Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 49 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 8dfa65cb-3d16-471a-8464-b71510d65fd5 | CRITICAL | 9.8 | The Toolbox theme for WordPress is vulnerable to generic SQL Injection via the βmlsβ parameter in versions up to, an… | — | wordfence | |
| 8df66139-68bc-4bb4-80b5-aca604800ece | < 1.4.1 |
CRITICAL | 9.8 | The Social Login, Passkeys, Magic Link & Email OTP β Passwordless Login by VentraConnect plugin for WordPress is vulne… | — | wordfence |
| 8de25651-4119-4806-91e4-4ea213086bfb | < 4.8.5 |
CRITICAL | 9.8 | The Hotel Booking Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili… | — | wordfence |
| 8ddf6964-e0e7-4093-8aea-ac33f4214122 | < 2.6 |
CRITICAL | 9.8 | The Blaze Slideshow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence |
| 8dd34937-7641-4b9c-ba59-c4a1ec95f4cd | < 3.8.0 |
CRITICAL | 9.8 | The Sweet Date theme for WordPress is vulnerable to privilege escalation due to a missing capability check on a function… | — | wordfence |
| 8d3aea10-d7a0-44bd-94dc-3bad0d27dbd8 | CRITICAL | 9.8 | The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inc… | — | wordfence | |
| 8d19e18d-6f2e-48e7-b8da-1d399dc4d65c | < 3.1.3 |
CRITICAL | 9.8 | Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to injec… | — | wordfence |
| 8d132e9c-2dfb-49f6-bd35-9616f7932023 | < 51.1.37 |
CRITICAL | 9.8 | The King Addons for Elementor β 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin… | — | wordfence |
| 8cf1276b-401d-4166-940e-e5d60f85e762 | < 1.7.3 |
CRITICAL | 9.8 | The Masteriyo LMS β eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to privilege … | — | wordfence |
| 8cd1d385-001c-4c84-9a80-553315336a63 | CRITICAL | 9.8 | The WPJobBoard plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.0 due to insuff… | — | wordfence | |
| 8ccb1304-326e-43af-b75d-23874f92ba8b | < 2.0.45 |
CRITICAL | 9.8 | The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login β User Verification p… | — | wordfence |
| 8cbf5121-2511-4e21-a346-67fa1e34fc02 | CRITICAL | 9.8 | The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.… | — | wordfence | |
| 8ca830d6-3d3c-4026-85cd-8447b8a568d3 | < 3.4.2 |
CRITICAL | 9.8 | The Burst Statistics β Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vul… | — | wordfence |
| 8ca7b2ab-bc01-4fd7-9cee-7cdc5a62177d | CRITICAL | 9.8 | The Echelon theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/lib… | — | wordfence | |
| 8c852eb8-4b55-48e1-95e8-43e9a2962015 | CRITICAL | 9.8 | The Spreadsheet Price Changer for WooCommerce and WP E-commerce β Light plugin for WordPress is vulnerable to Local Fi… | — | wordfence | |
| 8c652a98-2762-4ecf-8037-58377d6e1b5a | < 1.44 |
CRITICAL | 9.8 | The wordTube plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.43 via the 'w… | — | wordfence |
| 8c5042aa-80d6-47c3-aa85-7e16f40aa47d | CRITICAL | 9.8 | The WHMpress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.2-revision-9… | — | wordfence | |
| 8c3ef1bf-ef81-4e24-9813-de1a25b0e8ae | < 4.6.8.6 |
CRITICAL | 9.8 | The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection. | — | wordfence |
| 8c04d8c9-acad-4832-aa8a-8372c58a0387 | < 3.0.9.5 |
CRITICAL | 9.8 | The Everest Forms β Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress … | — | wordfence |
| 8bd81f3c-f801-4fc6-b2db-754e5ebed688 | < 1.6.1.1 |
CRITICAL | 9.8 | The InfiniteWP Client plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.0… | — | wordfence |
| 8bd035bf-003f-4f97-be76-7b1c50727d21 | < 2.6.0 |
CRITICAL | 9.8 | The Modular DS: Monitor, update, and backup multiple websites plugin for WordPress is vulnerable to Privilege Escalation… | — | wordfence |
| 8bc0969f-7b29-41fb-8d41-869049f87c7d | CRITICAL | 9.8 | The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [… | — | wordfence | |
| 8b865fde-1c47-4574-932c-334ebefb3579 | CRITICAL | 9.8 | Directory traversal vulnerability in main.php in the WP-Lytebox plugin 1.3 for WordPress allows remote attackers to incl… | — | wordfence | |
| 8b818586-99a2-4865-bd5b-3c77e9aca29e | < 1.9 |
CRITICAL | 9.8 | The Dessau theme for WordPress is vulnerable to Local File Inclusion in versions up to 1.9. This makes it possible for u… | — | wordfence |
| 8b7c9d89-c6bf-4973-87c8-0511758519f7 | < 1.5.35 |
CRITICAL | 9.8 | SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/control… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →