Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 55 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 850fc4db-6e02-44c7-836a-02c433a0bae7 | < 4.8 |
CRITICAL | 9.8 | The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation … | — | wordfence |
| 84f08111-d116-46f9-9765-28966e338753 | CRITICAL | 9.8 | The WP Real Estate Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includ… | — | wordfence | |
| 84b75f7d-7258-46f6-aee6-b96d70bee264 | < 1.3.9.1 |
CRITICAL | 9.8 | The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. Thi… | — | wordfence |
| 84afe5a7-1bf4-4b83-bf77-efbb003a30cd | < 3.34.2 |
CRITICAL | 9.8 | The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authent… | — | wordfence |
| 8494a17a-d6e7-4acb-b08f-3bc4aea0a488 | CRITICAL | 9.8 | The LaunchPage.app Importer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1 du… | — | wordfence | |
| 848f3b21-fb44-45c4-944e-7c4c62448ffc | < 8.1.1 |
CRITICAL | 9.8 | The L4 Shopping Cart Plugin for WordPress is vulnerable to SQL Injection via the βidβ parameter in versions up to, a… | — | wordfence |
| 846fb218-ba71-41a2-af2f-931c2bfd5fdb | < 2.1.1 |
CRITICAL | 9.8 | The ForumWP plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.0 via deser… | — | wordfence |
| 845fbf0f-c7c4-483e-b671-1a703d857792 | CRITICAL | 9.8 | The WPB Show Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2 v… | — | wordfence | |
| 843822f0-dd4c-4ae6-823d-96dd7a59df8e | < 1.5.2 |
CRITICAL | 9.8 | The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL inj… | — | wordfence |
| 84019c69-32fd-4331-95d7-53ea1aaff616 | < 2.0.9.2 |
CRITICAL | 9.8 | The MainWP Child β Securely connects sites to the MainWP WordPress Manager Dashboard plugin for WordPress is vulnerabl… | — | wordfence |
| 83b062c8-4884-4ffa-89e6-71140c99e422 | < 2.4 |
CRITICAL | 9.8 | The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) plugin for WordPress is vulnerable to SQL Injection in v… | — | wordfence |
| 8395e0c4-3feb-4551-9f2f-7b80cd187eca | < 1.4 |
CRITICAL | 9.8 | The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… | — | wordfence |
| 83009e29-6860-4d0c-954a-8035dc361cdc | CRITICAL | 9.8 | The WP-lightpop plugin for WordPress is vulnerable to Remote Media File Inclusion in versions up to, and including, 0.8.… | — | wordfence | |
| 82ffa37a-786c-4af7-8038-f452828160c9 | CRITICAL | 9.8 | The WPKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privile… | — | wordfence | |
| 82c3c97d-f9dd-4667-a1a8-94cf12947618 | < 2.1 |
CRITICAL | 9.8 | The Goto - Tour & Travel WordPress Theme WordPress theme before 2.1 did not sanitise, validate of escape the keywords GE… | — | wordfence |
| 82b46474-9a32-4d7e-8fa4-91f6465c5fa7 | < 1.1.0 |
CRITICAL | 9.8 | Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attack… | — | wordfence |
| 827b5482-cb42-4aaa-80b5-3d0143fcead8 | < 5.1 |
CRITICAL | 9.8 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi… | — | wordfence |
| 8276ecfe-962b-4813-8011-4c8ca59d5389 | < 1.5.3 |
CRITICAL | 9.8 | The Instant Image Generator (One Click Image Uploads from Pixabay, Pexels and OpenAI) plugin for WordPress is vulnerable… | — | wordfence |
| 8247acc4-04dc-463a-906a-f6085116cf40 | < 2.2.4 |
CRITICAL | 9.8 | The Zingiri Web Shop plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.2.3… | — | wordfence |
| 82420667-9ba6-46ed-9a53-d16850755bb9 | < 2.7.4 |
CRITICAL | 9.8 | The TI WooCommerce Wishlistplugin for WordPress is vulnerable to blind SQL Injection via the user_id parameter in versio… | — | wordfence |
| 81fb9d43-3c27-4de9-aa2e-66b783c78fa2 | < 1.2.6 |
CRITICAL | 9.8 | The Enzio - Responsive Business WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versions up… | — | wordfence |
| 81e7ab80-7df2-4ef4-80ee-a11d057151c4 | < 1.2.0 |
CRITICAL | 9.8 | The Vayu Blocks β Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbi… | — | wordfence |
| 81c62f9d-6a98-4f18-8c4a-c81c2730ce5d | CRITICAL | 9.8 | The Ads Booster by Ads Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, … | — | wordfence | |
| 81b44abb-6d30-4930-b68b-9a04d93f5169 | < 2.1.0 |
CRITICAL | 9.8 | The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0… | — | wordfence |
| 819b9565-2eb1-4b87-bf3a-5cd93429cafe | < 3.7.1.5 |
CRITICAL | 9.8 | The Registration Forms β User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form &… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →