Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 66 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 5e2bf4a8-1dca-47fb-8164-acca0b2cf4f2 | < 2.0.3.2 |
CRITICAL | 9.8 | The Wholesale Lead Capture Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to mi… | — | wordfence |
| 5e29b10e-81d5-4247-bfe8-2400bcd9aef9 | < 3.1.6 |
CRITICAL | 9.8 | LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection. | — | wordfence |
| 5e24feac-1812-45d7-b3c3-27787eed1cf1 | CRITICAL | 9.8 | The CE21 Suite plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability che… | — | wordfence | |
| 5e15e36e-55f9-4095-a0ba-48ef9434606a | < 2.2.6 |
CRITICAL | 9.8 | The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass… | — | wordfence |
| 5e0ce0dc-34eb-4577-82a5-8ed822847ff4 | < 1.4.6.1 |
CRITICAL | 9.8 | The WPS Limit Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.4.6.… | — | wordfence |
| 5e0bcf70-2ffc-45c8-b63e-a8376b6cd22b | < 2.33 |
CRITICAL | 9.8 | The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.31 via de… | — | wordfence |
| 5dfc2249-3761-49c6-966e-73c33be74c0e | < 5.9.0 |
CRITICAL | 9.8 | The PGS Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.8.0 via … | — | wordfence |
| 5dfa4ddf-bbe7-49b1-8b0d-c030ae81d0e8 | < 0.4 |
CRITICAL | 9.8 | The Visitors Online by BestWebSoft plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and in… | — | wordfence |
| 5de56a2e-f8e2-47d9-8a2b-989de640f018 | < 1.4.4 |
CRITICAL | 9.8 | SQL injection vulnerability in ajax_comments.php in the WP Comment Remix plugin before 1.4.4 for WordPress allows remote… | — | wordfence |
| 5dc8feae-fc89-4152-b9b2-2b70e6ccb30b | CRITICAL | 9.8 | The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence | |
| 5dc72d78-d47c-4b36-8d69-8672e15ddf8c | < 3.15.3 |
CRITICAL | 9.8 | The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP F… | — | wordfence |
| 5d875004-a589-4657-953c-ca175e3157c2 | < 2.8.4 |
CRITICAL | 9.8 | The Travel Booking WordPress Theme for WordPress is vulnerable to blind SQL Injection via the ‘location_id’ paramete… | — | wordfence |
| 5d84d749-0ab5-49dd-8e4f-45681f197742 | < 3.12.8 |
CRITICAL | 9.8 | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to … | — | wordfence |
| 5d7b75a4-67b4-4347-91a6-dbf98da5ceaf | CRITICAL | 9.8 | The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Res… | — | wordfence | |
| 5d5c553f-247d-4feb-8027-822cfaca4adf | < 2.4 |
CRITICAL | 9.8 | The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to mis… | — | wordfence |
| 5d371a8e-2997-4be3-afd9-60f752a6721c | < 5.2.7 |
CRITICAL | 9.8 | The OMGF Pro plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 5… | — | wordfence |
| 5d07d5e9-be7c-4c16-b931-d909ed8be361 | < 1.11.4 |
CRITICAL | 9.8 | The Login with WHMCS plugin for WordPress is vulnerable to authentication bypass in versions up to, and including 1.11.3… | — | wordfence |
| 5ce4b3cf-1c36-4596-b113-055945fceeb6 | < 1.6.10 |
CRITICAL | 9.8 | The Pix 4x sem juros - Pagaleve plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includ… | — | wordfence |
| 5ca1c55a-cd4e-429a-ab74-dd1bad1a65f5 | < 3.1.5 |
CRITICAL | 9.8 | The SupportCandy plugin for WordPress is vulnerable to SQL injection via the 'parse_user_filters' function in versions u… | — | wordfence |
| 5c9a23a3-5eb5-4f5b-bf32-c9d163426f29 | < 5.0.12 |
CRITICAL | 9.8 | The LatePoint plugin for WordPress is vulnerable to Arbitrary User Password Change via SQL Injection in versions up to, … | — | wordfence |
| 5c9320f9-2e1a-4d76-850b-fa6fb68cd09f | CRITICAL | 9.8 | The Realty Workstation plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including,… | — | wordfence | |
| 5c79d861-e2e8-4fca-883f-79401544b0b1 | CRITICAL | 9.8 | The RLSWordPressSearch plugin for WordPress is vulnerable to generic SQL Injection via the 'agentid' parameter in the 'r… | — | wordfence | |
| 5c75c156-225c-465a-8d03-35a6669e9c04 | < 1.0.12 |
CRITICAL | 9.8 | The Calculated Fields Form plugin for WordPress is vulnerable to SQL Injection via Cross-Site Request Forgery in version… | — | wordfence |
| 5c42a966-0035-4c12-8aa1-226a0157d98f | < 3.8.9.1 |
CRITICAL | 9.8 | The WP eCommerce plugin for WordPress is vulnerable to generic SQL Injection via the ‘view_purchlogs_by_status’ para… | — | wordfence |
| 5c024c77-31a8-45b8-9fcb-7ba729bec32c | CRITICAL | 9.8 | The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter. | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →