Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 46 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 979c1107-788a-4130-b1d1-5cad3717962b | < 1.2.7 |
CRITICAL | 9.8 | The OnionBuzz Plugin for WordPress is vulnerable to blind SQL Injection via the id parameter in versions up to, and incl… | — | wordfence |
| 979072fc-3bf9-4969-8e84-4648ec0928bd | < 1.5.0 |
CRITICAL | 9.8 | Multiple themes by bslthemes for WordPress are vulnerable to Local File Inclusion in various versions. This makes it pos… | — | wordfence |
| 978d1747-fbcf-4c08-9563-49041f225120 | CRITICAL | 9.8 | The MoneyMasters theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the… | — | wordfence | |
| 9781f10d-040d-4f2e-aac4-3aa395f364ec | CRITICAL | 9.8 | The Image Classify plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in a… | — | wordfence | |
| 9766a657-1cf2-448a-bd66-a27c0ebd8261 | < 0.1.1 |
CRITICAL | 9.8 | The Payment Gateways Caller for WP e-Commerce plugin for WordPress is vulnerable to Local File Inclusion in versions bef… | — | wordfence |
| 9758a59c-4370-4b26-b32a-004565f28d76 | < 3.2.0 |
CRITICAL | 9.8 | An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper in… | — | wordfence |
| 9754bdc9-5638-4227-87ee-3bda34d10e01 | < 1.2 |
CRITICAL | 9.8 | The Easy Stripe – Tips, Payments, and Donations plugin for WordPress is vulnerable to Remote Code Execution in all ver… | — | wordfence |
| 96fc3ead-7ae4-4d2c-a0b5-13f3e3bf429b | < 2.3 |
CRITICAL | 9.8 | SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attack… | — | wordfence |
| 96f9c5b3-43b7-46e0-aa0c-a5179a99096b | < 3.6.8 |
CRITICAL | 9.8 | SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, … | — | wordfence |
| 969d35b5-2f2e-4255-b336-947414f269a5 | < 2.38.5 |
CRITICAL | 9.8 | The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence |
| 9692deb2-2526-4983-8a13-93a382e230c8 | < 5.1.9 |
CRITICAL | 9.8 | The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in al… | — | wordfence |
| 965dce53-2865-4179-9505-a64e4db1d1fd | < 1.0.83 |
CRITICAL | 9.8 | The OttoKit: All-in-One Automation Platform (Formerly SureTriggers) plugin for WordPress is vulnerable to Privilege Esca… | — | wordfence |
| 963f2485-3afa-4e17-8278-b75415af3915 | < 0.1.0.45 |
CRITICAL | 9.8 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in al… | — | wordfence |
| 95ff5150-ff45-48f8-bd39-0df79838942e | < 3.3.4 |
CRITICAL | 9.8 | The BetterDocs plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.3.3 vi… | — | wordfence |
| 95a68ae0-36da-499b-a09d-4c91db8aa338 | < 3.0.9 |
CRITICAL | 9.8 | The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via th… | — | wordfence |
| 9555c48f-5ce3-4c0c-88f3-83776b42b808 | < 13.1.6 |
CRITICAL | 9.8 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t… | — | wordfence |
| 9546ab46-737c-4bd3-9542-8ab1b776b3ea | < 2.14 |
CRITICAL | 9.8 | The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in al… | — | wordfence |
| 952e299a-5cec-444b-8359-3e7d8dec3ccb | < 6.03.01 |
CRITICAL | 9.8 | The Event Registration plugin for WordPress is vulnerable to generic SQL Injection via the ‘submitted_token’ and ‘… | — | wordfence |
| 9505b778-294f-45bc-a36c-22fbb894a294 | < 3.1.0 |
CRITICAL | 9.8 | The LottieFiles plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… | — | wordfence |
| 94fdc98a-c8be-47b4-a0a2-02d7373ab85e | CRITICAL | 9.8 | The Talkback plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0 via deseri… | — | wordfence | |
| 94d67030-30ea-4583-a716-79805a5619e8 | CRITICAL | 9.8 | The Product Website Showcase plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and inc… | — | wordfence | |
| 948d40f5-2c87-4439-b4ef-3e02c397bf0f | < 1.1.6 |
CRITICAL | 9.8 | The CP Appointment Calendar Plugin plugin for WordPress is vulnerable to SQL Injection via the $itemnumber variable in a… | — | wordfence |
| 94736152-b365-4b3a-a786-ed49f7d0fc7a | < 3.3.2 |
CRITICAL | 9.8 | The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3… | — | wordfence |
| 946d5a2c-f20f-483a-8150-0266a631a112 | < 2.2 |
CRITICAL | 9.8 | The Homepage SlideShow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence |
| 94696151-9f99-4847-bd67-8fb77f8b6a0e | CRITICAL | 9.8 | The BCorp Shortcodes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →