Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 66 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 66969472-4b3c-4d56-b761-523ea854e3db | < 1.5.8 |
CRITICAL | 9.8 | The Leaflet Maps Marker Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… | — | wordfence |
| 668ba3a9-d53c-45ab-854f-1a9e83dd54b8 | < 1.6.7 |
CRITICAL | 9.8 | The WP e-Commerce β Store Exporter plugin for WordPress is vulnerable to authorization bypass due to a missing capabil… | — | wordfence |
| 6687ebbe-fdf4-4ecb-bf59-034bb4b0104c | < 3.5.1 |
CRITICAL | 9.8 | The Academy LMS β WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege… | — | wordfence |
| 66845165-02c7-4f4a-93fd-1a309fb7b386 | CRITICAL | 9.8 | The CAFEHAUS API plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, … | — | wordfence | |
| 66749606-e76f-41fb-bcf1-c06681de2ee3 | CRITICAL | 9.8 | The Master Slider Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3… | — | wordfence | |
| 664e6e2a-faa1-4609-b250-d7e94c5d5a04 | < 1.6.3 |
CRITICAL | 9.8 | The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… | — | wordfence |
| 6629e1a9-3b28-4c8c-95d4-3c0011a7364a | < 2.1.5 |
CRITICAL | 9.8 | An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_no… | — | wordfence |
| 661d4ea9-572d-4544-b5cf-39fd69c104a6 | < 3.9.8 |
CRITICAL | 9.8 | The SMS Alert β SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulne… | — | wordfence |
| 65fc2929-b65b-451b-b90d-6739a673ac16 | CRITICAL | 9.8 | The MBStore - Digital WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versions … | — | wordfence | |
| 65ebc744-6cc2-47ce-b225-81820e49d59c | < 1.6.0 |
CRITICAL | 9.8 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versio… | — | wordfence |
| 65e2e9e3-2778-4baf-8269-fc13d5ef1212 | < 2.7.2 |
CRITICAL | 9.8 | The JS Help Desk plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 2.7.1. T… | — | wordfence |
| 65c3ca36-79e6-47f8-9524-27e7631f4caf | < 3.21.1 |
CRITICAL | 9.8 | The Hummingbird β Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Cod… | — | wordfence |
| 65be9417-7029-4f34-b834-98208a42743b | < 8.0.0 |
CRITICAL | 9.8 | The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Authentication Bypass in versions 1.9.1 to… | — | wordfence |
| 65988550-d39d-40be-8d25-647e7237062d | < 6.1.1 |
CRITICAL | 9.8 | The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all ver… | — | wordfence |
| 657f3bd7-2cdc-4eb6-ba50-7c7fca468df0 | < 5.0.13 |
CRITICAL | 9.8 | The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and… | — | wordfence |
| 65386d2b-5d0c-4e49-a79a-a793b4b599e0 | CRITICAL | 9.8 | The FW Food Menu β Responsive food menu with ordering & delivery solutions plugin for WordPress is vulnerable to arbit… | — | wordfence | |
| 651aa149-0968-4916-b260-067d32193d83 | CRITICAL | 9.8 | The DoLeads Integrator plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.2… | — | wordfence | |
| 65192fdb-86db-475a-8c61-4db922920cfe | < 250214 |
CRITICAL | 9.8 | The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216… | — | wordfence |
| 65166432-a877-4070-94c1-cdaf7e5d7586 | < 1.5.99 |
CRITICAL | 9.8 | The Booking Package plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including 1.5.98 d… | — | wordfence |
| 64eb4bfe-09b4-43c7-9d7e-f14fc5edf3c1 | < 6.90 |
CRITICAL | 9.8 | The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in … | — | wordfence |
| 64e806df-4919-4a58-8f21-075f09668174 | < 1.0.73 |
CRITICAL | 9.8 | The 10Web Map Builder for Google Maps plugin for WordPress is vulnerable to generic SQL Injection via the multiple param… | — | wordfence |
| 64e125c7-3f1e-43ed-8655-e0fbb95bc84b | CRITICAL | 9.8 | The "CStar Design WordPress Theme" theme for WordPress is vulnerable to SQL Injection via the βidβ parameter in vers… | — | wordfence | |
| 6494e54c-db04-41f9-8b91-6ad12528cf01 | < 3.1.17 |
CRITICAL | 9.8 | The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin… | — | wordfence |
| 647cc71d-4d3a-4722-b498-baaee2450809 | < 10.6.7 |
CRITICAL | 9.8 | The RSVPMaker plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 10.6.6 via de… | — | wordfence |
| 647a2f27-092a-4db1-932d-87ae8c2efcca | CRITICAL | 9.8 | The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →