CRITICAL | 9.8 | Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for Wor… | — | wordfence |
| a5c290a1-b58a-4b5c-8112-076d5b17d940 | < 1.2.5 |
CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remot… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →