Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 63 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 65fc2929-b65b-451b-b90d-6739a673ac16 | CRITICAL | 9.8 | The MBStore - Digital WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versions … | — | wordfence | |
| 65ebc744-6cc2-47ce-b225-81820e49d59c | < 1.6.0 |
CRITICAL | 9.8 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versio… | — | wordfence |
| 65e2e9e3-2778-4baf-8269-fc13d5ef1212 | < 2.7.2 |
CRITICAL | 9.8 | The JS Help Desk plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 2.7.1. T… | — | wordfence |
| 65be9417-7029-4f34-b834-98208a42743b | < 8.0.0 |
CRITICAL | 9.8 | The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Authentication Bypass in versions 1.9.1 to… | — | wordfence |
| 65988550-d39d-40be-8d25-647e7237062d | < 6.1.1 |
CRITICAL | 9.8 | The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all ver… | — | wordfence |
| 657f3bd7-2cdc-4eb6-ba50-7c7fca468df0 | < 5.0.13 |
CRITICAL | 9.8 | The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and… | — | wordfence |
| 65386d2b-5d0c-4e49-a79a-a793b4b599e0 | CRITICAL | 9.8 | The FW Food Menu – Responsive food menu with ordering & delivery solutions plugin for WordPress is vulnerable to arbit… | — | wordfence | |
| 65192fdb-86db-475a-8c61-4db922920cfe | < 250214 |
CRITICAL | 9.8 | The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216… | — | wordfence |
| 65166432-a877-4070-94c1-cdaf7e5d7586 | < 1.5.99 |
CRITICAL | 9.8 | The Booking Package plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including 1.5.98 d… | — | wordfence |
| 64eb4bfe-09b4-43c7-9d7e-f14fc5edf3c1 | < 6.90 |
CRITICAL | 9.8 | The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in … | — | wordfence |
| 64e806df-4919-4a58-8f21-075f09668174 | < 1.0.73 |
CRITICAL | 9.8 | The 10Web Map Builder for Google Maps plugin for WordPress is vulnerable to generic SQL Injection via the multiple param… | — | wordfence |
| 64e125c7-3f1e-43ed-8655-e0fbb95bc84b | CRITICAL | 9.8 | The "CStar Design WordPress Theme" theme for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in vers… | — | wordfence | |
| 6494e54c-db04-41f9-8b91-6ad12528cf01 | < 3.1.17 |
CRITICAL | 9.8 | The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin… | — | wordfence |
| 647cc71d-4d3a-4722-b498-baaee2450809 | < 10.6.7 |
CRITICAL | 9.8 | The RSVPMaker plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 10.6.6 via de… | — | wordfence |
| 647a2f27-092a-4db1-932d-87ae8c2efcca | CRITICAL | 9.8 | The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via… | — | wordfence | |
| 643d41b9-f949-4fc1-acb4-d3147b59823b | CRITICAL | 9.8 | The Goodlayers Hotel plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.1.4 … | — | wordfence | |
| 64188179-1d7d-476f-866c-62bc10c85a3d | < 2.3.1 |
CRITICAL | 9.8 | The estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admi… | — | wordfence |
| 641123af-1ec6-4549-a58c-0a08b4678f45 | < 5.7.21 |
CRITICAL | 9.8 | The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ paramete… | — | wordfence |
| 640f2616-f3a5-4be6-901e-848d2d77506e | < 2.7.8 |
CRITICAL | 9.8 | The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archiv… | — | wordfence |
| 64087631-3514-4fec-ad2f-b095d7c727bd | < 2.8.3 |
CRITICAL | 9.8 | The Houzez theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.8.2 due to insufficie… | — | wordfence |
| 63fab608-1a75-4b07-8d82-8ab87e197547 | CRITICAL | 9.8 | The OTP-less one tap Sign in plugin for WordPress is vulnerable to privilege escalation via account takeover in versions… | — | wordfence | |
| 63f3aa9e-2d82-440b-b37c-211dc3b5d26d | < 3.3.4 |
CRITICAL | 9.8 | The Chaty Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all ve… | — | wordfence |
| 63f10214-69ef-4b5d-8d2b-2e2c1bafa7e7 | < 1.9.4.5 |
CRITICAL | 9.8 | The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in in… | — | wordfence |
| 63effbe3-e509-4f62-a7aa-7727e855bebf | CRITICAL | 9.8 | The Wp2android plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~… | — | wordfence | |
| 63c74d96-84da-408f-ba2c-cde0ff108bf1 | < 3.4.9 |
CRITICAL | 9.8 | The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to re… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →