Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 69 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 5fdd2919-396b-41ff-ae92-1b6fee5c6f5e | < 2.4.1 |
CRITICAL | 9.8 | The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any a… | — | wordfence |
| 5fa37909-932c-4879-bbf0-8b44cc995cc0 | < 1.7.0 |
CRITICAL | 9.8 | The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8… | — | wordfence |
| 5f98f4b3-8cce-45dd-a138-5f2c8031fab5 | < 2.9.2 |
CRITICAL | 9.8 | The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allo… | — | wordfence |
| 5f4d613d-f040-4b92-8192-483e66fac5fd | < 1.3.6 |
CRITICAL | 9.8 | The Oxpitan theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.5. This make… | — | wordfence |
| 5f3b0e75-d2f0-48b7-ba33-75c4e998030e | < 6.3-revision-1 |
CRITICAL | 9.8 | The WHMpress - WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local File Inclusion in all vers… | — | wordfence |
| 5f1700c2-9c1f-4882-9f11-13b4ee8477a9 | CRITICAL | 9.8 | The WP Shop plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on it's ajax fu… | — | wordfence | |
| 5ea26b4c-598b-486e-a19b-0bb83774239d | < 2.8 |
CRITICAL | 9.8 | The Happy Coders OTP Login for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up… | — | wordfence |
| 5e9d5c93-dcd7-450e-8c52-5c95fc5473d2 | CRITICAL | 9.8 | The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the db… | — | wordfence | |
| 5e999e0f-463c-4676-ad18-f4b467bc4bfc | < 4.1.8 |
CRITICAL | 9.8 | A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. … | — | wordfence |
| 5e90704e-1a0c-448c-9139-542927cfa4f8 | < 1.2.3 |
CRITICAL | 9.8 | PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordP… | — | wordfence |
| 5e491592-a17f-4789-8faa-d2a60b8ced70 | < 2.7.5 |
CRITICAL | 9.8 | The Download Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.7.4… | — | wordfence |
| 5e2bf4a8-1dca-47fb-8164-acca0b2cf4f2 | < 2.0.3.2 |
CRITICAL | 9.8 | The Wholesale Lead Capture Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to mi… | — | wordfence |
| 5e29b10e-81d5-4247-bfe8-2400bcd9aef9 | < 3.1.6 |
CRITICAL | 9.8 | LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection. | — | wordfence |
| 5e24feac-1812-45d7-b3c3-27787eed1cf1 | CRITICAL | 9.8 | The CE21 Suite plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability che… | — | wordfence | |
| 5e15e36e-55f9-4095-a0ba-48ef9434606a | < 2.2.6 |
CRITICAL | 9.8 | The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass… | — | wordfence |
| 5e0ce0dc-34eb-4577-82a5-8ed822847ff4 | < 1.4.6.1 |
CRITICAL | 9.8 | The WPS Limit Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.4.6.… | — | wordfence |
| 5e0bcf70-2ffc-45c8-b63e-a8376b6cd22b | < 2.33 |
CRITICAL | 9.8 | The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.31 via de… | — | wordfence |
| 5e0116d6-91c3-4212-9c68-6b706ab09768 | < 1.8.6 |
CRITICAL | 9.8 | The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injecti… | — | wordfence |
| 5dfc2249-3761-49c6-966e-73c33be74c0e | < 5.9.0 |
CRITICAL | 9.8 | The PGS Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.8.0 via … | — | wordfence |
| 5dfa4ddf-bbe7-49b1-8b0d-c030ae81d0e8 | < 0.4 |
CRITICAL | 9.8 | The Visitors Online by BestWebSoft plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and in… | — | wordfence |
| 5de56a2e-f8e2-47d9-8a2b-989de640f018 | < 1.4.4 |
CRITICAL | 9.8 | SQL injection vulnerability in ajax_comments.php in the WP Comment Remix plugin before 1.4.4 for WordPress allows remote… | — | wordfence |
| 5dc8feae-fc89-4152-b9b2-2b70e6ccb30b | < 2.4.0 |
CRITICAL | 9.8 | The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence |
| 5dc72d78-d47c-4b36-8d69-8672e15ddf8c | < 3.15.3 |
CRITICAL | 9.8 | The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP F… | — | wordfence |
| 5d875004-a589-4657-953c-ca175e3157c2 | < 2.8.4 |
CRITICAL | 9.8 | The Travel Booking WordPress Theme for WordPress is vulnerable to blind SQL Injection via the ‘location_id’ paramete… | — | wordfence |
| 5d84d749-0ab5-49dd-8e4f-45681f197742 | < 3.12.8 |
CRITICAL | 9.8 | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →