Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 58 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 73aa7b26-dbdf-4859-8fb9-f71dc734bb87 | < 1.3 |
CRITICAL | 9.8 | SQL injection vulnerability in the "the_search_function" function in cardoza_ajax_search.php in the AJAX Post Search (ca… | — | wordfence |
| 73a0d7a9-374b-430d-a7e5-3c7cdaff5785 | < 1.4.3 |
CRITICAL | 9.8 | The Login As Users plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4… | — | wordfence |
| 73837bb4-8af9-4455-93dc-522d64258014 | CRITICAL | 9.8 | The BuddyPress Better Registration plugin for WordPress is vulnerable to authentication bypass in all versions up to, an… | — | wordfence | |
| 73835cfc-4c10-40d5-8df2-903d907326d4 | < 1.9.5 |
CRITICAL | 9.8 | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrat… | — | wordfence |
| 73776e0a-4d2a-44f9-97a2-f06055ce2c63 | CRITICAL | 9.8 | TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary… | — | wordfence | |
| 733ddf62-278b-4a2d-9dc5-28db3491cb29 | CRITICAL | 9.8 | The moveto plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … | — | wordfence | |
| 7332fe2e-9bef-42b7-946e-4a2ee812ca26 | < 2.0 |
CRITICAL | 9.8 | The ERE Recently Viewed plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,… | — | wordfence |
| 73115c27-86f1-4421-9fe5-bf5d8cf54d9f | CRITICAL | 9.8 | The WPLocalPlaces theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… | — | wordfence | |
| 72ed9cba-fe5c-4cee-9e1b-c3edde2521ca | < 9.0.3 |
CRITICAL | 9.8 | Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulner… | — | wordfence |
| 72de9f64-f3e0-4705-adc1-6c22076b382f | < 5.4.8.2 |
CRITICAL | 9.8 | The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type v… | — | wordfence |
| 72aa362f-927d-427f-8de9-f5119d53497e | < 1.2.6 |
CRITICAL | 9.8 | The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions. | — | wordfence |
| 72633a5c-67e7-444f-9a32-ef3266468cee | < 1.2.78.0 |
CRITICAL | 9.8 | The MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. plugin for WordPress is vul… | — | wordfence |
| 7250da0a-1ac6-48a6-a480-0721d604add3 | CRITICAL | 9.8 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includ… | — | wordfence | |
| 72154404-f956-4ea2-96ec-166ade87885f | < 5.1.3 |
CRITICAL | 9.8 | The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2… | — | wordfence |
| 71cc804f-6146-4594-8e7a-854754a1ff20 | < 2.3.4 |
CRITICAL | 9.8 | The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… | — | wordfence |
| 71955ba0-42ba-49a1-8b91-81069c6132ea | < 3.1.4 |
CRITICAL | 9.8 | A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePr… | — | wordfence |
| 7192fb4c-0434-4e11-a2a7-c205b8d6b68e | < 1.2.9 |
CRITICAL | 9.8 | The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. Th… | — | wordfence |
| 7183288f-47f1-477b-974d-e5e21c170d0f | CRITICAL | 9.8 | SQL injection vulnerability in game_play.php in the FB Gorilla plugin for WordPress allows remote attackers to execute a… | — | wordfence | |
| 71625093-d813-43d9-95ec-d4ae0934abec | < 3.4.2 |
CRITICAL | 9.8 | The Wilmër theme for WordPress is vulnerable to Local File Inclusion in versions up to 3.4.2. This makes it possible fo… | — | wordfence |
| 715b0d61-1fac-4039-b18c-e9371788c24c | < 2.5.1 |
CRITICAL | 9.8 | A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitat… | — | wordfence |
| 71053df9-c4b6-4c27-9582-600363b82a36 | CRITICAL | 9.8 | The WP Newsletter Subscription plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc… | — | wordfence | |
| 70fb90f0-1ca4-41fe-8638-cdd05747adae | CRITICAL | 9.8 | The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. … | — | wordfence | |
| 70f64ea0-5375-479f-90ac-29bcdf817cef | CRITICAL | 9.8 | The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable t… | — | wordfence | |
| 70ede219-e59d-40dd-9e5e-4f44089d7524 | < 2.2.7 |
CRITICAL | 9.8 | Unrestricted file upload vulnerability in includes/doajaxfileupload.php in the MM Forms Community plugin 2.2.5 and 2.2.6… | — | wordfence |
| 70e29aa5-6f36-498f-ad85-f9d9ab8d9bcb | CRITICAL | 9.8 | The sem-wysiwyg plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →