Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 61 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 6b15eca5-fd47-4f8f-8ade-3a90e0bfc110 | < 7.3.2 |
CRITICAL | 9.8 | The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, a… | — | wordfence |
| 6afbdac4-e52a-4ad3-a99a-2d75e698e0fc | < 2.9.3 |
CRITICAL | 9.8 | The JS Help Desk plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.9.2. Thi… | — | wordfence |
| 6aef6fbb-be8c-49e1-ada5-7b4aa8b2ff72 | < 1.3.2 |
CRITICAL | 9.8 | The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication B… | — | wordfence |
| 6aeb0352-66ab-45d4-ad61-f425d7d41f45 | CRITICAL | 9.8 | The Daily Edition theme for WordPress is vulnerable to SQL Injection via the ‘&id’ parameter in versions up to, and … | — | wordfence | |
| 6abbdecd-782a-44a2-981a-ae6caa50dd6a | CRITICAL | 9.8 | The Article analytics plugin for WordPress is vulnerable to SQL Injection via the 'p' parameter in all versions up to, a… | — | wordfence | |
| 6ab975b0-4216-46df-bf5e-91e403728e5b | < 1.5.4 |
CRITICAL | 9.8 | The wpDataTables plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… | — | wordfence |
| 6ab578cd-3a0b-43d3-aaa7-0a01f431a4e2 | < 4.2.5.8 |
CRITICAL | 9.8 | The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all ve… | — | wordfence |
| 6ab0d342-bfa7-4760-b839-37c3354414ca | CRITICAL | 9.8 | The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5… | — | wordfence | |
| 6a7e794b-aa0e-4db3-8999-c9c5134a4ded | CRITICAL | 9.8 | The eTemplates plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.2.1 due to insuff… | — | wordfence | |
| 6a60e2c3-4597-4b21-ad20-6a00e483fcf1 | < 16.6 |
CRITICAL | 9.8 | The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va… | — | wordfence |
| 6a4d5a40-2ec0-468e-bafb-a713629f6006 | < 4.51 |
CRITICAL | 9.8 | The Webcam Video Conference plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… | — | wordfence |
| 6a0be61b-a1ee-499f-b991-58d5494bce18 | < 1.0.1 |
CRITICAL | 9.8 | The Zendrop – Global Dropshipping plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and … | — | wordfence |
| 6a050764-0ba6-49a4-bd71-f79e3129fc4c | < 2.9.9 |
CRITICAL | 9.8 | The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to mis… | — | wordfence |
| 6a04e6ad-9365-4cb5-a0a0-82e047647d6b | < 4.2.9 |
CRITICAL | 9.8 | The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modi… | — | wordfence |
| 69b2f126-8f57-4bea-b0e9-14b4566ac470 | < 2.0.3 |
CRITICAL | 9.8 | The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection via the 'orderby' and 'order' parameters. | — | wordfence |
| 6989e54b-ce5e-4c79-bd0d-0f7978a4bd44 | < 4.6.1 |
CRITICAL | 9.8 | The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?pag… | — | wordfence |
| 6980248b-195d-4e03-853e-a767a9a4b513 | CRITICAL | 9.8 | The Partners plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.2.0 via dese… | — | wordfence | |
| 6980112b-a555-47a4-b2d7-f0187d52fc63 | < 1.2.4 |
CRITICAL | 9.8 | The Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to … | — | wordfence |
| 6969d281-f280-4714-9859-38ac66e9cc60 | < 3.0.6 |
CRITICAL | 9.8 | The Edwiser Bridge plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.5. … | — | wordfence |
| 695819e6-2574-4047-a55d-a78289c29ba0 | < 1.5.55 |
CRITICAL | 9.8 | Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL inje… | — | wordfence |
| 694b67d2-7d60-4764-a2c0-02698c331772 | < 3.8.1 |
CRITICAL | 9.8 | The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 vi… | — | wordfence |
| 692a5838-4a32-4444-b1a0-018fa25594a9 | < 2.0.2 |
CRITICAL | 9.8 | The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc… | — | wordfence |
| 68ed894d-b48b-42ef-89a9-b6a2ea093fc4 | < 1.4 |
CRITICAL | 9.8 | The Custom Fields Account Registration For Woocommerce plugin for WordPress is vulnerable to Privilege Escalation in all… | — | wordfence |
| 68e838d4-2ff2-4925-b2ff-ba3f7b379010 | < 3.1.4 |
CRITICAL | 9.8 | A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress Word… | — | wordfence |
| 68e0f54d-08ec-4e41-ac9b-d72cdde5a724 | CRITICAL | 9.8 | The Where I Was, Where I Will Be plugin for WordPress is vulnerable to Remote File Inclusion in version <= 1.1.1 via the… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →