Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 64 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 6b558818-f459-4bc1-893c-8c1c7bf9d6d2 | < 3.7.22 |
CRITICAL | 9.8 | Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus di… | — | wordfence |
| 6b5288db-8996-4363-bdc0-d3bdd2445e9f | CRITICAL | 9.8 | The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Remote Code Exec… | — | wordfence | |
| 6b48cae6-254c-4882-a464-3a44a63cadf5 | < 3.16.12 |
CRITICAL | 9.8 | The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tab parameter… | — | wordfence |
| 6b456815-ffdf-41fb-b4a8-0f22fd059d34 | CRITICAL | 9.8 | The AJAX Store Locator plugin for WordPress is vulnerable to SQL Injection via the ‘StoreLocation’ parameter in vers… | — | wordfence | |
| 6b443610-416c-41d6-9449-9e20f719af06 | CRITICAL | 9.8 | The Contus Video Gallery plugin for WordPress is vulnerable to Arbitrary File Upload due to missing file type validation… | — | wordfence | |
| 6b431493-fd96-495b-aaa7-6dfeef04b011 | < 3.7.1 |
CRITICAL | 9.8 | The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement v… | — | wordfence |
| 6b26f41e-fab8-4fe4-b5ab-4c238a433eab | CRITICAL | 9.8 | The User registration & user profile – UserPlus plugin for WordPress is vulnerable to privilege escalation in all vers… | — | wordfence | |
| 6b15eca5-fd47-4f8f-8ade-3a90e0bfc110 | < 7.3.2 |
CRITICAL | 9.8 | The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, a… | — | wordfence |
| 6afbdac4-e52a-4ad3-a99a-2d75e698e0fc | < 2.9.3 |
CRITICAL | 9.8 | The JS Help Desk plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.9.2. Thi… | — | wordfence |
| 6aef6fbb-be8c-49e1-ada5-7b4aa8b2ff72 | < 1.3.2 |
CRITICAL | 9.8 | The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication B… | — | wordfence |
| 6aeb0352-66ab-45d4-ad61-f425d7d41f45 | CRITICAL | 9.8 | The Daily Edition theme for WordPress is vulnerable to SQL Injection via the ‘&id’ parameter in versions up to, and … | — | wordfence | |
| 6abbdecd-782a-44a2-981a-ae6caa50dd6a | CRITICAL | 9.8 | The Article analytics plugin for WordPress is vulnerable to SQL Injection via the 'p' parameter in all versions up to, a… | — | wordfence | |
| 6ab975b0-4216-46df-bf5e-91e403728e5b | < 1.5.4 |
CRITICAL | 9.8 | The wpDataTables plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… | — | wordfence |
| 6ab578cd-3a0b-43d3-aaa7-0a01f431a4e2 | < 4.2.5.8 |
CRITICAL | 9.8 | The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all ve… | — | wordfence |
| 6ab0d342-bfa7-4760-b839-37c3354414ca | CRITICAL | 9.8 | The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5… | — | wordfence | |
| 6a7e794b-aa0e-4db3-8999-c9c5134a4ded | CRITICAL | 9.8 | The eTemplates plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.2.1 due to insuff… | — | wordfence | |
| 6a60e2c3-4597-4b21-ad20-6a00e483fcf1 | < 16.6 |
CRITICAL | 9.8 | The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va… | — | wordfence |
| 6a4d5a40-2ec0-468e-bafb-a713629f6006 | < 4.51 |
CRITICAL | 9.8 | The Webcam Video Conference plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… | — | wordfence |
| 6a0be61b-a1ee-499f-b991-58d5494bce18 | < 1.0.1 |
CRITICAL | 9.8 | The Zendrop – Global Dropshipping plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and … | — | wordfence |
| 6a050764-0ba6-49a4-bd71-f79e3129fc4c | < 2.9.9 |
CRITICAL | 9.8 | The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to mis… | — | wordfence |
| 6a04e6ad-9365-4cb5-a0a0-82e047647d6b | < 4.2.9 |
CRITICAL | 9.8 | The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modi… | — | wordfence |
| 69b2f126-8f57-4bea-b0e9-14b4566ac470 | < 2.0.3 |
CRITICAL | 9.8 | The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection via the 'orderby' and 'order' parameters. | — | wordfence |
| 6989e54b-ce5e-4c79-bd0d-0f7978a4bd44 | < 4.6.1 |
CRITICAL | 9.8 | The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?pag… | — | wordfence |
| 6980248b-195d-4e03-853e-a767a9a4b513 | CRITICAL | 9.8 | The Partners plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.2.0 via dese… | — | wordfence | |
| 6980112b-a555-47a4-b2d7-f0187d52fc63 | < 1.2.4 |
CRITICAL | 9.8 | The Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →