Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 52 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 855ca8f0-5078-48ec-a5d0-3f43a217a91e | < 2.1.0.10 |
CRITICAL | 9.8 | In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sani… | — | wordfence |
| 854e5d70-f42f-48c4-b1bb-687610f86cfb | < 2.06.04 |
CRITICAL | 9.8 | The "FireStorm Professional Real Estate Plugin" plugin for WordPress is vulnerable to SQL Injection via the 'id' paramet… | — | wordfence |
| 854ab1f3-5f7c-40a4-85a5-db4e20dc72cc | < 2.1 |
CRITICAL | 9.8 | The Manager for Icomoon plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… | — | wordfence |
| 851daaab-4509-4a1e-b0bb-f9eda2b801c6 | CRITICAL | 9.8 | The Malmonation theme for WordPress is vulnerable to SQL Injection via the βidβ parameter in all versions due to ins… | — | wordfence | |
| 850fc4db-6e02-44c7-836a-02c433a0bae7 | < 4.8 |
CRITICAL | 9.8 | The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation … | — | wordfence |
| 84f08111-d116-46f9-9765-28966e338753 | CRITICAL | 9.8 | The WP Real Estate Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includ… | — | wordfence | |
| 84b75f7d-7258-46f6-aee6-b96d70bee264 | < 1.3.9.1 |
CRITICAL | 9.8 | The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. Thi… | — | wordfence |
| 8494a17a-d6e7-4acb-b08f-3bc4aea0a488 | CRITICAL | 9.8 | The LaunchPage.app Importer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1 du… | — | wordfence | |
| 848f3b21-fb44-45c4-944e-7c4c62448ffc | < 8.1.1 |
CRITICAL | 9.8 | The L4 Shopping Cart Plugin for WordPress is vulnerable to SQL Injection via the βidβ parameter in versions up to, a… | — | wordfence |
| 846fb218-ba71-41a2-af2f-931c2bfd5fdb | < 2.1.1 |
CRITICAL | 9.8 | The ForumWP plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.0 via deser… | — | wordfence |
| 845fbf0f-c7c4-483e-b671-1a703d857792 | CRITICAL | 9.8 | The WPB Show Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2 v… | — | wordfence | |
| 843822f0-dd4c-4ae6-823d-96dd7a59df8e | < 1.5.2 |
CRITICAL | 9.8 | The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL inj… | — | wordfence |
| 84019c69-32fd-4331-95d7-53ea1aaff616 | < 2.0.9.2 |
CRITICAL | 9.8 | The MainWP Child β Securely connects sites to the MainWP WordPress Manager Dashboard plugin for WordPress is vulnerabl… | — | wordfence |
| 83b062c8-4884-4ffa-89e6-71140c99e422 | < 2.4 |
CRITICAL | 9.8 | The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) plugin for WordPress is vulnerable to SQL Injection in v… | — | wordfence |
| 8395e0c4-3feb-4551-9f2f-7b80cd187eca | < 1.4 |
CRITICAL | 9.8 | The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… | — | wordfence |
| 83009e29-6860-4d0c-954a-8035dc361cdc | CRITICAL | 9.8 | The WP-lightpop plugin for WordPress is vulnerable to Remote Media File Inclusion in versions up to, and including, 0.8.… | — | wordfence | |
| 82ffa37a-786c-4af7-8038-f452828160c9 | CRITICAL | 9.8 | The WPKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privile… | — | wordfence | |
| 82c3c97d-f9dd-4667-a1a8-94cf12947618 | < 2.1 |
CRITICAL | 9.8 | The Goto - Tour & Travel WordPress Theme WordPress theme before 2.1 did not sanitise, validate of escape the keywords GE… | — | wordfence |
| 82b46474-9a32-4d7e-8fa4-91f6465c5fa7 | < 1.1.0 |
CRITICAL | 9.8 | Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attack… | — | wordfence |
| 827b5482-cb42-4aaa-80b5-3d0143fcead8 | < 5.1 |
CRITICAL | 9.8 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi… | — | wordfence |
| 8276ecfe-962b-4813-8011-4c8ca59d5389 | < 1.5.3 |
CRITICAL | 9.8 | The Instant Image Generator (One Click Image Uploads from Pixabay, Pexels and OpenAI) plugin for WordPress is vulnerable… | — | wordfence |
| 8247acc4-04dc-463a-906a-f6085116cf40 | < 2.2.4 |
CRITICAL | 9.8 | The Zingiri Web Shop plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.2.3… | — | wordfence |
| 82420667-9ba6-46ed-9a53-d16850755bb9 | < 2.7.4 |
CRITICAL | 9.8 | The TI WooCommerce Wishlistplugin for WordPress is vulnerable to blind SQL Injection via the user_id parameter in versio… | — | wordfence |
| 81fb9d43-3c27-4de9-aa2e-66b783c78fa2 | < 1.2.6 |
CRITICAL | 9.8 | The Enzio - Responsive Business WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versions up… | — | wordfence |
| 81e7ab80-7df2-4ef4-80ee-a11d057151c4 | < 1.2.0 |
CRITICAL | 9.8 | The Vayu Blocks β Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →