Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 64 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 63ab6b17-360d-49b2-b1b5-652629eba3be | CRITICAL | 9.8 | The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to Privilege Escalation in all versions u… | — | wordfence | |
| 6347f588-a3fd-4909-ad57-9d78787b5728 | < 2.1.2 |
CRITICAL | 9.8 | The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to … | — | wordfence |
| 6345d360-5f58-44d2-bc2d-1a20ee43e146 | < 3.7.35 |
CRITICAL | 9.8 | Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been p… | — | wordfence |
| 634303eb-b120-4384-9780-b950de491099 | CRITICAL | 9.8 | The µAudio Player plugin for WordPress is vulnerable to Remote File Inclusion of image files in versions up to, and inc… | — | wordfence | |
| 63388bb5-42f1-40c9-ac01-3ab6fc242106 | CRITICAL | 9.8 | The postMash Custom – custom post order plugin for WordPress is vulnerable to SQL Injection in versions up to, and inc… | — | wordfence | |
| 62bc53ae-7cdb-491c-a315-5bf8fa80c27b | < 3.2.7 |
CRITICAL | 9.8 | The Listingo theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via one of … | — | wordfence |
| 628bfa19-2ffa-426b-8b88-22a0c4d0ba92 | < 3.2.3 |
CRITICAL | 9.8 | The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to unauthorized arbitrary file uploads du… | — | wordfence |
| 624c98c2-3fce-4f6b-a049-da3bce2a8c6a | < 2.2.24 |
CRITICAL | 9.8 | The SEUR Oficial plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.23. Th… | — | wordfence |
| 623acb6d-9cab-483c-ad51-88adff8847a4 | < 8.1.6 |
CRITICAL | 9.8 | The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different v… | — | wordfence |
| 620e8931-64f0-4d9c-9a4c-1f5a703845ff | < 3.92.1 |
CRITICAL | 9.8 | The WordPress Automatic Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery and Arbitrary File Down… | — | wordfence |
| 6206a2f8-2de4-4c9f-b439-3c733a5a0a62 | CRITICAL | 9.8 | The WP FoodBakery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.3 via d… | — | wordfence | |
| 6203ffaf-5efd-4c66-85f0-cc3a05a03084 | CRITICAL | 9.8 | The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type val… | — | wordfence | |
| 61e6db2f-5dfd-44ef-9500-9f0cb5cd67ba | < 1.29.3 |
CRITICAL | 9.8 | The WP Job Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.29.2 v… | — | wordfence |
| 618a9ad7-3a13-43e6-84f4-35287f07e1c0 | CRITICAL | 9.8 | The CE21 Suite plugin for WordPress is vulnerable to sensitive information disclosure via the plugin-log.txt in versions… | — | wordfence | |
| 61820ca5-5548-4155-b350-df3db1bc1661 | < 5.6.68 |
CRITICAL | 9.8 | The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and inc… | — | wordfence |
| 6164c161-f764-4064-8139-609caad82204 | CRITICAL | 9.8 | Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slidesh… | — | wordfence | |
| 615d8b8f-037e-4741-bdb4-639daf690aff | CRITICAL | 9.8 | The The Novel Design Store Directory plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty… | — | wordfence | |
| 613f4bd1-e29a-4853-84a2-3e1437f06d33 | < 2.2.81 |
CRITICAL | 9.8 | The Events Made Easy plugin for WordPress is vulnerable to SQL Injection via the ‘lang’ parameter in versions up to,… | — | wordfence |
| 613f22f2-2f84-4d01-a1ea-c14a25843700 | < 2.0.6 |
CRITICAL | 9.8 | Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPre… | — | wordfence |
| 613f2035-3061-429b-b218-83805287e4f3 | < 3.28.21 |
CRITICAL | 9.8 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress … | — | wordfence |
| 613e1862-e0b7-4012-a77d-b5fb56cbbb9c | < 1.2.2 |
CRITICAL | 9.8 | The 360 Product Rotation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… | — | wordfence |
| 6130d49f-61b7-4b70-b1a5-036346f82650 | CRITICAL | 9.8 | The Baggage Freight Shipping Australia plugin for WordPress is vulnerable to arbitrary file uploads due to missing file … | — | wordfence | |
| 61080df6-836f-4365-964a-fa2517e8be5a | < 3.10.0 |
CRITICAL | 9.8 | The CozyStay and TinySalt plugins for WordPress are vulnerable to PHP Object Injection in all versions up to, and includ… | — | wordfence |
| 60f63cdc-9c19-4f6c-a555-519bdb61ce6d | < 1.6 |
CRITICAL | 9.8 | The RokMicroNews plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.5 due to… | — | wordfence |
| 60f043e9-7947-4fff-a9a8-94a1f421db7c | < 1.0.37 |
CRITICAL | 9.8 | The Woodmart Core plugin for WordPress is vulnerable to privilege escalation due to insufficient validation in its socia… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →