Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 54 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 7f99fc40-c5b8-4ce8-9422-9c02b1eca9cc | < 2.6.1 |
CRITICAL | 9.8 | The Foton theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.5.2. This makes … | — | wordfence |
| 7f7ffa58-d942-4d60-9df4-6e646fadc23a | CRITICAL | 9.8 | The Ahime Image Printer plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.0… | — | wordfence | |
| 7f7968c4-589c-4949-9f69-4a0ba4db4ea9 | < 7.2 |
CRITICAL | 9.8 | The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i… | — | wordfence |
| 7f380786-7fd8-4a01-b491-63a2c6098a9e | < 2.0.0 |
CRITICAL | 9.8 | The CBX Petition for WordPress plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions … | — | wordfence |
| 7f2b424c-8f2b-4535-a556-0bd833eff2aa | < 1.5.10 |
CRITICAL | 9.8 | The Formality plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.9. This m… | — | wordfence |
| 7f26cf69-5dad-41ab-b302-6d4a753a9586 | CRITICAL | 9.8 | The WeDesignTech Ultimate Booking Addon plugin for WordPress is vulnerable to Authentication Bypass in all versions up t… | — | wordfence | |
| 7f1e81de-44fc-4125-b722-2c16c1f22ffa | CRITICAL | 9.8 | The Portfolio Manager Pro - WordPress Responsive Portfolio & Gallery plugin for WordPress is vulnerable to arbitrary fil… | — | wordfence | |
| 7f1a0d90-2574-4d48-b673-f47c8bc65d21 | < 6.5.3 |
CRITICAL | 9.8 | The Easy Forms for Mailchimp plugin before 6.5.3 for WordPress has code injection via the admin input field. | — | wordfence |
| 7efacddc-3ca9-488b-a143-fe3a990d1324 | < 2.6.8 |
CRITICAL | 9.8 | The WC Place Order Without Payment plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inc… | — | wordfence |
| 7ef64118-b388-4260-930b-6a31992d4076 | CRITICAL | 9.8 | The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection. | — | wordfence | |
| 7ebe84ba-abc1-410c-b315-118746ff235a | < 1.8.3 |
CRITICAL | 9.8 | The EasyCommerce β AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin plugin for WordPress is vulnerable to Privi… | — | wordfence |
| 7eb018bc-2650-4e0d-8da9-325eac826d45 | CRITICAL | 9.8 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi… | — | wordfence | |
| 7e9fec92-f471-4ce9-9138-1c58ad658da2 | < 5.1.3 |
CRITICAL | 9.8 | The User Registration & Membership β Custom Registration Form Builder, Custom Login Form, User Profile, Content Restri… | — | wordfence |
| 7e9d3c2a-54af-4583-b008-b77ffad4e9cd | CRITICAL | 9.8 | The Testimonial Slider And Showcase Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, an… | — | wordfence | |
| 7e987c38-b3a0-470e-9688-c8d79c853501 | CRITICAL | 9.8 | The Woocommerce Product Design plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pa… | — | wordfence | |
| 7e96c65d-be0f-4333-90d2-e1cc792f54b2 | CRITICAL | 9.8 | The Debug Tool plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.2. Th… | — | wordfence | |
| 7e8f230e-3f96-4efd-806d-72725b960303 | < 2.2.2 |
CRITICAL | 9.8 | The Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via … | — | wordfence |
| 7e7acb4d-7f4c-4b3f-a0df-7de99249034e | < 15.6.9 |
CRITICAL | 9.8 | The Simple Business Directory Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and … | — | wordfence |
| 7e402e3e-7b11-4931-8a4b-a80d26b9eb04 | < 3.3.9 |
CRITICAL | 9.8 | The WP Webhooks β Automate repetitive tasks by creating powerful automation workflows directly within WordPress plugin… | — | wordfence |
| 7de26eac-9726-4285-8f65-439f318d8687 | CRITICAL | 9.8 | The advanced-custom-post-type plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and inc… | — | wordfence | |
| 7dd7542a-357e-4a0f-879d-794b3451668e | CRITICAL | 9.8 | The WhatsApp Click to Chat Plugin for WordPress plugin for WordPress is vulnerable to Local File Inclusion in versions u… | — | wordfence | |
| 7dcc3c09-8bd2-4a08-a368-3f406170081e | < 3.0 |
CRITICAL | 9.8 | importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that au… | — | wordfence |
| 7dc9dc1c-2d79-4dc3-9fee-be5d591d2400 | < 3.5.0 |
CRITICAL | 9.8 | The Google Analytics Counter Tracker plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and i… | — | wordfence |
| 7db04a93-a384-4093-8cab-6f1d6822f625 | < 6.2 |
CRITICAL | 9.8 | The Formidable Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.1.2 … | — | wordfence |
| 7da4e3a2-29b3-47f3-b3fb-3a6ad0b8b8ac | < 5.3.0 |
CRITICAL | 9.8 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Remote Code Execution in all ver… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →