Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
39,406 vulnerabilities found (page 70 of 1577)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 5391ad0a-a5c7-4fd8-b94e-9236cca41568 | CRITICAL | 9.8 | The JS Job Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in a… | — | wordfence | |
| 535f9f16-a7fc-40fe-8be1-90c542675cc4 | CRITICAL | 9.8 | The Woolook plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.0. This mak… | — | wordfence | |
| 53580b24-c0a7-4578-bb11-5952ebcacc42 | CRITICAL | 9.8 | The UltimateWoo plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.1.10 via … | — | wordfence | |
| 531e6da9-a24c-4b75-b909-ec4614075044 | CRITICAL | 9.8 | The PIMP theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7 via deseria… | — | wordfence | |
| 531d57c4-404a-475e-842a-08425959e150 | CRITICAL | 9.8 | The vBSSO-lite plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an… | — | wordfence | |
| 52db8d41-859a-4d68-8b83-3d3af8f1bf64 | < 1.2.6 |
CRITICAL | 9.8 | The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on severa… | — | wordfence |
| 52d05693-469f-4fd9-800a-d8b9b94760fb | CRITICAL | 9.8 | The WooCommerce Designer Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… | — | wordfence | |
| 52c19707-df18-4239-af46-12ea5ee86a4b | < 4.03.33 |
CRITICAL | 9.8 | The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin … | — | wordfence |
| 529c5785-214e-41e7-8cf3-4ff3d256e27c | CRITICAL | 9.8 | SQL injection vulnerability in wp-comments-post.php in the NOSpam PTI plugin 2.1 for WordPress allows remote attackers t… | — | wordfence | |
| 5284aef6-8fcd-4a75-a189-b2223bb83b60 | CRITICAL | 9.8 | The CBX Poll plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.7 via dese… | — | wordfence | |
| 525b466d-137a-467b-8b49-e51393a73866 | CRITICAL | 9.8 | The Kento Post View Counter plugin for WordPress is vulnerable to SQL Injection via the 'kento_pvc_geo' parameter in ver… | — | wordfence | |
| 523b5dd3-eb73-4156-ad2b-4d532e8d40f3 | < 2.6.60 |
CRITICAL | 9.8 | The Datalogics Ecommerce Delivery β Datalogics plugin for WordPress is vulnerable to privilege escalation in all versi… | — | wordfence |
| 522ecc1c-5834-4325-9234-79cf712213f3 | < 1.7.0.13 |
CRITICAL | 9.8 | The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and inclu… | — | wordfence |
| 5228221f-b0b4-4faf-bde6-07666a96a278 | < 3.6.3 |
CRITICAL | 9.8 | The Order Notification for WooCommerce β Get Audio Alert on new Orders plugin for WordPress is vulnerable to Remote Co… | — | wordfence |
| 521b1786-3527-4b4e-b1c4-ff4fbfed8107 | CRITICAL | 9.8 | The My Reading Library plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0 … | — | wordfence | |
| 52198053-206c-4002-8e26-dd5b4850e151 | < 1.6.30 |
CRITICAL | 9.8 | The SalesKing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.15. This … | — | wordfence |
| 520c1e8b-d0c1-4201-90bf-0cefab9af7e0 | CRITICAL | 9.8 | The Service Finder SMS System plugin for WordPress is vulnerable to privilege escalation via account takeover in all ver… | — | wordfence | |
| 5205fcde-2e6c-49de-b132-1ebefcd1ba59 | < 1.4.4 |
CRITICAL | 9.8 | Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote att… | — | wordfence |
| 51fc7d47-2a0f-4713-9859-120321aa32dc | < 3.3.7 |
CRITICAL | 9.8 | The DWT - Directory & Listing WordPress Theme theme for WordPress is vulnerable to privilege escalation via account take… | — | wordfence |
| 51f73041-927d-42da-92cc-14242a397356 | CRITICAL | 9.8 | The Email posts to subscribers plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.2… | — | wordfence | |
| 51d3c250-301c-4f91-9fe5-56879a65fde7 | CRITICAL | 9.8 | Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin… | — | wordfence | |
| 51957ee1-a423-485b-8cfd-8eafaf6744e4 | < 4.9.17.1 |
CRITICAL | 9.8 | The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers… | — | wordfence |
| 5183d676-eb91-4c03-8d12-c15c68839f02 | < 4.02 |
CRITICAL | 9.8 | The SEMA API WordPress plugin through 3.64 does not properly sanitise and escape some parameters before using them in SQ… | — | wordfence |
| 515d6e6c-e20d-4fc4-9c56-80020196f2f0 | < 1.7.2 |
CRITICAL | 9.8 | PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows re… | — | wordfence |
| 51424768-27c7-40b2-8d1c-838c419add8a | < 3.12 |
CRITICAL | 9.8 | SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execut… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →