Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 63 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 6ebffb82-7455-40c9-9ffd-b78e0e73e431 | < 2.9.3 |
CRITICAL | 9.8 | The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file… | — | wordfence |
| 6e954190-7c58-4044-a85e-a188fe5b6d89 | < 8.4.2 |
CRITICAL | 9.8 | The Soledad theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 8.4.1 via de… | — | wordfence |
| 6e5c6bf7-a653-4571-9566-574d2bb35c4f | < 1.2.6 |
CRITICAL | 9.8 | The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to… | — | wordfence |
| 6e583ae8-40f7-4cd6-b72d-c47d8bec77d4 | < 2.3.2 |
CRITICAL | 9.8 | The CheckView β Form & Checkout Testing plugin for WordPress is vulnerable to authorization bypass in all versions up … | — | wordfence |
| 6e32ff58-e205-4c81-82d1-2a1048256747 | CRITICAL | 9.8 | TheMailCWP plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'mail… | — | wordfence | |
| 6e2e294f-904b-4674-8baf-d3a9a260d634 | < 2.20.4 |
CRITICAL | 9.8 | The Bit Form builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… | — | wordfence |
| 6de3cbb4-61ac-443e-b7cf-5a2bfea25c56 | CRITICAL | 9.8 | The photokit plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0. Thi… | — | wordfence | |
| 6dd6169b-bc94-4642-8975-2e96bc01576f | < 5.4.22 |
CRITICAL | 9.8 | The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21.… | — | wordfence |
| 6d8916c7-0270-4159-8072-49b1d75a579e | CRITICAL | 9.8 | The MaanStore API plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.0.… | — | wordfence | |
| 6d3bfb78-0538-4627-a206-8d8b5b200bc7 | < 5.1.0.4 |
CRITICAL | 9.8 | The Custom Contact Forms plugin for WordPress is vulnerable to authentication bypass due to missing capability checks on… | — | wordfence |
| 6d2a2460-fbac-41cd-9487-f83af0073de7 | < 2.3.10 |
CRITICAL | 9.8 | The Besa theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.8. This makes i… | — | wordfence |
| 6cf01a38-1fba-4c93-b3fa-acfdd5b19410 | < 1.3 |
CRITICAL | 9.8 | The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.… | — | wordfence |
| 6cecd06f-c064-49fd-b3fa-505a5a0c2e0b | < 2.4.10 |
CRITICAL | 9.8 | The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 v… | — | wordfence |
| 6cc5f274-6e71-47a1-b4ec-9b3ba46fd7bf | CRITICAL | 9.8 | The 123ContactForm plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the c… | — | wordfence | |
| 6cc3c124-f200-4d38-92b3-b520702f3a04 | < 3.1.0 |
CRITICAL | 9.8 | The CouponXxL theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.0 via dese… | — | wordfence |
| 6ca0ce12-4759-4182-b69e-665e189b92f7 | < 3.1.2 |
CRITICAL | 9.8 | The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to PHP Object … | — | wordfence |
| 6c8456fa-939c-4ceb-8361-a8758aec7708 | < 2.9.0 |
CRITICAL | 9.8 | The TI WooCommerce Wishlist plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.… | — | wordfence |
| 6c6a4c5f-7a02-4c53-a0ba-a2c7f592a3a8 | < 2.3.3 |
CRITICAL | 9.8 | The Easy Digital Downloads β Simple Ecommerce for Selling Digital Files WordPress plugin was affected by a SQL Injecti… | — | wordfence |
| 6c31d037-1f9e-4887-aaff-3c32fb8b4501 | < 1.10.4 |
CRITICAL | 9.8 | The wp-hotel-booking plugin through 1.10.3 for WordPress allows remote attackers to execute arbitrary code because of an… | — | wordfence |
| 6c31cf92-26b7-484d-8c93-ce241d655d07 | < 260215 |
CRITICAL | 9.8 | The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and … | — | wordfence |
| 6bf743b1-5a59-4e22-8c59-3c17b2646ec8 | < 3.34 |
CRITICAL | 9.8 | The Store Locator Plugin for WordPress is vulnerable to blind SQL Injection via the sl_vars[num_initial_displayed] param… | — | wordfence |
| 6bde6384-0fcc-4726-a7e5-bad6c3993bce | < 3.3.2 |
CRITICAL | 9.8 | The AccessAlly plugin for WordPress is vulnerable to Arbitrary Code Execution in versions before 3.3.2 via the login_err… | — | wordfence |
| 6bb0462a-e801-4aa7-a98a-c5032cb8304c | < 9.9.7 |
CRITICAL | 9.8 | The plugin School Management Pro in version 8.9 contains code that allows an attacker to remotely execute code. | — | wordfence |
| 6b8ba516-54f8-4422-846a-106b9e8bca8d | < 3.9.8 |
CRITICAL | 9.8 | The SMS Alert β SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulne… | — | wordfence |
| 6b7f700f-e40c-4b45-b651-ab1752255083 | CRITICAL | 9.8 | SQL injection vulnerability in playlist.php in the Spiffy XSPF Player plugin 0.1 for WordPress allows remote attackers t… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →