Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
41,761 vulnerabilities found (page 71 of 1671)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 5ad12146-200b-48e5-82de-7572541edcc4 | < 4.9.1 |
CRITICAL | 9.8 | The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and includin… | — | wordfence |
| 5ab2c74d-b83b-40ea-951c-83aeb76a7515 | CRITICAL | 9.8 | The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass… | — | wordfence | |
| 5a97877b-fb4d-4e87-bcff-56be65fee6ce | < 20190426 |
CRITICAL | 9.8 | The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… | — | wordfence |
| 5a7f869d-e915-4048-b0e1-36cf25e732f9 | CRITICAL | 9.8 | The Audio Record plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… | — | wordfence | |
| 5a5f31ad-75f9-4534-a8a6-e76f9aefbd80 | CRITICAL | 9.8 | The Hospital Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing… | — | wordfence | |
| 5a5d5dbd-36f0-4886-adf8-045ec9c2e306 | < 3.6 |
CRITICAL | 9.8 | The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence |
| 5a0612de-0f85-44d3-9b81-1a6a7720a03a | < 7.20.01 |
CRITICAL | 9.8 | The WP Compress β Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Remote Code Execution… | — | wordfence |
| 59be1fc7-2854-404d-8e9d-dd9bd26e6a2c | < 3.11 |
CRITICAL | 9.8 | The Rencontre β Dating Site plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and in… | — | wordfence |
| 59aebe74-cf53-49f4-8f20-ebb5503d7dbd | < 5.9.9.7 |
CRITICAL | 9.8 | The ProfileGrid β User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via… | — | wordfence |
| 59a645e4-2a23-4440-a463-fa197dfa20b2 | CRITICAL | 9.8 | The WA Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the βwa_forms_Idβ parameter in v… | — | wordfence | |
| 59a05868-7457-4fb1-845e-bf7044d5cb81 | < 2.2.2 |
CRITICAL | 9.8 | The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader… | — | wordfence |
| 599c6984-5d52-4d0f-86a1-b88f6c9797ed | < 2.2.8 |
CRITICAL | 9.8 | The Buddyforms plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.2.7 due to insuff… | — | wordfence |
| 598fffcd-0318-4e41-8837-f65761390c19 | < 3.1.5 |
CRITICAL | 9.8 | The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers. | — | wordfence |
| 595fac73-c583-4712-ad37-fbd0fa3eb147 | < 1.3.6 |
CRITICAL | 9.8 | SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header. | — | wordfence |
| 5933fc11-8f06-4d58-9483-d06997e5d731 | < 0.3.0.04 |
CRITICAL | 9.8 | The Filebase Download Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includi… | — | wordfence |
| 58f8bba4-1be5-4111-aa41-d076a6f06948 | < 1.6.4 |
CRITICAL | 9.8 | The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_fa… | — | wordfence |
| 58ea0c9c-f63d-4c31-b02e-a86d5fe732aa | CRITICAL | 9.8 | The Flash News Theme for WordPress is vulnerable to Cross-Site Scripting in all versions due to inclusion of a vulnerabl… | — | wordfence | |
| 58bd4a75-8e24-4810-8b9d-c9ffad1c2208 | < 1.5 |
CRITICAL | 9.8 | The WP Donate plugin for WordPress is vulnerable to SQL Injection in donate-display.php in versions up to, and including… | — | wordfence |
| 589fa6f2-fa60-4bdc-9692-50d5591ceb93 | CRITICAL | 9.8 | The FlipBook plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /fl… | — | wordfence | |
| 588ece40-a848-4b2c-9db5-e63e0d11dda0 | < 2.0.2 |
CRITICAL | 9.8 | The WP e-Commerce β Store Toolkit plugin for WordPress is vulnerable to authorization bypass due to a missing capabili… | — | wordfence |
| 5881d16c-84e8-4610-8233-cfa5a94fe3f9 | < 3.9.2 |
CRITICAL | 9.8 | The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This… | — | wordfence |
| 5875a4c2-a309-41fb-8845-2935511ec6c0 | < 2.1.6 |
CRITICAL | 9.8 | The UnGallery plugin for WordPress is vulnerable to Command Injection in versions before 2.1.6 via the 'search' paramete… | — | wordfence |
| 586250e9-bc35-4c9d-b558-7346efd4dce9 | < 2.9.23.1 |
CRITICAL | 9.8 | The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation … | — | wordfence |
| 5846b5d9-5b69-47b0-b787-6a3416a5076e | < 1.3.2 |
CRITICAL | 9.8 | The WpBookingly plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.1 via d… | — | wordfence |
| 580f5cd1-2cda-4e8e-81b5-36ce39ebd907 | CRITICAL | 9.8 | The Zarzadzanie Kontem plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →