Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 62 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 68dd9f6f-ccee-4a27-bd21-2fb32b92cc62 | < 6.0.7.2 |
CRITICAL | 9.8 | The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6… | — | wordfence |
| 68ae048c-a897-4061-b839-56ca0dbb2581 | < 3.0 |
CRITICAL | 9.8 | The kineticPay for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… | — | wordfence |
| 689e86c4-5330-4837-b3ff-2553fa1c2ead | < 3.1.1 |
CRITICAL | 9.8 | The Global DNS plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.1.0. … | — | wordfence |
| 6843939b-889f-45d7-9758-4b76a20d15f1 | CRITICAL | 9.8 | The Dynamic Font Replacement DFR4WP EN plugin for WordPress is vulnerable to arbitrary file deletion in versions up to ,… | — | wordfence | |
| 6837b91d-b3ba-435a-965b-fa18d9b9b9c8 | < 9.2.7 |
CRITICAL | 9.8 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parame… | — | wordfence |
| 68052614-204f-4237-af0e-4b8210ebd59f | < 5.15.2 |
CRITICAL | 9.8 | The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, a… | — | wordfence |
| 67df10cc-ce3c-4157-9860-7e367062f710 | CRITICAL | 9.8 | The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing capability check on the remo… | — | wordfence | |
| 67d8dc60-e66e-4f2f-a06d-f95375ca1994 | CRITICAL | 9.8 | The WordPress & WooCommerce Scraper Plugin, Import Data from Any WebSite. plugin for WordPress is vulnerable to arbitrar… | — | wordfence | |
| 67c7e67e-3e68-4f49-9d81-fa0ed451376e | < 1.7.0 |
CRITICAL | 9.8 | The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more … | — | wordfence |
| 67c4066f-b8bc-4cd0-ae47-844af23e003f | CRITICAL | 9.8 | The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including… | — | wordfence | |
| 67b152b5-e662-4dbd-a7db-87fc63cfb307 | < 2.1.1 |
CRITICAL | 9.8 | TheTop Quark Architecture plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… | — | wordfence |
| 67890f13-df93-4c1d-aabe-a90437183bbd | < 2.20.1 |
CRITICAL | 9.8 | The Masteriyo LMS PRO plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2… | — | wordfence |
| 672edfd2-ca4b-4937-8237-3c0a4acc8690 | CRITICAL | 9.8 | The pb-embedFlash plugin for WordPress is vulnerable to Remote File Inclusion with media files in versions up to, and in… | — | wordfence | |
| 6711f542-8b75-4968-86ac-9686ded775b7 | < 2.1.2 |
CRITICAL | 9.8 | Version 2.1.1 of WordPress was injected with malicious code that supplied attackers with backdoor access to WordPress si… | — | wordfence |
| 66ce2d12-8f57-4140-b3cf-0fc8c1c4f3d5 | < 1.1.8 |
CRITICAL | 9.8 | SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar pl… | — | wordfence |
| 66c20a71-96e2-4d5e-a2ed-7e7afbe85306 | CRITICAL | 9.8 | The Automatic Translation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… | — | wordfence | |
| 66a6569b-88ec-42d8-8396-6e62f1c51b24 | CRITICAL | 9.8 | The Invit0r plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the ofc… | — | wordfence | |
| 66969472-4b3c-4d56-b761-523ea854e3db | < 1.5.8 |
CRITICAL | 9.8 | The Leaflet Maps Marker Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… | — | wordfence |
| 668ba3a9-d53c-45ab-854f-1a9e83dd54b8 | < 1.6.7 |
CRITICAL | 9.8 | The WP e-Commerce β Store Exporter plugin for WordPress is vulnerable to authorization bypass due to a missing capabil… | — | wordfence |
| 6687ebbe-fdf4-4ecb-bf59-034bb4b0104c | < 3.5.1 |
CRITICAL | 9.8 | The Academy LMS β WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege… | — | wordfence |
| 66845165-02c7-4f4a-93fd-1a309fb7b386 | CRITICAL | 9.8 | The CAFEHAUS API plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, … | — | wordfence | |
| 66749606-e76f-41fb-bcf1-c06681de2ee3 | CRITICAL | 9.8 | The Master Slider Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3… | — | wordfence | |
| 664e6e2a-faa1-4609-b250-d7e94c5d5a04 | < 1.6.3 |
CRITICAL | 9.8 | The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… | — | wordfence |
| 6629e1a9-3b28-4c8c-95d4-3c0011a7364a | < 2.1.5 |
CRITICAL | 9.8 | An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_no… | — | wordfence |
| 661d4ea9-572d-4544-b5cf-39fd69c104a6 | < 3.9.8 |
CRITICAL | 9.8 | The SMS Alert β SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulne… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →