Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 65 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 60a7cce0-637f-49bd-aa4a-fd7023d99a64 | < 1.6.3 |
CRITICAL | 9.8 | The Nokri β Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover i… | — | wordfence |
| 608b0506-074b-4df3-8c30-57cfb090f553 | < 2.3.0 |
CRITICAL | 9.8 | The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its o… | — | wordfence |
| 607c20b1-f8da-4f3f-a070-abdae64c8fc8 | < 1.1.97 |
CRITICAL | 9.8 | The Image Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'image-slider-widget/trunk/inc/func… | — | wordfence |
| 6065ad75-1685-4f1d-9ba9-d4c8ec840521 | < 2022.6 |
CRITICAL | 9.8 | The Stop Spammers Security plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, … | — | wordfence |
| 60656eff-7851-4b6e-97f4-840c299b1e4e | < 3.8.0 |
CRITICAL | 9.8 | The WavePlayer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '… | — | wordfence |
| 60470d54-2105-4dc1-8e0c-670e8e22977a | CRITICAL | 9.8 | The DigiWidgets Image Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and incl… | — | wordfence | |
| 604249c6-b23a-40e9-984d-2014f5c97249 | < 0.8.0 |
CRITICAL | 9.8 | The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and… | — | wordfence |
| 60405e54-e869-4623-892c-0821014f887b | < 1.2 |
CRITICAL | 9.8 | The Alloggio Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including… | — | wordfence |
| 6031edec-4274-4e42-9e3a-ce0c94958b17 | < 9.2.6 |
CRITICAL | 9.8 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parame… | — | wordfence |
| 602e088e-57af-4b30-96c3-a44b2a8e4edb | CRITICAL | 9.8 | The Advanced Advertising System plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includ… | — | wordfence | |
| 60242725-200e-4794-acdc-2ab4a1e8e4fc | CRITICAL | 9.8 | SQL injection vulnerability in stnl_iframe.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows r… | — | wordfence | |
| 601e52b6-36eb-4739-9b04-db779befa899 | CRITICAL | 9.8 | The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in… | — | wordfence | |
| 601d70ff-2e0e-403b-9c58-130d378a8240 | < 1.7.1 |
CRITICAL | 9.8 | The WooCommerce Ninja Forms Product Add-ons plugin for WordPress is vulnerable to arbitrary file uploads due to missing … | — | wordfence |
| 600f38eb-3c13-4792-8079-944ea0238ad2 | CRITICAL | 9.8 | The Contact Page With Google Map plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file … | — | wordfence | |
| 5fdd2919-396b-41ff-ae92-1b6fee5c6f5e | < 2.4.1 |
CRITICAL | 9.8 | The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any a… | — | wordfence |
| 5fa37909-932c-4879-bbf0-8b44cc995cc0 | < 1.7.0 |
CRITICAL | 9.8 | The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8… | — | wordfence |
| 5f98f4b3-8cce-45dd-a138-5f2c8031fab5 | < 2.9.2 |
CRITICAL | 9.8 | The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allo… | — | wordfence |
| 5f4d613d-f040-4b92-8192-483e66fac5fd | < 1.3.6 |
CRITICAL | 9.8 | The Oxpitan theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.5. This make… | — | wordfence |
| 5f3b0e75-d2f0-48b7-ba33-75c4e998030e | < 6.3-revision-1 |
CRITICAL | 9.8 | The WHMpress - WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local File Inclusion in all vers… | — | wordfence |
| 5f1700c2-9c1f-4882-9f11-13b4ee8477a9 | CRITICAL | 9.8 | The WP Shop plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on it's ajax fu… | — | wordfence | |
| 5ea26b4c-598b-486e-a19b-0bb83774239d | < 2.8 |
CRITICAL | 9.8 | The Happy Coders OTP Login for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up… | — | wordfence |
| 5e9d5c93-dcd7-450e-8c52-5c95fc5473d2 | CRITICAL | 9.8 | The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the db… | — | wordfence | |
| 5e999e0f-463c-4676-ad18-f4b467bc4bfc | < 4.1.8 |
CRITICAL | 9.8 | A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. … | — | wordfence |
| 5e90704e-1a0c-448c-9139-542927cfa4f8 | < 1.2.3 |
CRITICAL | 9.8 | PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordP… | — | wordfence |
| 5e491592-a17f-4789-8faa-d2a60b8ced70 | < 2.7.5 |
CRITICAL | 9.8 | The Download Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.7.4… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →