Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 50 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 92f3b923-884e-4f61-9bf8-62dfb267a27e | < 1.5.2 |
CRITICAL | 9.8 | The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘event_venue’ parameter in all vers… | — | wordfence |
| 92d5be7a-ce96-4e26-afd1-a84b6f46b03f | < 1.2.1 |
CRITICAL | 9.8 | The TAX SERVICE Electronic HDM plugin for WordPress is vulnerable to SQL Injection via the 'importTaxService' AJAX endpo… | — | wordfence |
| 92c79e51-3b14-4d1c-893b-a683b55f3011 | < 4.2 |
CRITICAL | 9.8 | The Support Plus Responsive Ticket System plugin before 4.2 for WordPress has SQL injection. | — | wordfence |
| 92a120ac-66ae-4678-a87a-e62da885d50b | < 3.9.6 |
CRITICAL | 9.8 | The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.9.… | — | wordfence |
| 92a00fb4-7b50-43fd-ac04-5d6e29336e9c | < 0.1.0.39 |
CRITICAL | 9.8 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates du… | — | wordfence |
| 92915943-c6ff-46df-adbd-382eabe44021 | < 4.9.3 |
CRITICAL | 9.8 | The Manage WP Worker plugin for WordPress is vulnerable to authentication bypass in versions up to, and including 4.9.2,… | — | wordfence |
| 928877a6-eeeb-4ed5-900b-9b1560e1bf87 | < 2.5.01 |
CRITICAL | 9.8 | The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2… | — | wordfence |
| 92544c04-c499-420e-98f4-58834e579725 | CRITICAL | 9.8 | The Custom css-js-php plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, … | — | wordfence | |
| 923c513b-596f-44db-a98f-a33e8baec12e | < 1.6 |
CRITICAL | 9.8 | The Multiple Shipping And Billing Address For Woocommerce plugin for WordPress is vulnerable to PHP Object Injection in … | — | wordfence |
| 92321a3e-947b-4013-9b36-8bd6ea361f20 | < 1.1.4 |
CRITICAL | 9.8 | The BBS e-Franchise for WordPress is vulnerable to generic SQL Injection via the ‘uid’ parameter in versions up to, … | — | wordfence |
| 92298f2d-aced-4177-b6e8-36e153e9c930 | < 3.5.3 |
CRITICAL | 9.8 | The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on c… | — | wordfence |
| 91de6cf4-e5df-4130-bb96-92b89717a678 | < 1.3.2 |
CRITICAL | 9.8 | The WP Frontend Profile plugin for WordPress is vulnerable to privilege in all versions up to, and including, 1.3.1. Thi… | — | wordfence |
| 91aa86d9-8e42-4deb-b6ca-c3b388fefcb1 | CRITICAL | 9.8 | The CE21 Suite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including… | — | wordfence | |
| 91a1604c-c729-4c68-90a8-91862a351ecc | CRITICAL | 9.8 | The WP User plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.0 due to insufficien… | — | wordfence | |
| 91754c4d-a0d0-4d35-a70a-446d2bdf6c73 | CRITICAL | 9.8 | The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th… | — | wordfence | |
| 916ada05-894e-4e61-ba0a-25b9a48461a1 | < 1.2.0 |
CRITICAL | 9.8 | The LetsRecover plugin for WordPress is vulnerable to SQL Injection via an AJAX action in versions up to, and including,… | — | wordfence |
| 913ffe0c-c8f8-4cda-be9a-96c056d4c4a8 | < 1.1 |
CRITICAL | 9.8 | The UrbanGo Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.… | — | wordfence |
| 91286dc8-8015-4adc-9a21-d6187997cef4 | < 3.6.1 |
CRITICAL | 9.8 | The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it … | — | wordfence |
| 911f3449-f906-493a-942b-eca26fdc10aa | CRITICAL | 9.8 | The Avaz theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.8. This makes it … | — | wordfence | |
| 911a9550-1f62-4f28-9d8c-00d9769949c9 | < 1.2 |
CRITICAL | 9.8 | The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including… | — | wordfence |
| 9095bf69-e682-48aa-b206-8bd2b6c2b170 | < 0.43.6 |
CRITICAL | 9.8 | The Sermon Browser plugin for WordPress is vulnerable to SQL Injection via the ‘sermon_id’ parameter in versions bef… | — | wordfence |
| 908dbe64-e214-4880-a85d-38df4c722a43 | CRITICAL | 9.8 | The Dagda Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload… | — | wordfence | |
| 90689ba2-4f82-4116-85d7-1266189aa34e | < 8.0.33 |
CRITICAL | 9.8 | The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api… | — | wordfence |
| 8ff54e1c-7d6c-4360-a9b3-4e8928fff6de | CRITICAL | 9.8 | The Coming Soon, Maintenance Mode plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and incl… | — | wordfence | |
| 8fd2ed33-6977-4480-bdcb-d7afae7bfd06 | CRITICAL | 9.8 | SQL injection vulnerability in the WP Rss Poster (wp-rss-poster) plugin 1.0.0 for WordPress allows remote attackers to e… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →