Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 6 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 83e5a0dc-fc51-4565-945f-190cf9175874 | CRITICAL | 9.9 | The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and … | — | wordfence | |
| 83189c51-2605-4808-a0fa-3e5245cc0806 | < 9.4.5 |
CRITICAL | 9.9 | The WordPress Tooltips plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 9.4.3 d… | — | wordfence |
| 80f7e161-b071-4cb1-8080-ff0ad926a5ca | < 8.6.03.005 |
CRITICAL | 9.9 | The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… | — | wordfence |
| 7f3dac5a-9ff8-4e8c-8c73-422123e121d8 | < 1.3.24 |
CRITICAL | 9.9 | The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all … | — | wordfence |
| 7e52882e-d86f-4863-bdb6-e33c0449d14c | < 3.0.0 |
CRITICAL | 9.9 | PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, whic… | — | wordfence |
| 7aa62be9-93b9-423f-89f8-809ca0035547 | < 3.0.0 |
CRITICAL | 9.9 | PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg blo… | — | wordfence |
| 79fb4f24-8a59-4e57-b583-c87ee2493cdb | < 21.3.5 |
CRITICAL | 9.9 | The Photos and Files Contest Gallery β Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordP… | — | wordfence |
| 7832f8fe-2b41-4cfb-a734-db4ec88d91a3 | < 2.6.8 |
CRITICAL | 9.9 | The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… | — | wordfence |
| 71105a3c-4eb7-49b4-ba47-7997ddeb62c3 | < 2.3.62 |
CRITICAL | 9.9 | The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the geodir_total_listings_count function in ver… | — | wordfence |
| 70e6a0b9-5bf2-4d0b-976e-6d5c56dff37c | < 1.2.8 |
CRITICAL | 9.9 | The Zoho Marketing Automation plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.… | — | wordfence |
| 6fed4181-400b-4414-aa50-1e7bc92d542f | < 1.3.5.3 |
CRITICAL | 9.9 | The HUSKY β Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution i… | — | wordfence |
| 6d9f5901-dc11-4877-b753-deb9c03f4a4e | < 1.6.2 |
CRITICAL | 9.9 | The Zita Elementor Site Library plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability… | — | wordfence |
| 6bef7dcd-920b-4aee-b227-c7eec9fe73fc | < 1.1.13 |
CRITICAL | 9.9 | The CubeWP β All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to arbitrary file uploads due to … | — | wordfence |
| 6bd03b86-e9b7-44d5-9528-efd94f0f79f5 | < 4.2.2 |
CRITICAL | 9.9 | The Event Manager and Tickets Selling Plugin for WooCommerce β WpEvently β WordPress Plugin plugin for WordPress is … | — | wordfence |
| 63d0cb9b-e6ac-474e-ac6b-c0cbd14a19bd | < 3.6.11 |
CRITICAL | 9.9 | The DirectoryPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.6.10 due to i… | — | wordfence |
| 5d8e3832-b3ed-4687-94d8-8ba2c832584c | CRITICAL | 9.9 | The SP Project & Document Manager plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all ve… | — | wordfence | |
| 53c9d3d0-5fea-4e36-b356-8d3c0e672cac | < 2.10.3 |
CRITICAL | 9.9 | Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders f… | — | wordfence |
| 491240c5-2045-4e0b-9916-4337946d2653 | < 1.4.12 |
CRITICAL | 9.9 | The WordPress PDF Light Viewer Plugin WordPress plugin before 1.4.12 allows users with Author roles to execute arbitrary… | — | wordfence |
| 466eec4a-8aac-4b0d-ba18-9667aa70de5a | CRITICAL | 9.9 | The Find Duplicates plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.6 due to i… | — | wordfence | |
| 4257d4ca-0e92-4d2f-b65b-dff9d7d48cb8 | < 3.7.5 |
CRITICAL | 9.9 | The Easy Form Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7.4 due to… | — | wordfence |
| 4174b47a-75d0-4ada-bd4d-efbaf0b1a049 | < 3.2.7 |
CRITICAL | 9.9 | The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in version… | — | wordfence |
| 4167f0ad-aeef-4525-82c9-336f9f48a55e | < 5.3.9 |
CRITICAL | 9.9 | The XStore Core plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … | — | wordfence |
| 41395c95-230d-441a-a261-cd67b95b76e3 | < 7.19.3 |
CRITICAL | 9.9 | The Element Pack Pro - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to Directory… | — | wordfence |
| 3ec997c8-3f47-45c8-8fa2-019b01c97c94 | < 2.9.4 |
CRITICAL | 9.9 | An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in … | — | wordfence |
| 3d8b4bb6-3715-40c1-8140-7fcf874ccec3 | CRITICAL | 9.9 | The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and incl… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →