Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 70 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 5d7b75a4-67b4-4347-91a6-dbf98da5ceaf | CRITICAL | 9.8 | The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Res… | — | wordfence | |
| 5d5c553f-247d-4feb-8027-822cfaca4adf | < 2.4 |
CRITICAL | 9.8 | The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to mis… | — | wordfence |
| 5d371a8e-2997-4be3-afd9-60f752a6721c | < 5.2.7 |
CRITICAL | 9.8 | The OMGF Pro plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 5… | — | wordfence |
| 5d07d5e9-be7c-4c16-b931-d909ed8be361 | < 1.11.4 |
CRITICAL | 9.8 | The Login with WHMCS plugin for WordPress is vulnerable to authentication bypass in versions up to, and including 1.11.3… | — | wordfence |
| 5ce4b3cf-1c36-4596-b113-055945fceeb6 | < 1.6.10 |
CRITICAL | 9.8 | The Pix 4x sem juros - Pagaleve plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includ… | — | wordfence |
| 5ca1c55a-cd4e-429a-ab74-dd1bad1a65f5 | < 3.1.5 |
CRITICAL | 9.8 | The SupportCandy plugin for WordPress is vulnerable to SQL injection via the 'parse_user_filters' function in versions u… | — | wordfence |
| 5c9a23a3-5eb5-4f5b-bf32-c9d163426f29 | < 5.0.12 |
CRITICAL | 9.8 | The LatePoint plugin for WordPress is vulnerable to Arbitrary User Password Change via SQL Injection in versions up to, … | — | wordfence |
| 5c9320f9-2e1a-4d76-850b-fa6fb68cd09f | CRITICAL | 9.8 | The Realty Workstation plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including,… | — | wordfence | |
| 5c79d861-e2e8-4fca-883f-79401544b0b1 | CRITICAL | 9.8 | The RLSWordPressSearch plugin for WordPress is vulnerable to generic SQL Injection via the 'agentid' parameter in the 'r… | — | wordfence | |
| 5c75c156-225c-465a-8d03-35a6669e9c04 | < 1.0.12 |
CRITICAL | 9.8 | The Calculated Fields Form plugin for WordPress is vulnerable to SQL Injection via Cross-Site Request Forgery in version… | — | wordfence |
| 5c601f75-3ee2-47ed-8d67-67fac4403a5d | CRITICAL | 9.8 | The JSON Options plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.0.4… | — | wordfence | |
| 5c42a966-0035-4c12-8aa1-226a0157d98f | < 3.8.9.1 |
CRITICAL | 9.8 | The WP eCommerce plugin for WordPress is vulnerable to generic SQL Injection via the ‘view_purchlogs_by_status’ para… | — | wordfence |
| 5c024c77-31a8-45b8-9fcb-7ba729bec32c | CRITICAL | 9.8 | The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter. | — | wordfence | |
| 5bf6d60f-57ac-4cbc-895f-a7db548cbf67 | < 1.2.0 |
CRITICAL | 9.8 | The Api2Cart Bridge Connector plugin for WordPress is vulnerable to arbitrary file uploads due to missing or incorrect f… | — | wordfence |
| 5bef5bd3-8ec9-4a5b-bcdd-98952c7ef390 | < 3.16.1 |
CRITICAL | 9.8 | The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the … | — | wordfence |
| 5bde312b-abbb-4e8e-91c6-a42dadbaedb5 | < 14.4.5 |
CRITICAL | 9.8 | The StoreKeeper for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va… | — | wordfence |
| 5b7c8a73-92da-4d2f-a37c-2ac380e56c5f | CRITICAL | 9.8 | The Energia - Renewable Energy WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to missin… | — | wordfence | |
| 5b75c322-539d-44e9-8f26-5ff929874b67 | < 1.2.6 |
CRITICAL | 9.8 | The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.… | — | wordfence |
| 5b67a9ce-44ad-4438-a545-84ca69e2ef47 | < 1.0.7 |
CRITICAL | 9.8 | The Fable Extra plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.6. This… | — | wordfence |
| 5b5ae0ae-1272-4bac-867f-4ff84155799e | < 1.0.8 |
CRITICAL | 9.8 | The HAPPY – Helpdesk Support Ticket System plugin for WordPress is vulnerable to Remote Code Execution in all versions… | — | wordfence |
| 5b546d24-82c1-4598-8926-6e73a4784b38 | < 4.6.6 |
CRITICAL | 9.8 | The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation… | — | wordfence |
| 5b53fa6f-7fb8-4643-a365-7630102e7e46 | < 1.4.7 |
CRITICAL | 9.8 | The BigContact Contact Page plugin for WordPress is vulnerable to SQL Injection via several parameters in versions befor… | — | wordfence |
| 5b39be2a-0769-4f3e-885f-a534682670ad | CRITICAL | 9.8 | The WPCHURCH plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7.0. This ma… | — | wordfence | |
| 5b07ea6a-511d-44ab-b0b7-5124702ad47d | < 3.9.1 |
CRITICAL | 9.8 | The Login as User or Customer plugin for WordPress is vulnerable to authentication bypass in all versions up to, and inc… | — | wordfence |
| 5b00cf9b-60c3-44a4-98a7-ee0f3e763c87 | < 3.4.11 |
CRITICAL | 9.8 | The Sunshine Photo Cart plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.4… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →