Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 5 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| be3a0b4b-cce5-4d78-99d5-697f2cf04427 | < 1.9.16 |
CRITICAL | 9.9 | The Tumult Hype Animations plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… | — | wordfence |
| b54f38b6-5f98-469c-802a-a4c1e1f2ab0e | < 2.0.8 |
CRITICAL | 9.9 | Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 allow any authenticated attacker, including a subscriber or cu… | — | wordfence |
| afb5b791-0bc7-466f-87f6-f6c5ebed576b | CRITICAL | 9.9 | The Import Export For WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type … | — | wordfence | |
| adb1d8b0-b1d6-40df-b591-f1062ee744fb | < 18.3 |
CRITICAL | 9.9 | The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and inc… | — | wordfence |
| a979e885-f7dd-4616-a881-64f3d97c309d | < 3.0.2.1 |
CRITICAL | 9.9 | The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and… | — | wordfence |
| a169934d-17ce-4d34-be00-c5ac0b488066 | < 4.9.50 |
CRITICAL | 9.9 | The WooCommerce Follow-Up Emails plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type v… | — | wordfence |
| a14cf955-e354-49c3-a685-d5bd51c79ba9 | < 29.7 |
CRITICAL | 9.9 | The WooCommerce Customers Manager plugin for WordPress is vulnerable to SQL Injection via the 'max_amount_total' paramet… | — | wordfence |
| a14c04e8-72cc-4415-a95c-e26f6335b485 | < 14.11 |
CRITICAL | 9.9 | SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remo… | — | wordfence |
| 9a09102c-391e-4057-b883-3d2eef1671ce | < 1.5.61 |
CRITICAL | 9.9 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file upl… | — | wordfence |
| 97ed0ef5-2a01-4531-a844-81766bdfc7c8 | < 16.26.6 |
CRITICAL | 9.9 | The WP-Recall β Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection in all vers… | — | wordfence |
| 9670bd32-34ce-48b1-82d9-62ab8869a89b | < 2.4.12 |
CRITICAL | 9.9 | The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attri… | — | wordfence |
| 964d6dd2-0e93-4fc2-87ca-0257186d1b37 | < 3.9.0 |
CRITICAL | 9.9 | The Shipment Tracking, Tracking, and Order Tracking for WooCommerce β ParcelPanel (Free to install) plugin for WordPre… | — | wordfence |
| 9476b41d-a9a2-46a7-8cf1-62de5d1703b1 | < 5.7.9 |
CRITICAL | 9.9 | The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.8 due to insu… | — | wordfence |
| 93f377a1-2c33-4dd7-8fd6-190d9148e804 | < 7.2.2 |
CRITICAL | 9.9 | The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and… | — | wordfence |
| 8f50812a-c6a7-4bb3-9833-e10acd0460c0 | < 1.3.3.4 |
CRITICAL | 9.9 | The MDTF β Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' attr… | — | wordfence |
| 8edb060b-349c-46bb-9440-94f753621111 | CRITICAL | 9.9 | The Gallery β Image and Video Gallery with Thumbnails plugin for WordPress is vulnerable to SQL Injection in all versi… | — | wordfence | |
| 8d54079a-1a7e-4391-b7ee-d06d7f8b2312 | < 3.9.2 |
CRITICAL | 9.9 | The Greenshift Query and Meta Addon plugin for WordPress is vulnerable to SQL Injection in versions up to 3.9.2 due to i… | — | wordfence |
| 8d03af4d-a1f9-4c15-a62e-f4cdbcfc9af7 | < 4.0.8 |
CRITICAL | 9.9 | The Widget Options β The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Remote Code … | — | wordfence |
| 8c57211a-f59d-4379-b09e-7c6049a6b04d | < 1.5.6 |
CRITICAL | 9.9 | The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including,… | — | wordfence |
| 8c2707ae-8dc0-417c-be4b-83db7dda9c76 | < 3.5 |
CRITICAL | 9.9 | The WP Poll Maker β Best WordPress Poll Plugin for Voting Contest plugin for WordPress is vulnerable to arbitrary file… | — | wordfence |
| 8c0dc694-854e-4f96-8c2d-7251c41a3ee9 | < 1.6.2 |
CRITICAL | 9.9 | The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability che… | — | wordfence |
| 8b104666-a038-442f-8db8-78ccb64879a7 | < 2.9.5 |
CRITICAL | 9.9 | The ListingPro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.4 due to insuff… | — | wordfence |
| 866e4bc3-080a-4498-b210-e692d72d3db0 | < 2024.09.14 |
CRITICAL | 9.9 | The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_ver… | — | wordfence |
| 8647005a-23ce-417f-9bdb-c54ac506942b | < 1.1.18 |
CRITICAL | 9.9 | The WP Responsive Tabs horizontal vertical and accordion Tabs plugin for WordPress is vulnerable to SQL Injection in ver… | — | wordfence |
| 84090828-f132-4848-8d84-dfff79b44818 | < 3.27 |
CRITICAL | 9.9 | The CSV to html plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →