Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 49 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 965dce53-2865-4179-9505-a64e4db1d1fd | < 1.0.83 |
CRITICAL | 9.8 | The OttoKit: All-in-One Automation Platform (Formerly SureTriggers) plugin for WordPress is vulnerable to Privilege Esca… | — | wordfence |
| 963f2485-3afa-4e17-8278-b75415af3915 | < 0.1.0.45 |
CRITICAL | 9.8 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in al… | — | wordfence |
| 95ff5150-ff45-48f8-bd39-0df79838942e | < 3.3.4 |
CRITICAL | 9.8 | The BetterDocs plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.3.3 vi… | — | wordfence |
| 95a68ae0-36da-499b-a09d-4c91db8aa338 | < 3.0.9 |
CRITICAL | 9.8 | The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via th… | — | wordfence |
| 9555c48f-5ce3-4c0c-88f3-83776b42b808 | < 13.1.6 |
CRITICAL | 9.8 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t… | — | wordfence |
| 9546ab46-737c-4bd3-9542-8ab1b776b3ea | < 2.14 |
CRITICAL | 9.8 | The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in al… | — | wordfence |
| 952e299a-5cec-444b-8359-3e7d8dec3ccb | < 6.03.01 |
CRITICAL | 9.8 | The Event Registration plugin for WordPress is vulnerable to generic SQL Injection via the ‘submitted_token’ and ‘… | — | wordfence |
| 9505b778-294f-45bc-a36c-22fbb894a294 | < 3.1.0 |
CRITICAL | 9.8 | The LottieFiles plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… | — | wordfence |
| 94fdc98a-c8be-47b4-a0a2-02d7373ab85e | CRITICAL | 9.8 | The Talkback plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0 via deseri… | — | wordfence | |
| 94e987be-bdfc-4691-b250-2b7d7249df0a | < 2.29.0 |
CRITICAL | 9.8 | The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.28.… | — | wordfence |
| 94d67030-30ea-4583-a716-79805a5619e8 | CRITICAL | 9.8 | The Product Website Showcase plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and inc… | — | wordfence | |
| 948d40f5-2c87-4439-b4ef-3e02c397bf0f | < 1.1.6 |
CRITICAL | 9.8 | The CP Appointment Calendar Plugin plugin for WordPress is vulnerable to SQL Injection via the $itemnumber variable in a… | — | wordfence |
| 94736152-b365-4b3a-a786-ed49f7d0fc7a | < 3.3.2 |
CRITICAL | 9.8 | The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3… | — | wordfence |
| 946d5a2c-f20f-483a-8150-0266a631a112 | < 2.2 |
CRITICAL | 9.8 | The Homepage SlideShow plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence |
| 94696151-9f99-4847-bd67-8fb77f8b6a0e | CRITICAL | 9.8 | The BCorp Shortcodes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.… | — | wordfence | |
| 944cd237-d5cb-44da-8d4a-5cf7edd368a4 | < 1.2 |
CRITICAL | 9.8 | SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 fo… | — | wordfence |
| 942fd805-0f4f-44e5-98df-0b44ed8c7543 | < 3.1 |
CRITICAL | 9.8 | The CouponXxL Custom Post Types plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and in… | — | wordfence |
| 941233d8-f382-40a0-81b2-18a682ae07ca | < 3.9.5 |
CRITICAL | 9.8 | The Ad manager & AdSense Ads for WordPress is vulnerable to blind SQL Injection via the ‘track’ parameter in version… | — | wordfence |
| 93b5552e-bb24-4dfb-a779-8451f619ff50 | < 3.9.9.2 |
CRITICAL | 9.8 | The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functional… | — | wordfence |
| 936564ab-3119-4627-b7eb-4ca45ea377e5 | < 1.0.6 |
CRITICAL | 9.8 | The AI Magic – SEO Content Generator & Article Writer plugin for WordPress is vulnerable to Privilege Escalation in al… | — | wordfence |
| 935caa43-4c75-47ad-a631-63988e21f834 | < 2.2.1 |
CRITICAL | 9.8 | The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,… | — | wordfence |
| 934c3ce9-cf2d-4bf6-9a34-f448cb2e5a1d | < 2.1.6 |
CRITICAL | 9.8 | The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This… | — | wordfence |
| 933dd704-5a31-42a9-9b87-bf14a9d4ffa9 | < 1.1.7 |
CRITICAL | 9.8 | The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in a… | — | wordfence |
| 9319dfc7-2b23-4056-8310-41a07535379d | CRITICAL | 9.8 | The ajax-extend plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0 vi… | — | wordfence | |
| 9312c73d-8eb6-4ca0-a03b-566099dc6487 | < 1.4.3 |
CRITICAL | 9.8 | The WP GDPR Compliance plugin for WordPress is vulnerability to arbitrary options updates and action calling in version… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →