Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,409 vulnerabilities found (page 67 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 5bf6d60f-57ac-4cbc-895f-a7db548cbf67 | < 1.2.0 |
CRITICAL | 9.8 | The Api2Cart Bridge Connector plugin for WordPress is vulnerable to arbitrary file uploads due to missing or incorrect f… | — | wordfence |
| 5bde312b-abbb-4e8e-91c6-a42dadbaedb5 | < 14.4.5 |
CRITICAL | 9.8 | The StoreKeeper for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va… | — | wordfence |
| 5b7c8a73-92da-4d2f-a37c-2ac380e56c5f | CRITICAL | 9.8 | The Energia - Renewable Energy WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to missin… | — | wordfence | |
| 5b75c322-539d-44e9-8f26-5ff929874b67 | < 1.2.6 |
CRITICAL | 9.8 | The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.… | — | wordfence |
| 5b67a9ce-44ad-4438-a545-84ca69e2ef47 | < 1.0.7 |
CRITICAL | 9.8 | The Fable Extra plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.6. This… | — | wordfence |
| 5b5ae0ae-1272-4bac-867f-4ff84155799e | < 1.0.8 |
CRITICAL | 9.8 | The HAPPY β Helpdesk Support Ticket System plugin for WordPress is vulnerable to Remote Code Execution in all versions… | — | wordfence |
| 5b546d24-82c1-4598-8926-6e73a4784b38 | < 4.6.6 |
CRITICAL | 9.8 | The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation… | — | wordfence |
| 5b53fa6f-7fb8-4643-a365-7630102e7e46 | < 1.4.7 |
CRITICAL | 9.8 | The BigContact Contact Page plugin for WordPress is vulnerable to SQL Injection via several parameters in versions befor… | — | wordfence |
| 5b39be2a-0769-4f3e-885f-a534682670ad | CRITICAL | 9.8 | The WPCHURCH plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7.0. This ma… | — | wordfence | |
| 5b07ea6a-511d-44ab-b0b7-5124702ad47d | < 3.9.1 |
CRITICAL | 9.8 | The Login as User or Customer plugin for WordPress is vulnerable to authentication bypass in all versions up to, and inc… | — | wordfence |
| 5b00cf9b-60c3-44a4-98a7-ee0f3e763c87 | < 3.4.11 |
CRITICAL | 9.8 | The Sunshine Photo Cart plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.4… | — | wordfence |
| 5ad12146-200b-48e5-82de-7572541edcc4 | < 4.9.1 |
CRITICAL | 9.8 | The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and includin… | — | wordfence |
| 5ab2c74d-b83b-40ea-951c-83aeb76a7515 | CRITICAL | 9.8 | The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass… | — | wordfence | |
| 5a97877b-fb4d-4e87-bcff-56be65fee6ce | < 20190426 |
CRITICAL | 9.8 | The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… | — | wordfence |
| 5a7f869d-e915-4048-b0e1-36cf25e732f9 | CRITICAL | 9.8 | The Audio Record plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… | — | wordfence | |
| 5a5f31ad-75f9-4534-a8a6-e76f9aefbd80 | CRITICAL | 9.8 | The Hospital Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing… | — | wordfence | |
| 5a5d5dbd-36f0-4886-adf8-045ec9c2e306 | < 3.6 |
CRITICAL | 9.8 | The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence |
| 59be1fc7-2854-404d-8e9d-dd9bd26e6a2c | < 3.11 |
CRITICAL | 9.8 | The Rencontre β Dating Site plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and in… | — | wordfence |
| 59aebe74-cf53-49f4-8f20-ebb5503d7dbd | < 5.9.9.7 |
CRITICAL | 9.8 | The ProfileGrid β User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via… | — | wordfence |
| 59a645e4-2a23-4440-a463-fa197dfa20b2 | CRITICAL | 9.8 | The WA Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the βwa_forms_Idβ parameter in v… | — | wordfence | |
| 59a05868-7457-4fb1-845e-bf7044d5cb81 | < 2.2.2 |
CRITICAL | 9.8 | The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader… | — | wordfence |
| 599c6984-5d52-4d0f-86a1-b88f6c9797ed | < 2.2.8 |
CRITICAL | 9.8 | The Buddyforms plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.2.7 due to insuff… | — | wordfence |
| 598fffcd-0318-4e41-8837-f65761390c19 | < 3.1.5 |
CRITICAL | 9.8 | The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers. | — | wordfence |
| 595fac73-c583-4712-ad37-fbd0fa3eb147 | < 1.3.6 |
CRITICAL | 9.8 | SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header. | — | wordfence |
| 5933fc11-8f06-4d58-9483-d06997e5d731 | < 0.3.0.04 |
CRITICAL | 9.8 | The Filebase Download Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includi… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →