Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 51 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 885ee376-26cb-4330-9494-019b8870a982 | CRITICAL | 9.8 | The La Boom theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7. This makes … | — | wordfence | |
| 885eb923-8e69-416b-8494-a42a9465cfe0 | CRITICAL | 9.8 | The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… | — | wordfence | |
| 884dd491-c5b9-4278-9532-4896b6076f0a | CRITICAL | 9.8 | The Multi Purpose Mail Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… | — | wordfence | |
| 8840bb3c-3e4b-48d5-bf01-2ed9bcfcf27a | < 1.5.11 |
CRITICAL | 9.8 | The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows… | — | wordfence |
| 87ec5542-b6e7-4b18-a3ec-c258e749d32e | < 5.2.1.1 |
CRITICAL | 9.8 | The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.… | — | wordfence |
| 87d153df-93b0-40a3-b119-9fad41fbd0ee | < 2.0.4 |
CRITICAL | 9.8 | Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable paramete… | — | wordfence |
| 87c7fe1a-c7d3-4d95-b3ed-da08c7428ad1 | CRITICAL | 9.8 | The WDES Responsive Mobile Menu plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includ… | — | wordfence | |
| 878420ce-3a39-494d-9169-44220b2c3307 | < 1.4.3 |
CRITICAL | 9.8 | The iThemes2 Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the the… | — | wordfence |
| 876efd71-8867-44b8-8017-86fad2a1b89f | < 1.2.2 |
CRITICAL | 9.8 | The WP Fastest Cache plugin for WordPress is vulnerable to SQL Injection via the '$username' variable retrieved via user… | — | wordfence |
| 87399a07-d2d8-42cd-81f0-9060f6cfff48 | < 1.2.0 |
CRITICAL | 9.8 | The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 … | — | wordfence |
| 86f91589-b309-49aa-8b04-ca972acaf8fb | < 7.8.5 |
CRITICAL | 9.8 | The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file upload… | — | wordfence |
| 86eb42de-a820-4ba7-99cb-03d068e208a9 | < 0.9.2 |
CRITICAL | 9.8 | The Category and Page Icons plugin for WordPress is vulnerable to Arbitrary File Upload and Deletion due to a directory … | — | wordfence |
| 86d32797-a924-4d38-8543-eddb5f725d46 | CRITICAL | 9.8 | The NIX Anti-Spam Light plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.0… | — | wordfence | |
| 86becbbf-6d3c-4f06-bcb9-92167aad4084 | < 1.2 |
CRITICAL | 9.8 | The Széchenyi 2020 Logo plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.… | — | wordfence |
| 866f780e-46fa-407a-b777-951a328003dd | CRITICAL | 9.8 | The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manua… | — | wordfence | |
| 86609dfe-2060-4db2-8c5c-4e541302fc50 | < 1.24.1 |
CRITICAL | 9.8 | The Ultimate Addons for Beaver Builder plugin for WordPress is vulnerable to authorization bypass due to missing capabil… | — | wordfence |
| 8621bc52-3a71-4e01-9823-129ce0831ec4 | < 2.5.96 |
CRITICAL | 9.8 | Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPres… | — | wordfence |
| 860e70be-2ccd-4d4d-b0d9-bde8d163c211 | CRITICAL | 9.8 | The 123ContactForm for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type v… | — | wordfence | |
| 860b13d9-f906-4a10-98be-d4a7ac75d09d | CRITICAL | 9.8 | The Acnoo Flutter API plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, … | — | wordfence | |
| 8607acb6-743b-4a32-9941-27ce72379f0a | CRITICAL | 9.8 | The Firebase OTP Authentication plugin for WordPress is vulnerable to privilege escalation via account takeover in all v… | — | wordfence | |
| 85dc6513-90cb-433d-8f8f-5b56b4a76897 | < 1.6.6 |
CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in VastHTML Forum Server (aka ForumPress) plugin 1.6.1 and 1.6.5 for WordPress al… | — | wordfence |
| 85bea3da-f54a-4a77-9abe-6c24bbdcc25c | < 2.5.0 |
CRITICAL | 9.8 | The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files. | — | wordfence |
| 8599cb81-4f51-40b5-a0aa-5d27f2ae085d | < 2.9.8.6 |
CRITICAL | 9.8 | The Feed Them Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … | — | wordfence |
| 8571b80b-a76d-4ade-98c9-c0bd44eee344 | < 7.3.0.6 |
CRITICAL | 9.8 | The Uncanny Automator Pro plugin for WordPress contains a backdoor in all versions up to, and including, 7.3.0.5. This i… | — | wordfence |
| 855d3e2a-8ab1-4e7b-b435-f3c31171deeb | < 8.9.3 |
CRITICAL | 9.8 | WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation. | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →