Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 68 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 6164c161-f764-4064-8139-609caad82204 | CRITICAL | 9.8 | Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slidesh… | — | wordfence | |
| 615d8b8f-037e-4741-bdb4-639daf690aff | CRITICAL | 9.8 | The The Novel Design Store Directory plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty… | — | wordfence | |
| 613f4bd1-e29a-4853-84a2-3e1437f06d33 | < 2.2.81 |
CRITICAL | 9.8 | The Events Made Easy plugin for WordPress is vulnerable to SQL Injection via the ‘lang’ parameter in versions up to,… | — | wordfence |
| 613f22f2-2f84-4d01-a1ea-c14a25843700 | < 2.0.6 |
CRITICAL | 9.8 | Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPre… | — | wordfence |
| 613f2035-3061-429b-b218-83805287e4f3 | < 3.28.21 |
CRITICAL | 9.8 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress … | — | wordfence |
| 613e1862-e0b7-4012-a77d-b5fb56cbbb9c | < 1.2.2 |
CRITICAL | 9.8 | The 360 Product Rotation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… | — | wordfence |
| 6130d49f-61b7-4b70-b1a5-036346f82650 | CRITICAL | 9.8 | The Baggage Freight Shipping Australia plugin for WordPress is vulnerable to arbitrary file uploads due to missing file … | — | wordfence | |
| 61080df6-836f-4365-964a-fa2517e8be5a | < 3.10.0 |
CRITICAL | 9.8 | The CozyStay and TinySalt plugins for WordPress are vulnerable to PHP Object Injection in all versions up to, and includ… | — | wordfence |
| 60f63cdc-9c19-4f6c-a555-519bdb61ce6d | < 1.6 |
CRITICAL | 9.8 | The RokMicroNews plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.5 due to… | — | wordfence |
| 60f043e9-7947-4fff-a9a8-94a1f421db7c | < 1.0.37 |
CRITICAL | 9.8 | The Woodmart Core plugin for WordPress is vulnerable to privilege escalation due to insufficient validation in its socia… | — | wordfence |
| 60dacb8d-0de6-4755-8857-6b05083a23b8 | < 1.4.3 |
CRITICAL | 9.8 | The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions u… | — | wordfence |
| 60a7cce0-637f-49bd-aa4a-fd7023d99a64 | < 1.6.3 |
CRITICAL | 9.8 | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover i… | — | wordfence |
| 608b0506-074b-4df3-8c30-57cfb090f553 | < 2.3.0 |
CRITICAL | 9.8 | The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its o… | — | wordfence |
| 607c20b1-f8da-4f3f-a070-abdae64c8fc8 | < 1.1.97 |
CRITICAL | 9.8 | The Image Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'image-slider-widget/trunk/inc/func… | — | wordfence |
| 6065ad75-1685-4f1d-9ba9-d4c8ec840521 | < 2022.6 |
CRITICAL | 9.8 | The Stop Spammers Security plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, … | — | wordfence |
| 60656eff-7851-4b6e-97f4-840c299b1e4e | < 3.8.0 |
CRITICAL | 9.8 | The WavePlayer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '… | — | wordfence |
| 60470d54-2105-4dc1-8e0c-670e8e22977a | CRITICAL | 9.8 | The DigiWidgets Image Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and incl… | — | wordfence | |
| 604249c6-b23a-40e9-984d-2014f5c97249 | < 0.8.0 |
CRITICAL | 9.8 | The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and… | — | wordfence |
| 60405e54-e869-4623-892c-0821014f887b | < 1.2 |
CRITICAL | 9.8 | The Alloggio Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including… | — | wordfence |
| 6031edec-4274-4e42-9e3a-ce0c94958b17 | < 9.2.6 |
CRITICAL | 9.8 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parame… | — | wordfence |
| 602e088e-57af-4b30-96c3-a44b2a8e4edb | CRITICAL | 9.8 | The Advanced Advertising System plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includ… | — | wordfence | |
| 60242725-200e-4794-acdc-2ab4a1e8e4fc | CRITICAL | 9.8 | SQL injection vulnerability in stnl_iframe.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows r… | — | wordfence | |
| 601e52b6-36eb-4739-9b04-db779befa899 | CRITICAL | 9.8 | The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in… | — | wordfence | |
| 601d70ff-2e0e-403b-9c58-130d378a8240 | < 1.7.1 |
CRITICAL | 9.8 | The WooCommerce Ninja Forms Product Add-ons plugin for WordPress is vulnerable to arbitrary file uploads due to missing … | — | wordfence |
| 600f38eb-3c13-4792-8079-944ea0238ad2 | CRITICAL | 9.8 | The Contact Page With Google Map plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →