Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,758 vulnerabilities found (page 43 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a5b7538f-891a-423f-97d1-b0212efcdb98 | < 4.2.153 |
CRITICAL | 9.8 | An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almos… | — | wordfence |
| a597d36c-72ce-44f0-af7b-2b9aad46957c | CRITICAL | 9.8 | The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does no… | — | wordfence | |
| a57b2afa-b943-419f-9819-d7b6835c4d10 | CRITICAL | 9.8 | The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to p… | — | wordfence | |
| a5763e3b-01b3-4541-8fef-80fcb7e7e88e | < 2.6.7 |
CRITICAL | 9.8 | The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authen… | — | wordfence |
| a5706025-962f-47e2-8d1d-16bafd937c92 | CRITICAL | 9.8 | The Amoveo Multipurpose Wordpress Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type v… | — | wordfence | |
| a56d5a2f-ae13-4523-bc4a-17bb2fb4c6f0 | < 3.1 |
CRITICAL | 9.8 | The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /i… | — | wordfence |
| a56b59ce-29c2-4172-b703-a06d7bb28da0 | < 7.8.0 |
CRITICAL | 9.8 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to auth… | — | wordfence |
| a537f82c-5139-439e-817f-7fd0ece958bd | CRITICAL | 9.8 | The Chocolate WP β Responsive Photography Theme for WordPress is vulnerable to arbitrary file uploads due to inclusion… | — | wordfence | |
| a5341bbd-55bd-41ad-b5d1-d6b56c141277 | < 8.6.1 |
CRITICAL | 9.8 | The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and includi… | — | wordfence |
| a52e6242-33b4-4981-932f-d825b4fc9941 | CRITICAL | 9.8 | The Prime Listing Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all version… | — | wordfence | |
| a521b6a4-1a4f-4433-9163-8de71e1976dd | < 2.6.63 |
CRITICAL | 9.8 | The Datalogics Ecommerce Delivery β Datalogics plugin for WordPress is vulnerable to Privilege Escalation in all versi… | — | wordfence |
| a50b3304-d55b-487a-8137-d5083c704cf4 | < 3.5.2 |
CRITICAL | 9.8 | The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and includi… | — | wordfence |
| a5082982-e605-4ab3-a5b8-785c1850da98 | < 1.1.1 |
CRITICAL | 9.8 | The WPGuppy plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1.0 via deser… | — | wordfence |
| a4f8df3a-f247-4365-a9f6-6124065b4883 | < 1.3.1 |
CRITICAL | 9.8 | The Penci Soledad Data Migrator plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in… | — | wordfence |
| a4e1315b-31e5-428c-9a48-6185b4eeb2fc | < 1.7.3 |
CRITICAL | 9.8 | The Bitcoin / AltCoin Payment Gateway for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up… | — | wordfence |
| a4d4532c-f29f-44e2-9aab-beab915efd3c | CRITICAL | 9.8 | The FAT Cooming Soon plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1. T… | — | wordfence | |
| a4cbc0e7-4328-451f-a595-1ce17e9d0031 | < 1.2.15 |
CRITICAL | 9.8 | The Spirit Framework plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1… | — | wordfence |
| a4b71893-b0fd-476e-aa93-5f0b239e8301 | < 1.2 |
CRITICAL | 9.8 | The ColdFusion Responsive Fullscreen Video Image Audio Theme for WordPress is vulnerable to arbitrary file uploads due t… | — | wordfence |
| a4a26f60-5912-4d4a-8ef8-e4357c1fb1ff | < 3.9.4 |
CRITICAL | 9.8 | The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3… | — | wordfence |
| a4562535-ef69-4337-b03e-0b7c869cb042 | < 3.1.11 |
CRITICAL | 9.8 | The Kadence Blocks for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the proc… | — | wordfence |
| a4294f5f-d989-4b97-88ee-4e94f4f7845a | < 3.0.8 |
CRITICAL | 9.8 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versi… | — | wordfence |
| a3fc4bac-9be0-4a1c-b4bb-4384d80e22f7 | < 1.9.99 |
CRITICAL | 9.8 | The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file up… | — | wordfence |
| a3f173b6-f039-4865-8882-8ef7d1f88413 | < 2.0 |
CRITICAL | 9.8 | The Cryptocurrency Widgets Pack plugin for WordPress is vulnerable to SQL Injection via one of its AJAX actions in versi… | — | wordfence |
| a3ee01da-218a-421d-8f9c-1dc6c056ef74 | < 2.2.2.1 |
CRITICAL | 9.8 | The Madara β Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inc… | — | wordfence |
| a3deedc4-b939-4c54-8376-95d3728872d4 | < 2.2.83 |
CRITICAL | 9.8 | The FluentSMTP β WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →