Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 48 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 916ada05-894e-4e61-ba0a-25b9a48461a1 | < 1.2.0 |
CRITICAL | 9.8 | The LetsRecover plugin for WordPress is vulnerable to SQL Injection via an AJAX action in versions up to, and including,… | — | wordfence |
| 913ffe0c-c8f8-4cda-be9a-96c056d4c4a8 | < 1.1 |
CRITICAL | 9.8 | The UrbanGo Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.… | — | wordfence |
| 91286dc8-8015-4adc-9a21-d6187997cef4 | < 3.6.1 |
CRITICAL | 9.8 | The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it … | — | wordfence |
| 911f3449-f906-493a-942b-eca26fdc10aa | CRITICAL | 9.8 | The Avaz theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.8. This makes it … | — | wordfence | |
| 911a9550-1f62-4f28-9d8c-00d9769949c9 | < 1.2 |
CRITICAL | 9.8 | The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including… | — | wordfence |
| 9095bf69-e682-48aa-b206-8bd2b6c2b170 | < 0.43.6 |
CRITICAL | 9.8 | The Sermon Browser plugin for WordPress is vulnerable to SQL Injection via the ‘sermon_id’ parameter in versions bef… | — | wordfence |
| 908dbe64-e214-4880-a85d-38df4c722a43 | CRITICAL | 9.8 | The Dagda Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload… | — | wordfence | |
| 90689ba2-4f82-4116-85d7-1266189aa34e | < 8.0.33 |
CRITICAL | 9.8 | The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api… | — | wordfence |
| 8ff54e1c-7d6c-4360-a9b3-4e8928fff6de | CRITICAL | 9.8 | The Coming Soon, Maintenance Mode plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and incl… | — | wordfence | |
| 8fd2ed33-6977-4480-bdcb-d7afae7bfd06 | CRITICAL | 9.8 | SQL injection vulnerability in the WP Rss Poster (wp-rss-poster) plugin 1.0.0 for WordPress allows remote attackers to e… | — | wordfence | |
| 8fcf7283-eb6c-4fee-b606-79026e2227fc | < 3.1.1 |
CRITICAL | 9.8 | The Profile Builder and Profile Builder Pro plugin versions up to and including 3.1.0 allows unauthenticated attackers t… | — | wordfence |
| 8fc02501-2bb6-4817-8e01-273d3d91ac57 | < 1.0.7 |
CRITICAL | 9.8 | SQL injection vulnerability in ajax.php in SCORM Cloud For WordPress plugin before 1.0.7 for WordPress allows remote att… | — | wordfence |
| 8fbc88da-8944-433c-b94d-9604ffe13d8a | < 0.4.2.2 |
CRITICAL | 9.8 | The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the up… | — | wordfence |
| 8fa4b5df-dc71-49de-880b-895eb1d9cdca | < 16.26.9 |
CRITICAL | 9.8 | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/acco… | — | wordfence |
| 8f8b1d8f-b2b6-415c-91f2-e5b98048258d | < 1.5.1 |
CRITICAL | 9.8 | The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.5.0.… | — | wordfence |
| 8f5fa529-4c6e-465e-a281-78ba74e5a718 | CRITICAL | 9.8 | The Accordion plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/… | — | wordfence | |
| 8f3ed0f0-897d-47f4-acdc-b483838af4bc | < 2.3.5 |
CRITICAL | 9.8 | The SlideDeck 2 plugin for WordPress is vulnerable to Local/Remote File Inclusion in versions up to, and including, 2.3.… | — | wordfence |
| 8f3c9b96-70e8-452e-9065-28dff744a69d | < 4.8.0 |
CRITICAL | 9.8 | The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.7.… | — | wordfence |
| 8f20734d-4105-401b-992a-b47d049f70f4 | < 2.0 |
CRITICAL | 9.8 | The AJAX Multi Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… | — | wordfence |
| 8e7693a3-642a-4eff-902c-d29a3c12deb0 | < 3.3.2 |
CRITICAL | 9.8 | The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authen… | — | wordfence |
| 8e64d865-5acc-419b-8c61-e8fd8207fa94 | < 3.1.4 |
CRITICAL | 9.8 | The Adifier System plugin for WordPress is vulnerable to SQL Injection in versions up to 3.1.4 due to insufficient escap… | — | wordfence |
| 8e40a954-53c4-453b-85f0-d3febaa6ae84 | < 4.3.6 |
CRITICAL | 9.8 | The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have auth… | — | wordfence |
| 8e3e07c8-8fd0-4966-8276-aece794b75b2 | < 3.1.1.4.2 |
CRITICAL | 9.8 | The Easy Digital Downloads plugin for WordPress is vulnerable to Unauthenticated Arbitrary Password Resets to Privilege … | — | wordfence |
| 8e3c45ac-44c0-47e1-81af-65014f064513 | CRITICAL | 9.8 | Several themes from Chimpstudio and Pixfill are vulnerable to arbitrary file uploads due to missing file type validation… | — | wordfence | |
| 8e2c6030-d117-4c0b-a97a-d0bb89e948ef | CRITICAL | 9.8 | The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'upload… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →