Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,891 vulnerabilities found (page 454 of 1596)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 8a711984-4eb2-4d96-b2b9-0ecd840679b1 | < 1.5.4 |
MEDIUM | 6.5 | The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_sav… | — | wordfence |
| 89de168e-1bce-4e11-a765-afc1d7dce8fe | < 4.0.3 |
MEDIUM | 6.5 | The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing… | — | wordfence |
| 89a02485-a2a5-467d-ad19-6b267059389d | < 2.69.0 |
MEDIUM | 6.5 | The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMO… | — | wordfence |
| 898ba68f-2b0c-462a-87ee-272ee624396e | < 5.6.2 |
MEDIUM | 6.5 | The Jock on air now plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5… | — | wordfence |
| 8972b507-4aae-40cc-a79e-2603dbdc70c0 | < 3.6.0.2 |
MEDIUM | 6.5 | The Tickera β Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_ord… | — | wordfence |
| 88a9abf4-62a9-4695-87e7-18ff0b0075e9 | < 10.3.2 |
MEDIUM | 6.5 | The Quiz and Survey Master (QSM) β Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized acces… | — | wordfence |
| 88241855-075b-4608-aa04-ceb96d062033 | MEDIUM | 6.5 | The RSVP ME plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9.9 due to insuffici… | — | wordfence | |
| 8808e4bd-76ea-4e31-8a2c-92c5b7dd3c68 | < 2.7.8 |
MEDIUM | 6.5 | The Schema Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.7.… | — | wordfence |
| 87adbc9d-cb7b-4e3b-be43-73663d549d20 | < 1.5 |
MEDIUM | 6.5 | The GymBase Theme Classes plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4 due … | — | wordfence |
| 8794854d-e931-4a85-b767-2ab81bfcb780 | MEDIUM | 6.5 | The CataBlog plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.7.0. … | — | wordfence | |
| 873e8f12-19a8-43b4-8da0-8b740853b658 | MEDIUM | 6.5 | The Lodgix.com Vacation Rental Website Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, an… | — | wordfence | |
| 87099513-d8e2-45e5-b7e6-b46558a10d3b | < 1.0.20 |
MEDIUM | 6.5 | The Cloud SAML SSO plugin for WordPress is vulnerable to Identity Provider Deletion due to a missing capability check on… | — | wordfence |
| 86f15e94-6ca7-4eb2-8a38-b4add9251dab | < 2.0.9.3 |
MEDIUM | 6.5 | The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a… | — | wordfence |
| 86e990ae-6bfe-4f2b-8c37-b0675430a638 | < 3.1.26 |
MEDIUM | 6.5 | The FULL β Cliente plugin for WordPress is vulnerable to SQL Injection via the 'formId' parameter in all versions 3.1.… | — | wordfence |
| 867c9de4-b547-4bf2-8ff1-897c49077f76 | MEDIUM | 6.5 | The Find Me On plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.9.1 due to … | — | wordfence | |
| 86632212-37b5-4280-8a2a-163957ad9787 | < 3.6.5 |
MEDIUM | 6.5 | The KiviCare β Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 's… | — | wordfence |
| 864a3444-0479-4b9f-beca-584a4a9b8682 | < 3.2.0 |
MEDIUM | 6.5 | The User Registration β Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress i… | — | wordfence |
| 86346be9-7ca6-49b7-83b2-01a335d48c94 | < 3.15.3 |
MEDIUM | 6.5 | The Avada Builder plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.15.2… | — | wordfence |
| 8584e86d-bafe-4032-9483-c92ecb28ab9c | MEDIUM | 6.5 | The The Contact Form 7 β Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in… | — | wordfence | |
| 85674d8a-96b3-4fae-8bff-900ca78073a4 | < 6.4 |
MEDIUM | 6.5 | The Page and Post Clone plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' parameter in the content_… | — | wordfence |
| 84c61d00-20c1-4176-a74d-ea6ff6220f26 | < 18.3 |
MEDIUM | 6.5 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up t… | — | wordfence |
| 843b569d-d70e-46ae-b8f1-65579f0af333 | < 1.2.4 |
MEDIUM | 6.5 | The Tablesome Table β Contact Form DB β WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable… | — | wordfence |
| 840fefde-8c9d-413f-a6a6-1e796fb9e910 | MEDIUM | 6.5 | The Testimonial plugin for WordPress is vulnerable to SQL Injection via the 'iNICtestimonial' shortcode in all versions … | — | wordfence | |
| 840f54c4-898d-40f3-ad0b-fb1a359165e5 | < 2.1.7 |
MEDIUM | 6.5 | The uListing plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.6 due to insuffic… | — | wordfence |
| 83f8adea-4735-4c72-b274-58e813cab6ab | < 4.6 |
MEDIUM | 6.5 | Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPre… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →