Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 47 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 944cd237-d5cb-44da-8d4a-5cf7edd368a4 | < 1.2 |
CRITICAL | 9.8 | SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 fo… | — | wordfence |
| 942fd805-0f4f-44e5-98df-0b44ed8c7543 | < 3.1 |
CRITICAL | 9.8 | The CouponXxL Custom Post Types plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and in… | — | wordfence |
| 941233d8-f382-40a0-81b2-18a682ae07ca | < 3.9.5 |
CRITICAL | 9.8 | The Ad manager & AdSense Ads for WordPress is vulnerable to blind SQL Injection via the ‘track’ parameter in version… | — | wordfence |
| 93b5552e-bb24-4dfb-a779-8451f619ff50 | < 3.9.9.2 |
CRITICAL | 9.8 | The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functional… | — | wordfence |
| 936564ab-3119-4627-b7eb-4ca45ea377e5 | < 1.0.6 |
CRITICAL | 9.8 | The AI Magic – SEO Content Generator & Article Writer plugin for WordPress is vulnerable to Privilege Escalation in al… | — | wordfence |
| 935caa43-4c75-47ad-a631-63988e21f834 | < 2.2.1 |
CRITICAL | 9.8 | The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,… | — | wordfence |
| 934c3ce9-cf2d-4bf6-9a34-f448cb2e5a1d | < 2.1.6 |
CRITICAL | 9.8 | The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This… | — | wordfence |
| 933dd704-5a31-42a9-9b87-bf14a9d4ffa9 | < 1.1.7 |
CRITICAL | 9.8 | The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in a… | — | wordfence |
| 9319dfc7-2b23-4056-8310-41a07535379d | CRITICAL | 9.8 | The ajax-extend plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0 vi… | — | wordfence | |
| 9312c73d-8eb6-4ca0-a03b-566099dc6487 | < 1.4.3 |
CRITICAL | 9.8 | The WP GDPR Compliance plugin for WordPress is vulnerability to arbitrary options updates and action calling in version… | — | wordfence |
| 92f3b923-884e-4f61-9bf8-62dfb267a27e | < 1.5.2 |
CRITICAL | 9.8 | The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘event_venue’ parameter in all vers… | — | wordfence |
| 92d5be7a-ce96-4e26-afd1-a84b6f46b03f | < 1.2.1 |
CRITICAL | 9.8 | The TAX SERVICE Electronic HDM plugin for WordPress is vulnerable to SQL Injection via the 'importTaxService' AJAX endpo… | — | wordfence |
| 92c79e51-3b14-4d1c-893b-a683b55f3011 | < 4.2 |
CRITICAL | 9.8 | The Support Plus Responsive Ticket System plugin before 4.2 for WordPress has SQL injection. | — | wordfence |
| 92a120ac-66ae-4678-a87a-e62da885d50b | < 3.9.6 |
CRITICAL | 9.8 | The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.9.… | — | wordfence |
| 92a00fb4-7b50-43fd-ac04-5d6e29336e9c | < 0.1.0.39 |
CRITICAL | 9.8 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates du… | — | wordfence |
| 92915943-c6ff-46df-adbd-382eabe44021 | < 4.9.3 |
CRITICAL | 9.8 | The Manage WP Worker plugin for WordPress is vulnerable to authentication bypass in versions up to, and including 4.9.2,… | — | wordfence |
| 928877a6-eeeb-4ed5-900b-9b1560e1bf87 | < 2.5.01 |
CRITICAL | 9.8 | The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2… | — | wordfence |
| 92544c04-c499-420e-98f4-58834e579725 | CRITICAL | 9.8 | The Custom css-js-php plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, … | — | wordfence | |
| 923c513b-596f-44db-a98f-a33e8baec12e | < 1.6 |
CRITICAL | 9.8 | The Multiple Shipping And Billing Address For Woocommerce plugin for WordPress is vulnerable to PHP Object Injection in … | — | wordfence |
| 92321a3e-947b-4013-9b36-8bd6ea361f20 | < 1.1.4 |
CRITICAL | 9.8 | The BBS e-Franchise for WordPress is vulnerable to generic SQL Injection via the ‘uid’ parameter in versions up to, … | — | wordfence |
| 92298f2d-aced-4177-b6e8-36e153e9c930 | < 3.5.3 |
CRITICAL | 9.8 | The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on c… | — | wordfence |
| 91de6cf4-e5df-4130-bb96-92b89717a678 | < 1.3.2 |
CRITICAL | 9.8 | The WP Frontend Profile plugin for WordPress is vulnerable to privilege in all versions up to, and including, 1.3.1. Thi… | — | wordfence |
| 91aa86d9-8e42-4deb-b6ca-c3b388fefcb1 | CRITICAL | 9.8 | The CE21 Suite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including… | — | wordfence | |
| 91a1604c-c729-4c68-90a8-91862a351ecc | CRITICAL | 9.8 | The WP User plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.0 due to insufficien… | — | wordfence | |
| 91754c4d-a0d0-4d35-a70a-446d2bdf6c73 | CRITICAL | 9.8 | The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →