Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 59 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 70dffb0a-eef0-4df7-977b-a36f937a4a89 | < 1.9.0 |
CRITICAL | 9.8 | The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing ca… | — | wordfence |
| 70a2b6ff-defc-4722-9af9-3cae94e98632 | < 5.4.2 |
CRITICAL | 9.8 | The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up… | — | wordfence |
| 708c2c69-aa1b-4bfb-bef5-f2faa1e49a10 | < 1.5.31 |
CRITICAL | 9.8 | A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitat… | — | wordfence |
| 7085e16a-cdf3-4467-b957-23ab372416e6 | < 1.0.2 |
CRITICAL | 9.8 | SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.0.1 for WordPress allows remote attackers to ex… | — | wordfence |
| 7053978d-4780-4532-b504-265b60d1911c | < 1.8.5 |
CRITICAL | 9.8 | The Makeaholic theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.8.4. This m… | — | wordfence |
| 70361501-8adc-499a-91d2-cf91fab5934a | < 2.0.7 |
CRITICAL | 9.8 | The 百度站长SEOåˆé›†(支æŒç™¾åº¦/神马/Bing/å¤´æ¡æŽ¨é€) plugin for WordPress is vulnerable to arbitrary file up… | — | wordfence |
| 701d99b7-759f-4543-824d-dad84c35f5f3 | < 1.1.65 |
CRITICAL | 9.8 | The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection via query parameter. | — | wordfence |
| 7019b542-9b9a-4d16-94a0-412cccf1e6eb | < 5.3.9 |
CRITICAL | 9.8 | The XStore Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.3.8. … | — | wordfence |
| 6ff01c24-fa35-43bc-be60-f2bb37854681 | < 1.5.4 |
CRITICAL | 9.8 | The Doccure Core plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… | — | wordfence |
| 6feae1c4-3735-4a33-85a5-867d458d2e8a | < 1.3.14 |
CRITICAL | 9.8 | The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclu… | — | wordfence |
| 6fb01045-d38f-469f-8aaf-ff8882132acc | < 2.0.18 |
CRITICAL | 9.8 | The iThemes Sync plugin for WordPress is vulnerable to authentication bypass due to a missing validation on the secure k… | — | wordfence |
| 6fa4aa8d-d7f1-4e91-bb2c-c9f80a4bb216 | < 4.8.2 |
CRITICAL | 9.8 | The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8.… | — | wordfence |
| 6f9a6fc2-0375-480e-8c42-c6b97613bf68 | < 0.9.2.9 |
CRITICAL | 9.8 | WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability | — | wordfence |
| 6f9152fe-0273-4af3-8dee-ecb96ec7479b | < 1.3.1 |
CRITICAL | 9.8 | The Integration for Contact Form 7 and Zoho CRM, Bigin plugin for WordPress is vulnerable to PHP Object Injection in ver… | — | wordfence |
| 6f89c43c-6729-40c5-bd32-3c328f83e366 | < 6.2 |
CRITICAL | 9.8 | The RSVPMaker plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 6.1.9 due to… | — | wordfence |
| 6f65d5c4-6f53-4836-9130-c9f4ed3be893 | < 2.2.0 |
CRITICAL | 9.8 | The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization wi… | — | wordfence |
| 6f476fc6-54c8-438f-ae6a-d29d1ffb4fbc | CRITICAL | 9.8 | The Flexi – Guest Submit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, … | — | wordfence | |
| 6f2cf7a3-5710-4db0-b75a-44d4073ee344 | CRITICAL | 9.8 | The Affiliator plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 2.1.3.… | — | wordfence | |
| 6f25b0cc-60ec-49a0-8356-fd3fba97e987 | < 4.5.0 |
CRITICAL | 9.8 | The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all ver… | — | wordfence |
| 6ec02202-18e3-4a57-be2c-7dbf50e500dc | < 4.1.1 |
CRITICAL | 9.8 | The MainWP File Uploader Extension for WordPress is vulnerable to arbitrary file uploads in versions up to, and includin… | — | wordfence |
| 6ebffb82-7455-40c9-9ffd-b78e0e73e431 | < 2.9.3 |
CRITICAL | 9.8 | The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file… | — | wordfence |
| 6e954190-7c58-4044-a85e-a188fe5b6d89 | < 8.4.2 |
CRITICAL | 9.8 | The Soledad theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 8.4.1 via de… | — | wordfence |
| 6e5c6bf7-a653-4571-9566-574d2bb35c4f | < 1.2.6 |
CRITICAL | 9.8 | The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to… | — | wordfence |
| 6e32ff58-e205-4c81-82d1-2a1048256747 | CRITICAL | 9.8 | TheMailCWP plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'mail… | — | wordfence | |
| 6e2e294f-904b-4674-8baf-d3a9a260d634 | < 2.20.4 |
CRITICAL | 9.8 | The Bit Form builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →