Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,403 vulnerabilities found (page 7 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 3ca6605f-7c9c-43c7-ae32-ca1d781c1e86 | < 3.15 |
CRITICAL | 9.9 | The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal perm… | — | wordfence |
| 3b472eb8-9808-4a50-b2b4-0b0b3256053f | < 7.4.2 |
CRITICAL | 9.9 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSort… | — | wordfence |
| 3b4012dd-7c0a-45f1-8ada-8f9dc6867e1e | < 1.2.2 |
CRITICAL | 9.9 | The mFolio Lite plugin for WordPress is vulnerable to file uploads due to a missing capability check in all versions up … | — | wordfence |
| 38a405f2-344c-4ee1-a67e-5f6afad66b84 | CRITICAL | 9.9 | The Visual Slide Box Builder WordPress plugin through 3.2.9 does not sanitise and escape various parameters before using… | — | wordfence | |
| 381ea693-3e59-4ecb-a96b-4b58d47298c0 | < 15.5.9 |
CRITICAL | 9.9 | The Calendarista plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 15.5.7 due to… | — | wordfence |
| 37b9ed0e-5af2-47c1-b2da-8d103e4c31bf | < 4.3.1 |
CRITICAL | 9.9 | The OpenHook plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.3.0 via the… | — | wordfence |
| 2f0c85f4-07ae-4a2b-bd82-93467e7d9325 | < 2.6.5 |
CRITICAL | 9.9 | The Brizy β Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… | — | wordfence |
| 2d3150b3-fba1-4e89-8f4e-b6c605227395 | < 21.3.2.1 |
CRITICAL | 9.9 | The Photos and Files Contest Gallery β Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordP… | — | wordfence |
| 2ae916a0-b0a8-4722-9d8a-3d1f163bc8e5 | < 10.1.76 |
CRITICAL | 9.9 | The WP Cost Estimation & Payment Forms Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, an… | — | wordfence |
| 29a2cb14-bf70-4936-a7c9-bf417a403de8 | < 7.3.8 |
CRITICAL | 9.9 | The Zotpress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.3.7 due to insuffic… | — | wordfence |
| 2923afdd-36b7-4181-aade-d757a70a06c0 | < 6.2.10 |
CRITICAL | 9.9 | The Advanced Custom Fields Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and including… | — | wordfence |
| 2912f693-c8fd-48f7-8030-5e1f0edd715f | < 1.1.9 |
CRITICAL | 9.9 | The Contact Form to Any API plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.… | — | wordfence |
| 28ecf168-c215-4fc3-8dd7-1ab84ae6b4a6 | < 3.0.9 |
CRITICAL | 9.9 | The Newspack Blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … | — | wordfence |
| 28e4cc53-53c3-47bf-8ea4-818040d10abd | < 6.9.8 |
CRITICAL | 9.9 | The Super Store Finder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.9.7 due t… | — | wordfence |
| 26e35c4a-79ec-4742-8004-1c799d2c56ff | < 2.12.3 |
CRITICAL | 9.9 | The Registrations for the Events Calendar β Event Registration Plugin plugin for WordPress is vulnerable to SQL Inject… | — | wordfence |
| 241dc2e4-b079-407b-b610-c40b23d038cb | < 4.6.0.4 |
CRITICAL | 9.9 | In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (wi… | — | wordfence |
| 1ffbff82-85ba-4f6f-b2de-9ba99003d981 | < 1.3.1 |
CRITICAL | 9.9 | The Consulting Elementor Widgets plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1… | — | wordfence |
| 198ad1bf-7ce1-4367-bef7-1f58113c0719 | < 8.1.8 |
CRITICAL | 9.9 | The Media Library Folders plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.1.7 du… | — | wordfence |
| 134ad095-b0a0-4f0f-832d-3e558d4a250a | < 2.5.1 |
CRITICAL | 9.9 | The Woody code snippets β Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Exe… | — | wordfence |
| 107c82fa-fcb1-40df-9c53-bc8f23810f2a | < 1.6.5 |
CRITICAL | 9.9 | The BA Book Everything plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.4 due t… | — | wordfence |
| 0b748dc9-4d44-41dd-b159-380214e7646a | < 1.5 |
CRITICAL | 9.9 | Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress al… | — | wordfence |
| 0aced5de-e9df-4ffe-9d10-93dc3897ef4c | < 5.5.4 |
CRITICAL | 9.9 | The Element Pack Elementor Addons plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … | — | wordfence |
| 0358d8f8-f7fd-487e-b75c-08e1cfdeeeec | CRITICAL | 9.9 | The Unite Gallery Lite plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.62 due … | — | wordfence | |
| ffff2ff3-769d-4eb2-acbe-d8ce6f042581 | CRITICAL | 9.8 | The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file typ… | — | wordfence | |
| ffeb4b5e-4c83-4b0e-a513-6b5cada95073 | < 3.0.0 |
CRITICAL | 9.8 | The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →