Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 55 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 7d98f57f-5ae8-4669-8d79-cc3f236e7a8e | < 25.07000000-WP6.8.1 |
CRITICAL | 9.8 | The Click & Pledge Connect plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 25.… | — | wordfence |
| 7d8dcf85-9009-4788-9a12-7f2656aa5595 | CRITICAL | 9.8 | The JS Restaurant plugin for WordPress is vulnerable to generic SQL Injection via the ‘restuarant_id’ parameter in a… | — | wordfence | |
| 7d70e56f-3bb2-4cfd-8998-e419bbdf016c | CRITICAL | 9.8 | The Meetup plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1. This i… | — | wordfence | |
| 7d636768-37b4-4343-9028-30e7b1f997f2 | < 3.0.0.266 |
CRITICAL | 9.8 | The Javo Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.0.0.080… | — | wordfence |
| 7d5f2f1c-e93d-4fc5-bf1b-2f18996f2b5b | < 1.3.6 |
CRITICAL | 9.8 | The Kiamo - Responsive Business Service WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in ver… | — | wordfence |
| 7d5d05ad-1a7a-43d2-bbbf-597e975446be | < 9.1.2 |
CRITICAL | 9.8 | The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass … | — | wordfence |
| 7d1cc8c4-6c14-4d0c-9420-02d709f88b2f | < 3.9.9 |
CRITICAL | 9.8 | The MStore API plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.9.8 due to… | — | wordfence |
| 7d0919de-dac5-4168-aae4-74bf528a27e4 | < 1.4.5 |
CRITICAL | 9.8 | The GravityWP - Merge Tags plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, … | — | wordfence |
| 7cf05767-af07-4577-9f00-b2695237e041 | < 1.48 |
CRITICAL | 9.8 | The FluentBoards plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.47 via d… | — | wordfence |
| 7cdfce88-b6c2-4820-9d6f-446f61b9b596 | < 1.2.85 |
CRITICAL | 9.8 | The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is du… | — | wordfence |
| 7cd8dc3e-6328-49f2-8cc7-cc395646ee40 | CRITICAL | 9.8 | The Zenny theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.5. This makes … | — | wordfence | |
| 7cce9b8b-0589-4b09-b184-a66fc86fcb46 | < 2.7.10 |
CRITICAL | 9.8 | The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including,… | — | wordfence |
| 7ca93715-bcc4-4710-bfda-f1774fc66cbe | CRITICAL | 9.8 | The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and in… | — | wordfence | |
| 7ca2c82d-0962-4e18-83d7-636bcef18ca5 | CRITICAL | 9.8 | The Dash theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3 via deserializa… | — | wordfence | |
| 7c7ad744-949c-4a27-81c9-b2badbaa1eec | < 4.2.4 |
CRITICAL | 9.8 | The Greenmart theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2.3. This ma… | — | wordfence |
| 7c6be4e1-1b24-4a95-a6fd-3196f47796a6 | CRITICAL | 9.8 | The TDO Mini Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via … | — | wordfence | |
| 7c5092fa-a2ea-4a84-8ebd-273faf6c8707 | < 1.2 |
CRITICAL | 9.8 | The Kish Guest Posting plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence |
| 7c48a2dc-65d8-4fc5-9ee2-70c6a78611e6 | CRITICAL | 9.8 | The Critical Site Intel plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to… | — | wordfence | |
| 7c3ae610-44ef-4354-b085-00c00a486dc9 | < 1.4.7 |
CRITICAL | 9.8 | The Login with Cognito plugin for WordPress is vulnerable to authentication bypass in versions up to, and including 1.4.… | — | wordfence |
| 7c31d9b3-38b1-49a1-b361-ffe97e02bff0 | < 2.4 |
CRITICAL | 9.8 | The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to mis… | — | wordfence |
| 7c1388d2-ba60-4738-94d6-31123ef64ef8 | < 3.6.6 |
CRITICAL | 9.8 | The Course Builder - Online Course WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all vers… | — | wordfence |
| 7c1372bd-821d-439c-9b11-dfa5f08dd0dd | < 2.34.0 |
CRITICAL | 9.8 | The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence |
| 7bfe87cf-9883-4f8f-a0f5-23bbc7bb9b7c | < 2.20 |
CRITICAL | 9.8 | The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.19. This is d… | — | wordfence |
| 7bcd9611-8f1e-42da-a47b-abcbe0cfd849 | < 4.0.1 |
CRITICAL | 9.8 | The News & Blog Designer Pack plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… | — | wordfence |
| 7bc33a05-d462-492e-9ea5-cf37b887cc94 | < 2.0.0 |
CRITICAL | 9.8 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →