Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,758 vulnerabilities found (page 45 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| a1817c58-e807-4ef2-a382-28ca2fd5239e | < 1.2.3 |
CRITICAL | 9.8 | The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This … | — | wordfence |
| a1800241-802b-4c6a-a9d8-a7cf78450346 | < 1.4.3 |
CRITICAL | 9.8 | The WTI Like Post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTT… | — | wordfence |
| a146ea86-52a8-4488-b904-965409ec02ad | CRITICAL | 9.8 | The Type Hub plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all ver… | — | wordfence | |
| a13c364f-bf86-41a9-b56e-949af38c01c6 | < 1.1.0 |
CRITICAL | 9.8 | The Registration Form for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, … | — | wordfence |
| a135a298-0c8f-40d1-ad38-b55f81db0481 | < 1.5.4 |
CRITICAL | 9.8 | The Kata Plus plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.3 via des… | — | wordfence |
| a10ba041-ded4-41d4-93ba-7fa7389acd54 | < 2.1.8 |
CRITICAL | 9.8 | The WordPress OpenID Connect Client plugin for WordPress is vulnerable to authentication bypass in versions up to, and i… | — | wordfence |
| a10a3f01-082d-4a94-89c6-b5b46891aa4d | < 4.3.3 |
CRITICAL | 9.8 | The Gift Cards (Gift Vouchers and Packages) plugin for WordPress is vulnerable to SQL Injection via the 'template' param… | — | wordfence |
| a0da53ab-c750-4ff4-b3d1-49b6603182ae | CRITICAL | 9.8 | The Private Feed Key plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0… | — | wordfence | |
| a0cb0970-7e21-44ff-bbca-4b3e18f4466e | < 2.5.30 |
CRITICAL | 9.8 | Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows re… | — | wordfence |
| a0c67346-534a-4b67-a904-fa148703707a | < 6.17.4.1 |
CRITICAL | 9.8 | The "The Events Calendar" plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi… | — | wordfence |
| a0b37050-b320-4c59-8d93-db611aa55283 | < 1.16.45 |
CRITICAL | 9.8 | The Booking Activities plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, … | — | wordfence |
| a0998721-7b5e-4657-894c-52dfadde5d4a | < 1.1.33 |
CRITICAL | 9.8 | The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Privilege Escalati… | — | wordfence |
| a08fa649-3092-4c26-a009-2dd576b9b1ac | < 2.6.1 |
CRITICAL | 9.8 | The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activ… | — | wordfence |
| a0695f66-5932-4ca4-86d3-ef53f1a669b5 | CRITICAL | 9.8 | The Oberliga Theme for WordPress is vulnerable to generic SQL Injection via the ‘team’ parameter in all versions due… | — | wordfence | |
| a042b1be-d39f-4d28-8566-d9974becdd40 | CRITICAL | 9.8 | The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download func… | — | wordfence | |
| a0146f17-35bd-45cf-b9c6-c4fce688efc2 | < 1.1.2 |
CRITICAL | 9.8 | The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable… | — | wordfence |
| a003e922-d6c6-4f99-9b94-a3232d311677 | < 5.4.02 |
CRITICAL | 9.8 | The Hide My WP Ghost plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.4.01… | — | wordfence |
| a00222f4-6f41-4a88-a50a-1e25b11a2ffc | < 1.2.9 |
CRITICAL | 9.8 | The Nika theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.8. This makes i… | — | wordfence |
| 9fdb6e4d-a94d-448c-aaea-0f38eeafd033 | < 2.5.4 |
CRITICAL | 9.8 | The WooLentor plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5.3 via des… | — | wordfence |
| 9fb4c58d-321d-453f-92b9-ae409541911b | < 9.3.9 |
CRITICAL | 9.8 | The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.3.8. This m… | — | wordfence |
| 9fb09a77-aba1-422c-961b-dc2c7ce82320 | < 1.7.5.7 |
CRITICAL | 9.8 | The Cooked Pro plugin for WordPress is vulnerable to PHP Object Injection in versions up to, but not including, 1.7.5.7 … | — | wordfence |
| 9fa30fa2-6c42-4e5f-a0b5-8711ce5d8121 | < 2.150 |
CRITICAL | 9.8 | The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin … | — | wordfence |
| 9f9fd9e1-c4b8-420e-a4d3-30c934853a98 | < 12.6.7 |
CRITICAL | 9.8 | An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the A… | — | wordfence |
| 9f606fba-f779-42ea-a160-6c3b20dc5e79 | < 3.16.5 |
CRITICAL | 9.8 | The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up t… | — | wordfence |
| 9f5cdb47-205a-4c03-a8a9-f39d1b4fc769 | < 1.0.24 |
CRITICAL | 9.8 | The Agency Toolkit plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege es… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →