Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 57 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 781a15da-5747-4480-a8a6-2944632742c1 | < 1.5.1 |
CRITICAL | 9.8 | The PHP Event Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence |
| 7815322d-a240-4855-b458-60caa3cec96c | < 3.18.4 |
CRITICAL | 9.8 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type v… | — | wordfence |
| 7802ed1f-138c-4a3d-916c-80fb4f7699b2 | < 9.9.1 |
CRITICAL | 9.8 | The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmy… | — | wordfence |
| 77ea4ba8-6c13-494a-92e3-12643003635b | < 2.7.4 |
CRITICAL | 9.8 | The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … | — | wordfence |
| 775860e5-87c9-4878-a629-d7a7cd0cbf1d | < 2.6 |
CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly… | — | wordfence |
| 7713f2b3-1f85-4ad3-822a-3a6746fcf6ec | CRITICAL | 9.8 | The SNS Anton theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1. This make… | — | wordfence | |
| 76e41376-3db0-481b-9f86-bb77b00882e0 | CRITICAL | 9.8 | The Mistape plugin for WordPress is vulnerable to a developer-created backdoor in version 1.4.0. The backdoor is present… | — | wordfence | |
| 76dbd82d-60a4-40c8-8f66-6bbe45b4d199 | < 51.1.37 |
CRITICAL | 9.8 | The King Addons for Elementor β 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin… | — | wordfence |
| 76529b0d-6679-4709-851e-5c9c01e7e085 | CRITICAL | 9.8 | The Grand Tour | Travel Agency WordPress theme for WordPress is vulnerable to PHP Object Injection in versions up to, an… | — | wordfence | |
| 762c5217-bea7-4351-92bb-d3e408c47d6a | CRITICAL | 9.8 | The SS Quiz plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.5 via deser… | — | wordfence | |
| 761ec035-5961-45a5-8197-b5209df8bc3a | < 1.3.9 |
CRITICAL | 9.8 | The Jigoshop β Store Toolkit plugin for WordPress is vulnerable to authorization bypass due to a missing capability ch… | — | wordfence |
| 75fc21c8-352c-48dc-9d3f-53a738306f97 | < 1.6.3 |
CRITICAL | 9.8 | The Role Based Pricing for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and… | — | wordfence |
| 75699831-de38-4c3b-840d-82a04fc97048 | CRITICAL | 9.8 | The Ghost theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the via the… | — | wordfence | |
| 75432cfd-7c0d-4d93-9b62-cac0fd9b49d5 | < 5.1.1 |
CRITICAL | 9.8 | The ChatBot with AI plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.1… | — | wordfence |
| 753a4f7a-7bd4-43a4-b8fb-9e982239ba0e | < 1.3.8 |
CRITICAL | 9.8 | The YayExtra β WooCommerce Extra Product Options plugin for WordPress is vulnerable to arbitrary file uploads due to m… | — | wordfence |
| 74ee6bf0-7091-40b8-a3e7-9ba1411b7ea4 | < 7.4.1 |
CRITICAL | 9.8 | The WPDating plugin for WordPress is vulnerable to SQL Injection via the 'sender_id' parameter in versions up to, and in… | — | wordfence |
| 74e728fd-1498-4b2f-8a0d-9d5aaf58787e | < 1.1.0 |
CRITICAL | 9.8 | The License For Envato plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.… | — | wordfence |
| 74e38291-b312-4742-857e-b080321d8225 | < 2.8.33 |
CRITICAL | 9.8 | The Filter & Grids plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.… | — | wordfence |
| 74bd595b-d2fa-4c62-82d2-dba2c2b128f0 | < 1.0.26 |
CRITICAL | 9.8 | The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable… | — | wordfence |
| 74a26e81-c063-4590-abe8-6cac9ec62316 | < 3.2.7 |
CRITICAL | 9.8 | The MarketPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.2.6 via d… | — | wordfence |
| 743e40f6-dde3-4d8f-938e-b2a0dcdfb901 | < 1.0.22 |
CRITICAL | 9.8 | The Build App Online plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.2… | — | wordfence |
| 743d7370-cf33-481c-8d0a-c6f969e38b42 | < 3.4.1 |
CRITICAL | 9.8 | The Email Before Download plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.4 due … | — | wordfence |
| 741915a7-c88d-41e1-9347-1d5d6494d051 | CRITICAL | 9.8 | The mTheme-Unus theme for WordPress is vulnerable to Local File Inclusion in all versions via the 'files' parameter. Thi… | — | wordfence | |
| 740ed055-8548-42fd-81e1-9f63dda85374 | < 3.8120 |
CRITICAL | 9.8 | The CRM WordPress Plugin β RepairBuddy plugin for WordPress is vulnerable to account takeover in all versions up to, a… | — | wordfence |
| 73c98e25-98ae-48b8-9572-2d6a5dbbeb99 | < 1.1.9 |
CRITICAL | 9.8 | The Medcity - Health & Medical WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to missin… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →